Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-04-09 Thread Joshua Kinard
On 04/09/2014 10:54, Rich Freeman wrote: > On Tue, Apr 8, 2014 at 11:03 PM, Rick "Zero_Chaos" Farina > wrote: >> Gentoo typically tries to keep patching to a minimum in general. To be >> enabling something like this by default seems bad, the fact that it is >> openssh compounds that. +1 for remo

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-04-09 Thread Kristian Fiskerstrand
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 04/09/2014 05:03 AM, Rick "Zero_Chaos" Farina wrote: > On 04/08/2014 02:40 PM, Mike Gilbert wrote: > > Gentoo typically tries to keep patching to a minimum in general. > To be enabling something like this by default seems bad, the fact > that it

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-04-09 Thread Rich Freeman
On Tue, Apr 8, 2014 at 11:03 PM, Rick "Zero_Chaos" Farina wrote: > Gentoo typically tries to keep patching to a minimum in general. To be > enabling something like this by default seems bad, the fact that it is > openssh compounds that. +1 for removing the + and leaving this optional > (default

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-04-09 Thread Rick "Zero_Chaos" Farina
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 04/08/2014 02:40 PM, Mike Gilbert wrote: Gentoo typically tries to keep patching to a minimum in general. To be enabling something like this by default seems bad, the fact that it is openssh compounds that. +1 for removing the + and leaving this

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-04-09 Thread Dirkjan Ochtman
On Tue, Apr 8, 2014 at 8:40 PM, Mike Gilbert wrote: > A bug in an upstream-supported feature is quite different from a > patched-in feature that upstream doesn't support. Since no maintainer has spoken up here, I filed a bug: https://bugs.gentoo.org/show_bug.cgi?id=507210 I filed a similar bug

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-04-08 Thread Mike Gilbert
On Tue, Apr 8, 2014 at 2:34 PM, Marcin Mirosław wrote: > According to last problem with openssl and +tls-heartbeat I'd like to > see less features enabled by default. USE="-*" isn't the best solution;) > A bug in an upstream-supported feature is quite different from a patched-in feature that upst

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-04-08 Thread Marcin Mirosław
W dniu 2014-03-31 19:35, Toralf Förster pisze: > On 03/31/2014 01:15 PM, Alex Xu wrote: >> On 31/03/14 03:36 AM, Dirkjan Ochtman wrote: >>> So, I'm interested... How widely used is the HPN patch set? Are there >>> any good indications that it doesn't negatively impact security? > >> https://bugs.d

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-03-31 Thread Toralf Förster
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 03/31/2014 01:15 PM, Alex Xu wrote: > On 31/03/14 03:36 AM, Dirkjan Ochtman wrote: >> So, I'm interested... How widely used is the HPN patch set? Are there >> any good indications that it doesn't negatively impact security? > > https://bugs.debia

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-03-31 Thread Alex Xu
On 31/03/14 03:36 AM, Dirkjan Ochtman wrote: > So, I'm interested... How widely used is the HPN patch set? Are there > any good indications that it doesn't negatively impact security? https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=292932 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=693424

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-03-31 Thread Dirkjan Ochtman
On Sat, Mar 29, 2014 at 11:31 PM, hasufell wrote: > We have had those debates whether the "+" should follow upstream > decisions and such. Short answer: the maintainer decides. There is no > consistency for this and there will never be. That may be true, I still think it behooves us to be particu

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-03-29 Thread hasufell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Toralf Förster: > On 03/29/2014 08:12 PM, Tom Wijsman wrote: >> On Sat, 29 Mar 2014 07:15:14 -0400 Alex Xu >> wrote: > >>> On 29/03/14 06:07 AM, Toralf Förster wrote: WRT to but 504616 I'd like to address my questions made in https://bu

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-03-29 Thread Toralf Förster
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 03/29/2014 08:12 PM, Tom Wijsman wrote: > On Sat, 29 Mar 2014 07:15:14 -0400 Alex Xu > wrote: > >> On 29/03/14 06:07 AM, Toralf Förster wrote: >>> WRT to but 504616 I'd like to address my questions made in >>> https://bugs.gentoo.org/show_bug.c

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-03-29 Thread Tom Wijsman
On Sat, 29 Mar 2014 07:15:14 -0400 Alex Xu wrote: > On 29/03/14 06:07 AM, Toralf Förster wrote: > > WRT to but 504616 I'd like to address my questions made in > > https://bugs.gentoo.org/show_bug.cgi?id=504616#c6 to this list > > again : > > > > "Since the Debian debakel with "fixing" an uni

Re: [gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-03-29 Thread Alex Xu
On 29/03/14 06:07 AM, Toralf Förster wrote: > WRT to but 504616 I'd like to address my questions made in > https://bugs.gentoo.org/show_bug.cgi?id=504616#c6 to this list again : > > "Since the Debian debakel with "fixing" an uninitialized memeory I'm > very skeptical to distribution specif

[gentoo-dev] Why is IUSE=hpn mandatory in openssh ?

2014-03-29 Thread Toralf Förster
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 WRT to but 504616 I'd like to address my questions made in https://bugs.gentoo.org/show_bug.cgi?id=504616#c6 to this list again : "Since the Debian debakel with "fixing" an uninitialized memeory I'm very skeptical to distribution specific