Re: [gentoo-dev] Guidelines for dangerous USE flags

2017-08-25 Thread William Hubbs
On Thu, Aug 24, 2017 at 11:22:24AM -0400, Michael Orlitzky wrote: > On 08/22/2017 02:44 PM, Robin H. Johnson wrote: > > From a Gentoo Infrastructure team perspective, we'd strongly prefer USE > > flags, because that fits better into existing configuration management > > tools, almost none of which

Re: [gentoo-dev] [PATCH 2/2] git-r3.eclass: Explicitly warn about unsecure protocols

2017-08-25 Thread Hanno Böck
On Wed, 23 Aug 2017 11:46:02 +0300 Andrew Savchenko wrote: > Sigh... https also makes MITM attacks possible, especially if SSL > or TLS < 1.2 is used or are allowed and protocol version downgrade > attack may be performed. None of that is true. You're probably referring to attacks that were spe

Re: [gentoo-dev] [PATCH] flag-o-matic.eclass: LDFLAGS stripping, take two

2017-08-25 Thread Michał Górny
W dniu pią, 11.08.2017 o godzinie 17∶26 +0200, użytkownik Michał Górny napisał: > Hi, everyone. > > I've just reverted the LDFLAGS stripping code I've committed earlier > because it failed hard with clang. Here's an updated patch set that > ensures that clang is going to work fine. Please review.

Re: [gentoo-dev] [PATCH 1/2] git-r3.eclass: Update docs to discourage unsafe protocols

2017-08-25 Thread Michał Górny
W dniu sob, 19.08.2017 o godzinie 10∶25 +0200, użytkownik Michał Górny napisał: > --- > eclass/git-r3.eclass | 14 +- > 1 file changed, 9 insertions(+), 5 deletions(-) > > diff --git a/eclass/git-r3.eclass b/eclass/git-r3.eclass > index bc7d4d920299..42b586811368 100644 > --- a/eclass

Re: [gentoo-dev] [PATCH 2/2] git-r3.eclass: Explicitly warn about unsecure protocols

2017-08-25 Thread Michał Górny
W dniu śro, 23.08.2017 o godzinie 11∶46 +0300, użytkownik Andrew Savchenko napisał: > On Sat, 19 Aug 2017 10:25:02 +0200 Michał Górny wrote: > > Explicitly warn about any URI that uses an unsecure protocol (git, http) > > even if it's a fallback URI. This is necessary because an attacker may > > bl