public inbox for gentoo-hardened@lists.gentoo.org
 help / color / mirror / Atom feed
From: Kerin Millar <kerframil@gmail.com>
To: gentoo-hardened@lists.gentoo.org
Subject: Re: [gentoo-hardened] hardened glibc downgrade
Date: Fri, 13 Feb 2009 18:49:21 +0000	[thread overview]
Message-ID: <279fbba40902131049n4cceb80dm51440beb35791d28@mail.gmail.com> (raw)
In-Reply-To: <200902131909.05093.casta@xwing.info>

2009/2/13 Guillaume Castagnino <casta@xwing.info>:
> Le vendredi 13 février 2009 18:48:03, Gordon Malm a écrit :
>> On Friday, February 13, 2009 09:15:18 Guillaume Castagnino wrote:
>> > In fact, no: glibc-2.9 was allready keyworded on hardened ~x86 in the
>> > portage tree, and not masked until 2009-02-11.
>> > So ~x86 hardened was naturally upgraded to glibc 2.9 without any
>> > intervention.
>>
>> And naturally if you're running ~ARCH you should know how to
>> manipulate /etc/portage.
>>
>> > I have no problem to package.unmask it, it's just to know what is the
>> > reason for this mask :)
>>
>> Because sys-libs/glibc-2.8 is about to go stable and stable hardened is not
>> ready for it.
>>
>> > But keep in mind that for ~x86 hardened, this mask has a dependency
>> > problem, since ~x86 iproute2 depends on glibc that is now masked on
>> > ~x86 hardened (and was not before 2009-02-11)
>>
>> So put sys-libs/glibc into /etc/portage/package.unmask.
>
> Yes of course.
> I perfectly know how to do to fix this problem *for me* as ~arch user for many
> years.
>
>
> But what I want to point, is that currently, depdency tree seems to be broken
> for ~x86 : some packages in the ~x86 tree (iproute2 for example) ask for
> package not available in ~x86 (glibc).
> Doesn't it sounds wrong to have such situation in the official tree ?
>

It is not ideal but, as has already been established, it poses only
the most trivial inconvenience for users such as yourself. On the
other hand, if that is what it takes to be absolutely assured that
Hardened Gentoo users who are using the stable tree will continue to
have a functional system then it is surely a sensible precaution on
the part of the maintainer. The needs of this demographic should not
be (potentially) jepoardized so as to prevent the ~arch users from
having to enter a single line into package.unmask. Under the
circumstances, what would you have done?

In terms of how other packages are stabilised, bear in mind that the
developers concerned - unlike Gordon - will seldom have the interests
of the Hardened userbase first and foremost in their minds ... a
situation exacerbated by the current disparity between the vanilla and
hardened toolchain/kernel versions and the limited manpower at the
disposal of the project. Nevertheless, things continue to move
forwards but there will be occasions - such as this - where special
measures need to be enacted.

Those of us using a bleeding-edge toolchain might consider thoroughly
testing the current stable kernel so as to determine whether this
precaution is indeed necessary.

Regards,

--Kerin



      reply	other threads:[~2009-02-13 18:49 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-02-13  9:05 [gentoo-hardened] hardened glibc downgrade Guillaume Castagnino
2009-02-13 15:27 ` Thomas Sachau
2009-02-13 16:18   ` Gordon Malm
2009-02-13 17:15     ` Guillaume Castagnino
2009-02-13 17:48       ` Gordon Malm
2009-02-13 18:03         ` [gentoo-hardened] " Peter Hjalmarsson
2009-02-13 19:29           ` Gordon Malm
2009-02-13 18:09         ` [gentoo-hardened] " Guillaume Castagnino
2009-02-13 18:49           ` Kerin Millar [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=279fbba40902131049n4cceb80dm51440beb35791d28@mail.gmail.com \
    --to=kerframil@gmail.com \
    --cc=gentoo-hardened@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox