> On 27 Jul 2021, at 13:32, David Seifert <[email protected]> wrote: > > Signed-off-by: David Seifert <[email protected]> > --- > .../2021-08-01-tcpd-disabled.en.txt | 62 +++++++++++++++++++ > 1 file changed, 62 insertions(+) > create mode 100644 2021-08-01-tcpd-disabled/2021-08-01-tcpd-disabled.en.txt > > diff --git a/2021-08-01-tcpd-disabled/2021-08-01-tcpd-disabled.en.txt > b/2021-08-01-tcpd-disabled/2021-08-01-tcpd-disabled.en.txt > new file mode 100644 > index 0000000..3631de3 > --- /dev/null > +++ b/2021-08-01-tcpd-disabled/2021-08-01-tcpd-disabled.en.txt > @@ -0,0 +1,62 @@ > +Title: USE=tcpd no longer globally enabled > +Author: David Seifert <[email protected]> > +Posted: 2021-08-01 > +Revision: 1 > +News-Item-Format: 2.0 > [snip] > + > +On 2021-11-01, we will remove USE="tcpd" from the globally default > +enabled USE flags. USE="tcpd" usually enables sys-apps/tcp-wrappers > +for an adhoc firewall based on /etc/hosts.allow and /etc/hosts.deny. > +
This lgtm overall and thanks for working on it. Some minor comments below. Could you file and reference a bug within the news item (and in the commit message for the news item) to allow issues to be raised in one place by users? > +The base system project has come to the conclusion that 24 years after s/base system/Base System/. > +the last upstream release, tcp-wrappers is not relevant in 2021 anymore. How about: "tcp-wrappers is not suitable for a default configuration in 2021 anymore."? > +Other distributions have completely removed support at this point. If > +you rely on tcp-wrappers, you can re-enable the flag. We strongly > +recommend you switch to more modern packet filters, such as BPF, > +nftables or iptables. Let's add that we recommend users who specifically rely on functionality, including tcpd, can and should enable it specifically for that package via their package manager's configuration? (make.conf/package.use for Portage). We'll link to https://wiki.gentoo.org/wiki//etc/portage/package.use. best, sam
signature.asc
Description: Message signed with OpenPGP
