| From | Sent On | Attachments |
|---|---|---|
| Chris Rees | Sep 4, 2011 9:55 am | |
| Chris Rees | Sep 4, 2011 12:20 pm | |
| Julian H. Stacey | Sep 4, 2011 1:32 pm | |
| Chris Rees | Sep 4, 2011 1:36 pm | |
| Mark Linimon | Sep 4, 2011 4:17 pm | |
| per...@pluto.rain.com | Sep 4, 2011 7:12 pm | |
| Julian H. Stacey | Sep 5, 2011 2:32 am | |
| Julian H. Stacey | Sep 5, 2011 3:05 am | |
| Chris Rees | Sep 5, 2011 4:11 am | |
| Oliver Fromme | Sep 5, 2011 4:38 am | |
| Doug Barton | Sep 5, 2011 5:40 am | |
| Julian H. Stacey | Sep 5, 2011 9:29 am | |
| Mikhail T. | Sep 5, 2011 10:15 am | |
| Chris Rees | Sep 5, 2011 10:31 am | |
| Kostik Belousov | Sep 5, 2011 11:01 am | |
| Mikhail T. | Sep 5, 2011 11:29 am | |
| Matthias Andree | Sep 5, 2011 12:06 pm | |
| Mikhail T. | Sep 5, 2011 2:42 pm | |
| Julian H. Stacey | Sep 5, 2011 2:46 pm | |
| per...@pluto.rain.com | Sep 5, 2011 4:05 pm | |
| Eitan Adler | Sep 5, 2011 4:29 pm | |
| Doug Barton | Sep 5, 2011 7:13 pm | |
| Yar Tikhiy | Sep 5, 2011 9:52 pm | |
| Tony Mc | Sep 6, 2011 1:13 am | |
| Chris Rees | Sep 6, 2011 6:19 am | |
| Matthias Andree | Sep 6, 2011 10:12 am | |
| per...@pluto.rain.com | Sep 6, 2011 5:15 pm | |
| per...@pluto.rain.com | Sep 6, 2011 5:15 pm | |
| Yar Tikhiy | Sep 6, 2011 5:34 pm | |
| Doug Barton | Sep 6, 2011 9:14 pm | |
| Mikhail T. | Sep 6, 2011 10:25 pm | |
| Stanislav Sedov | Sep 6, 2011 11:29 pm | |
| Erwin Lansing | Sep 6, 2011 11:32 pm | |
| Chad Perrin | Sep 7, 2011 12:35 am | |
| per...@pluto.rain.com | Sep 7, 2011 3:24 am | |
| Kurt Jaeger | Sep 7, 2011 3:53 am | |
| Peter Jeremy | Sep 7, 2011 4:36 am | |
| Erik Trulsson | Sep 7, 2011 4:54 am | |
| Oliver Fromme | Sep 7, 2011 6:52 am | |
| Chad Perrin | Sep 7, 2011 8:20 am | |
| Chad Perrin | Sep 7, 2011 8:24 am | |
| Mikhail T. | Sep 7, 2011 8:52 am | |
| Erik Trulsson | Sep 7, 2011 8:56 am | |
| Chris Rees | Sep 7, 2011 9:03 am | |
| Chad Perrin | Sep 7, 2011 9:17 am | |
| Mikhail T. | Sep 7, 2011 9:19 am | |
| per...@pluto.rain.com | Sep 7, 2011 3:15 pm | |
| Doug Barton | Sep 7, 2011 3:45 pm | |
| Mikhail T. | Sep 7, 2011 5:14 pm | |
| Julian H. Stacey | Sep 7, 2011 6:28 pm | |
| Glen Barber | Sep 7, 2011 9:12 pm | |
| Chris Rees | Sep 7, 2011 11:20 pm | |
| Greg Byshenk | Sep 8, 2011 1:41 am | |
| Julian H. Stacey | Sep 8, 2011 2:31 am | |
| Matt Burke | Sep 8, 2011 4:52 am | |
| Mikhail T. | Sep 8, 2011 7:15 am | |
| Michel Talon | Sep 8, 2011 7:45 am | |
| Matthias Andree | Sep 8, 2011 9:36 am | |
| Matthias Andree | Sep 8, 2011 9:46 am | |
| Matthias Andree | Sep 8, 2011 9:54 am | |
| Chad Perrin | Sep 8, 2011 2:23 pm | |
| Julian H. Stacey | Sep 8, 2011 4:00 pm | |
| Julian H. Stacey | Sep 8, 2011 5:26 pm | |
| Chad Perrin | Sep 8, 2011 6:05 pm | |
| Erik Trulsson | Sep 8, 2011 10:21 pm | |
| Erik Trulsson | Sep 8, 2011 10:27 pm | |
| Greg Byshenk | Sep 9, 2011 12:48 am | |
| Conrad J. Sabatier | Sep 9, 2011 2:09 am | |
| Miroslav Lachman | Sep 9, 2011 2:25 am | |
| Conrad J. Sabatier | Sep 9, 2011 4:20 am | |
| Matt Burke | Sep 9, 2011 5:38 am | |
| Matthias Andree | Sep 9, 2011 9:06 am | |
| Matthias Andree | Sep 9, 2011 10:05 am | |
| Matthias Andree | Sep 9, 2011 10:12 am | |
| Conrad J. Sabatier | Sep 9, 2011 10:45 pm | |
| Chris Rees | Sep 9, 2011 11:38 pm | |
| per...@pluto.rain.com | Sep 10, 2011 12:11 am | |
| Matthias Andree | Sep 10, 2011 3:08 am | |
| Matthias Andree | Sep 10, 2011 3:24 am | |
| Chad Perrin | Sep 10, 2011 9:12 am | |
| Chad Perrin | Sep 10, 2011 9:17 am | |
| Matthias Andree | Sep 10, 2011 1:38 pm | |
| Conrad J. Sabatier | Sep 10, 2011 1:51 pm | |
| Chad Perrin | Sep 10, 2011 3:43 pm | |
| per...@pluto.rain.com | Sep 10, 2011 4:14 pm | |
| Julian H. Stacey | Sep 12, 2011 2:31 pm | |
| Eric Masson | Sep 13, 2011 2:23 am | |
| Mark Linimon | Sep 13, 2011 8:55 am | |
| Matthias Andree | Sep 13, 2011 10:13 am | |
| Chris Rees | Sep 13, 2011 10:41 am | |
| Chris Rees | Sep 13, 2011 10:44 am | |
| Chris Rees | Sep 13, 2011 11:24 am | |
| Chris Rees | Sep 13, 2011 1:51 pm | |
| Julian H. Stacey | Sep 13, 2011 3:57 pm | |
| Glen Barber | Sep 13, 2011 7:20 pm | |
| Jason Hellenthal | Sep 13, 2011 8:55 pm |
| Subject: | Re: Re: sysutils/cfs | |
|---|---|---|
| From: | Kostik Belousov (kost...@gmail.com) | |
| Date: | Sep 5, 2011 11:01:51 am | |
| List: | org.freebsd.freebsd-ports | |
On Mon, Sep 05, 2011 at 06:32:00PM +0100, Chris Rees wrote:
On 5 Sep 2011 18:15, "Mikhail T." <mi+th...@aldan.algebra.com> wrote:
On -10.01.-28163 14:59, Chris Rees wrote:
I've had to deprecate sysutils/cfs -- there's a confirmed issue with failing locks [1] which has been open for two years with no fix.
Whoops, also missed a CVE -- buffer overflows can cause a DoS. Expiration date altered to 1 month accordingly.
Is this the only vulnerability you are talking about?
Does not seem hard to fix at all... Listing all of the fatal problems
would be helpful...
-mi
If it's not that hard to fix then do it. If you're not going to fix it, why are you even commenting?
More noise. Stop whining and do something about it.
No, it is not a noise.
First, note that an issue in the local deamon can be only utilized by local users. As a consequence, there is a huge set of machines for which the cited issue is simply irrelevant.
For the analogous issues that are irrelevant for 90% of the port users, look at the vulnerabilities listed for the quake ports.
Second, I personally consider the crusade to remove old but compiling and working (*) ports as a damage both to the project functionality and to the project reputation.
* Working exactly because users report bugs in the software, otherwise they would not be able to describe corner cases that break.
I saw a port that is:
- broken - vulnerable - unmaintained - dead upstream - has been removed by other distributions
I don't use it, you don't use it, why do you care?
See above. This is the sort of rethoric that I find damaging.
The only point that I buy from the list is 'had been removed by other distributions'. Everything else is relative, and since _you_ are not the user of the package, did not even tried to use it, and obviously not estimated the risks and brokeness of the package right (as shown by two episodes, once with the NLM, second with the vulnerability), I consider the removal as frivolous and damaging.
It only continues the trend, I agree.





