David Shakaryan napsal(a): > Alec Warner wrote: >> Jakub Moc wrote: >>> Ciaran McCreesh napsal(a): >>>> So what happens when users have an old, masked package installed that's >>>> no longer masked thanks to this change? >>> Err, exactly nothing? If they didn't unmerge it, they'll continue to >>> have it installed as they did before? >>> >> For things like security packages; it is troublesome. >> >> 1.x has a sec vuln but 2.x fixes it; upstream isn't willing to backport >> and both stay in the tree. So we mask 1.x for sec reasons. > > It seems like you didn't understand exactly what I did. The masks I > removed are *ONLY* those which are masking a package or version that is > no longer in the tree.
I also fail to see the problem. I checked and none of the "unmasked" versions/ebuilds is actually in the tree. Where's the security issue here? Do we need a dumspace for non-existant stuff in package.mask? -- Best regards, Jakub Moc mailto:[EMAIL PROTECTED] GPG signature: http://subkeys.pgp.net:11371/pks/lookup?op=get&search=0xCEBA3D9E Primary key fingerprint: D2D7 933C 9BA1 C95B 2C95 B30F 8717 D5FD CEBA 3D9E ... still no signature ;)
signature.asc
Description: OpenPGP digital signature
