Bug#318946: User expectations and shorewall

2005-09-16 Thread Lorenzo Martignoni
* Martin Schulze [EMAIL PROTECTED]: Florian Weimer wrote: (Note that I have yet to test Lorenzo's new package.) Are you in a position to do so? Sure, but the question is if you want to rely on the results. You don't seem to trust my judgement on this matter, for reasons I don't

Bug#318946: User expectations and shorewall

2005-09-16 Thread Martin Schulze
Lorenzo Martignoni wrote: If you can, please build an updated package, based on the version in sarge and woody if that's needed as well, and place them on a .debian.org host. I already have a fixed package. I only need to add the CVE ID. On which host of .debian.org should I upload it?

Bug#318946: User expectations and shorewall

2005-09-15 Thread Martin Schulze
Florian Weimer wrote: (Note that I have yet to test Lorenzo's new package.) Are you in a position to do so? Sure, but the question is if you want to rely on the results. You don't seem to trust my judgement on this matter, for reasons I don't know. I simply did not understand the

Bug#318946: User expectations and shorewall

2005-09-06 Thread Florian Weimer
* Lorenzo Martignoni: The patch has been tested by me and by Paul Gear but further tests will be better, so your feedback will be very precious. Apart from the lack of CVE entry in the changelog, the package seems to be fine. Both problems are fixed. There is a surprising reduction of the

Bug#318946: User expectations and shorewall

2005-09-06 Thread Lorenzo Martignoni
* Florian Weimer [EMAIL PROTECTED]: * Lorenzo Martignoni: The patch has been tested by me and by Paul Gear but further tests will be better, so your feedback will be very precious. Apart from the lack of CVE entry in the changelog, the package seems to be fine. Both problems are

Bug#318946: User expectations and shorewall

2005-09-02 Thread Florian Weimer
* Martin Schulze: What was the behaviour pre-sarge? What is the behaviour post-sarge (or rather in sarge)? Do you mean before and after the upstream security update? The terms pre-sarge/post-sarge do not make much sense to me in this context, I'm afraid. Ok, so when did the behaviour

Bug#318946: User expectations and shorewall

2005-09-02 Thread Lorenzo Martignoni
* Florian Weimer [EMAIL PROTECTED]: * Martin Schulze: What was the behaviour pre-sarge? What is the behaviour post-sarge (or rather in sarge)? Do you mean before and after the upstream security update? The terms pre-sarge/post-sarge do not make much sense to me in this context,

Bug#318946: User expectations and shorewall

2005-09-01 Thread Florian Weimer
As far as I understand it, from the perspective of the security team, it is not clear if the upstream change breaks existing user configurations. Users might rely on the current behavior and use it to deliberately weaken the filter policy. This is a reasonable question because the existing

Bug#318946: User expectations and shorewall

2005-09-01 Thread Martin Schulze
Florian Weimer wrote: As far as I understand it, from the perspective of the security team, it is not clear if the upstream change breaks existing user configurations. Users might rely on the current behavior and use it to deliberately weaken the filter policy. This is a reasonable question

Bug#318946: User expectations and shorewall

2005-09-01 Thread Florian Weimer
* Martin Schulze: So a summary would be to leave the package as it is in sarge, right? Based on the facts, I reach the opposite conclusion. The upstream changes should be merged. However, since easy workarounds are possible, we might get away without code changes, if issuing the update

Bug#318946: User expectations and shorewall

2005-09-01 Thread Martin Schulze
Florian Weimer wrote: * Martin Schulze: So a summary would be to leave the package as it is in sarge, right? Based on the facts, I reach the opposite conclusion. The upstream changes should be merged. However, since easy workarounds are possible, we might get away without code changes,

Bug#318946: User expectations and shorewall

2005-09-01 Thread Lorenzo Martignoni
* Florian Weimer [EMAIL PROTECTED]: * Martin Schulze: What was the behaviour pre-sarge? What is the behaviour post-sarge (or rather in sarge)? Do you mean before and after the upstream security update? The terms pre-sarge/post-sarge do not make much sense to me in this context, I'm

Bug#318946: User expectations and shorewall

2005-09-01 Thread Martin Schulze
Florian Weimer wrote: * Martin Schulze: What was the behaviour pre-sarge? What is the behaviour post-sarge (or rather in sarge)? Do you mean before and after the upstream security update? The terms pre-sarge/post-sarge do not make much sense to me in this context, I'm afraid. Ok, so