> On 27 Jul 2021, at 13:32, David Seifert <[email protected]> wrote:
> 
> Signed-off-by: David Seifert <[email protected]>
> ---
> .../2021-08-01-tcpd-disabled.en.txt           | 62 +++++++++++++++++++
> 1 file changed, 62 insertions(+)
> create mode 100644 2021-08-01-tcpd-disabled/2021-08-01-tcpd-disabled.en.txt
> 
> diff --git a/2021-08-01-tcpd-disabled/2021-08-01-tcpd-disabled.en.txt 
> b/2021-08-01-tcpd-disabled/2021-08-01-tcpd-disabled.en.txt
> new file mode 100644
> index 0000000..3631de3
> --- /dev/null
> +++ b/2021-08-01-tcpd-disabled/2021-08-01-tcpd-disabled.en.txt
> @@ -0,0 +1,62 @@
> +Title: USE=tcpd no longer globally enabled
> +Author: David Seifert <[email protected]>
> +Posted: 2021-08-01
> +Revision: 1
> +News-Item-Format: 2.0
> [snip]
> +
> +On 2021-11-01, we will remove USE="tcpd" from the globally default
> +enabled USE flags. USE="tcpd" usually enables sys-apps/tcp-wrappers
> +for an adhoc firewall based on /etc/hosts.allow and /etc/hosts.deny.
> +

This lgtm overall and thanks for working on it. Some minor comments below.

Could you file and reference a bug within the news item (and in the commit
message for the news item) to allow issues to be raised in one place by users?

> +The base system project has come to the conclusion that 24 years after

s/base system/Base System/.

> +the last upstream release, tcp-wrappers is not relevant in 2021 anymore.

How about: "tcp-wrappers is not suitable for a default configuration in 2021 
anymore."?

> +Other distributions have completely removed support at this point. If
> +you rely on tcp-wrappers, you can re-enable the flag. We strongly
> +recommend you switch to more modern packet filters, such as BPF,
> +nftables or iptables.

Let's add that we recommend users who specifically rely on functionality,
including tcpd, can and should enable it specifically for that package
via their package manager's configuration? (make.conf/package.use for
Portage).

We'll link to https://wiki.gentoo.org/wiki//etc/portage/package.use.

best,
sam

Attachment: signature.asc
Description: Message signed with OpenPGP

Reply via email to