[gentoo-dev] Re: Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Duncan
Andrew Savchenko posted on Sun, 29 Mar 2015 21:04:52 +0300 as excerpted: On Sun, 29 Mar 2015 19:52:38 +0200 Sebastian Pipping wrote: On 29.03.2015 19:39, Andrew Savchenko wrote: On Sun, 29 Mar 2015 18:41:33 +0200 Sebastian Pipping wrote: So I would like to propose that * support for

Re: [gentoo-dev] rfc: add-on files handling improvements

2015-03-29 Thread William Hubbs
On Sun, Mar 29, 2015 at 07:49:32PM -0400, Rich Freeman wrote: On Sun, Mar 29, 2015 at 7:28 PM, William Hubbs willi...@gentoo.org wrote: On Mon, Mar 30, 2015 at 12:11:34AM +0200, Matthias Maier wrote: Thoughts? One point in favor of the current practice (installing add-on files

[gentoo-dev] Automated Package Removal and Addition Tracker, for the week ending 2015-03-29 23:59 UTC

2015-03-29 Thread Robin H. Johnson
The attached list notes all of the packages that were added or removed from the tree, for the week ending 2015-03-29 23:59 UTC. Removals: dev-python/py-freebsd 2015-03-24 01:24:48 idella4 dev-python/cherryflow 2015-03-24 02:46:31 idella4

Re: [gentoo-dev] Re: [gentoo-user] Re: This nite's switch to full multilib

2015-03-29 Thread Davide Pesavento
On Mon, Mar 30, 2015 at 1:12 AM, Rich Freeman ri...@gentoo.org wrote: On Sun, Mar 29, 2015 at 5:56 PM, Davide Pesavento p...@gentoo.org wrote: On Sun, Mar 29, 2015 at 8:23 PM, Rich Freeman ri...@gentoo.org wrote: qt is a pretty significant package to have break with multilib, and trying to

[gentoo-dev] RFC News item: FFmpeg default

2015-03-29 Thread Ben de Groot
Title: FFmpeg default Author: Ben de Groot yng...@gentoo.org Content-Type: text/plain Posted: 2015-04-01 Revision: 1 News-Item-Format: 1.0 Display-If-Installed: virtual/ffmpeg Since the choice between ffmpeg and libav has been made more explicit, there has been a lot of discussion about what the

Re: [gentoo-dev] RFC News item: FFmpeg default

2015-03-29 Thread Michał Górny
Dnia 2015-03-30, o godz. 00:07:16 Ben de Groot yng...@gentoo.org napisał(a): Title: FFmpeg default Author: Ben de Groot yng...@gentoo.org Content-Type: text/plain Posted: 2015-04-01 Revision: 1 News-Item-Format: 1.0 Display-If-Installed: virtual/ffmpeg Since the choice between ffmpeg

[gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Nikos Chantziaras
On 17/03/15 18:29, Michał Górny wrote: Dnia 2015-03-17, o godz. 16:55:32 René Neumann li...@necoro.eu napisał(a): Am 17.03.2015 um 16:33 schrieb Michał Górny: However, some users may prefer setting ABI_X86 globally to enable 32-bit libraries in all packages that support building them. This

Re: [gentoo-dev] Should Gentoo do https by default?

2015-03-29 Thread Michał Górny
Dnia 2015-03-27, o godz. 15:33:15 Hanno Böck ha...@gentoo.org napisał(a): I think defaulting the net to HTTPS is a big step for more security and I think Gentoo should join the trend here. While I don't mind this entirely, we need to make sure to get things right. For example, I'm quite

Re: [gentoo-dev] Last rites: app-emulation/emul-linux-x86*

2015-03-29 Thread Michał Górny
Dnia 2015-03-29, o godz. 11:57:12 James Le Cuirot ch...@gentoo.org napisał(a): On Sun, 29 Mar 2015 12:13:32 +0200 Pacho Ramos pa...@gentoo.org wrote: app-emulation/emul-linux-x86-jna-20140508-r1 Why do we need to keep app-emulation/emul-linux-x86-jna-20140508-r1 to simply end up

Re: [gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Michał Górny
Dnia 2015-03-29, o godz. 19:14:43 Nikos Chantziaras rea...@gmail.com napisał(a): On 17/03/15 18:29, Michał Górny wrote: Dnia 2015-03-17, o godz. 16:55:32 René Neumann li...@necoro.eu napisał(a): Am 17.03.2015 um 16:33 schrieb Michał Górny: However, some users may prefer setting

Re: [gentoo-dev] rfc: zsh completions -- optional or mandatory?

2015-03-29 Thread Andreas K. Huettel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Am Donnerstag, 26. März 2015, 17:51:04 schrieb William Hubbs: I'm seeing at least two ways of handling zsh completion files in the tree. [...] The other method is shown by dev-vcs/hub at least, and maybe several other packages -- e.g.

Re: [gentoo-dev] rfc: zsh completions -- optional or mandatory?

2015-03-29 Thread Michał Górny
Dnia 2015-03-29, o godz. 14:22:56 Andreas K. Huettel dilfri...@gentoo.org napisał(a): -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Am Donnerstag, 26. März 2015, 17:51:04 schrieb William Hubbs: I'm seeing at least two ways of handling zsh completion files in the tree. [...]

[gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Nikos Chantziaras
On 29/03/15 19:24, Michał Górny wrote: Dnia 2015-03-29, o godz. 19:14:43 Nikos Chantziaras rea...@gmail.com napisał(a): On 17/03/15 18:29, Michał Górny wrote: Dnia 2015-03-17, o godz. 16:55:32 René Neumann li...@necoro.eu napisał(a): Am 17.03.2015 um 16:33 schrieb Michał Górny: However,

Re: [gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Michał Górny
Dnia 2015-03-29, o godz. 19:59:19 Nikos Chantziaras rea...@gmail.com napisał(a): On 29/03/15 19:24, Michał Górny wrote: Dnia 2015-03-29, o godz. 19:14:43 Nikos Chantziaras rea...@gmail.com napisał(a): On 17/03/15 18:29, Michał Górny wrote: Dnia 2015-03-17, o godz. 16:55:32 René

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Vadim A. Misbakh-Soloviov
Despite of all you're talking about is right from paranoid point of view, I'd, anyway, say DO NOT DO THAT, because you propose to revoke the right of choice from the users. It is user's decision, which protocol to use to fetch the sources. Although, you're, of course, free to make layman to

Re: [gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Andrew Savchenko
On Sun, 29 Mar 2015 19:28:22 +0200 Michał Górny wrote: If this is not the case, and */* abi_x86_32 in package.use really does something different, then this is implemented in a way too confusing for people and should be considered a bug :-/ Yes, USE support in make.conf is a big pile of

Re: [gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Michał Górny
Dnia 2015-03-29, o godz. 20:35:27 Andrew Savchenko birc...@gentoo.org napisał(a): On Sun, 29 Mar 2015 19:28:22 +0200 Michał Górny wrote: If this is not the case, and */* abi_x86_32 in package.use really does something different, then this is implemented in a way too confusing for

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Vadim A. Misbakh-Soloviov
Doesn't git:// uses SSH wich is secure? I think that was on github. git+ssh:// — does. git:// — does not. It is just git-daemon listening on separate port and serving plaintext, readonly (by default) access. signature.asc Description: This is a digitally signed message part.

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Vadim A. Misbakh-Soloviov
GitHub does not support git:// but only secure protocols (HTTPS, SSH), GitHub DO (!) support git:// $ git clone git://github.com/msva/mva-overlay.git Cloning into 'mva-overlay'... remote: Counting objects: 10435, done. remote: Compressing objects: 100% (41/41), done. remote: Total 10435 (delta

[gentoo-dev] Re: [gentoo-user] Re: This nite's switch to full multilib

2015-03-29 Thread Rich Freeman
(crossposting to -dev since this is fairly high-impact) On Sun, Mar 29, 2015 at 1:27 PM, Michael Palimaka kensing...@gentoo.org wrote: On 30/03/15 03:43, waben...@gmail.com wrote: I also have dev-qt/qtcore-4.8.5-r2 and some other qt packages installed but I had no problems with that. I'm on

[gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Nikos Chantziaras
On 29/03/15 21:00, Andrew Savchenko wrote: */* long list of 433 flags Yeah, just noticed that I can't split the lines. I then tried to define an array of USE flags in make.conf: GLOBAL_USE_FLAGS=( ... ) so that I can then use that array in package.use, but for some reason make.conf

Re: [gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Michał Górny
Dnia 2015-03-29, o godz. 21:31:49 Nikos Chantziaras rea...@gmail.com napisał(a): On 29/03/15 21:00, Andrew Savchenko wrote: */* long list of 433 flags Yeah, just noticed that I can't split the lines. I then tried to define an array of USE flags in make.conf: GLOBAL_USE_FLAGS=( ...

[gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Sebastian Pipping
Hi! For the current Gentoo Git setup I found these methods working for accessing a repository, betagarden in this case: git://anongit.gentoo.org/proj/betagarden.git (git://git.gentoo.org/proj/betagarden.git) (git://git.overlays.gentoo.org/proj/betagarden.git)

Re: [gentoo-dev] Should Gentoo do https by default?

2015-03-29 Thread Michał Górny
Dnia 2015-03-29, o godz. 18:50:17 Hanno Böck ha...@gentoo.org napisał(a): On Sun, 29 Mar 2015 16:46:05 +0200 Michał Górny mgo...@gentoo.org wrote: While I don't mind this entirely, we need to make sure to get things right. For example, I'm quite unhappy being unable to use Forums or

Re: [gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Ciaran McCreesh
On Sun, 29 Mar 2015 20:35:27 +0300 Andrew Savchenko birc...@gentoo.org wrote: The proposal above is an absolute madness, especially for global USE flags. Why users should deal with dozens (if not hundreds useless */*)? The syntax for package.use allows multiple flags per line, and

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Kristian Fiskerstrand
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 03/29/2015 06:41 PM, Sebastian Pipping wrote: Hi! ... * Why do we serve Git over git:// and http:// if those are vulnerable to man-in-the-middle attacks (before having waterproof GPG protection for whole repositories in place)?

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Vadim A. Misbakh-Soloviov
They would not do online banking over http, right? Why would they run code with root privileges from http? 1) Actually, they will :( 2) Because they can't review what bank received via insecure channel, while they can review what they're themselves received via http/git. -- Best regards,

[gentoo-dev] multilib and different CFLAGS for 32 and 64bit ABIs

2015-03-29 Thread Matthias Schwarzott
Hi there! I updated my ~amd64 system recently to new hardware (Intel Core i3-4160). Since then valgrind did no longer work for 32bit programs because -march=native did choose instructions that valgrind does not support in 32bit mode (even ld.so was unusable). After some research I put this into

Re: [gentoo-dev] RFC News item: FFmpeg default

2015-03-29 Thread Peter Stuge
Ben de Groot wrote: Title: FFmpeg default Posted: 2015-04-01 Bad date for such news. //Peter

Re: [gentoo-dev] Should Gentoo do https by default?

2015-03-29 Thread James Le Cuirot
On Sun, 29 Mar 2015 19:23:51 +0200 Michał Górny mgo...@gentoo.org wrote: Xperia X10 Mini, with ancient Android 2.1. bugs.gentoo.org works, though it complains about hostname mismatch (I guess it doesn't handle wildcard certs or sth). Not exactly, it can't handle servers with more than one

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Andrew Savchenko
On Sun, 29 Mar 2015 18:41:33 +0200 Sebastian Pipping wrote: So I would like to propose that * support for Git access through https:// is activated, * Git access through http:// and git:// is deactivated, and Some people have https blocked. http:// and git:// must be available read-only.

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Sebastian Pipping
On 29.03.2015 19:39, Andrew Savchenko wrote: On Sun, 29 Mar 2015 18:41:33 +0200 Sebastian Pipping wrote: So I would like to propose that * support for Git access through https:// is activated, * Git access through http:// and git:// is deactivated, and Some people have https blocked.

[gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Nikos Chantziaras
On 29/03/15 20:28, Michał Górny wrote: Dnia 2015-03-29, o godz. 19:59:19 Nikos Chantziaras rea...@gmail.com napisał(a): According to emerge --info, ABI_X86 seems to append, not override. In make.conf: ABI_X86=32 Then: $ emerge --info | grep -i abi_x86 You get: ABI_X86=32 64

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Diamond
On Sun, 29 Mar 2015 18:41:33 +0200 Sebastian Pipping sp...@gentoo.org wrote: Hi! For the current Gentoo Git setup I found these methods working for accessing a repository, betagarden in this case: git://anongit.gentoo.org/proj/betagarden.git

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Andrew Savchenko
On Sun, 29 Mar 2015 19:52:38 +0200 Sebastian Pipping wrote: On 29.03.2015 19:39, Andrew Savchenko wrote: On Sun, 29 Mar 2015 18:41:33 +0200 Sebastian Pipping wrote: So I would like to propose that * support for Git access through https:// is activated, * Git access through http://

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Sebastian Pipping
On 29.03.2015 19:56, Diamond wrote: Doesn't git:// uses SSH wich is secure? I think that was on github. git:// is the git protocol [1] with absolutely no authentication and no encryption. GitHub does not support git:// but only secure protocols (HTTPS, SSH), see [2]. Best, Sebastian [1]

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Vadim A. Misbakh-Soloviov
pedantOpenPGP (GPG is just one implementation)/pedant, but indeed, that is what the gentoo-keys project is about. There is experimental support for OpenPGP verification in portage already using gkeys. Currently the focus is on getting developer's keys up to GLEP63 specs, i currently see 36

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Rich Freeman
On Sun, Mar 29, 2015 at 1:52 PM, Sebastian Pipping sp...@gentoo.org wrote: On 29.03.2015 19:39, Andrew Savchenko wrote: On Sun, 29 Mar 2015 18:41:33 +0200 Sebastian Pipping wrote: So I would like to propose that * support for Git access through https:// is activated, * Git access through

Re: [gentoo-dev] Should Gentoo do https by default?

2015-03-29 Thread Hanno Böck
On Sun, 29 Mar 2015 16:46:05 +0200 Michał Górny mgo...@gentoo.org wrote: While I don't mind this entirely, we need to make sure to get things right. For example, I'm quite unhappy being unable to use Forums or sources.g.o from my phone because of some SSL issues… Can you be more specific on

Re: [gentoo-dev] Re: multilib amd64 news item for review

2015-03-29 Thread Andrew Savchenko
On Sun, 29 Mar 2015 19:43:51 +0200 Michał Górny wrote: Dnia 2015-03-29, o godz. 20:35:27 Andrew Savchenko birc...@gentoo.org napisał(a): On Sun, 29 Mar 2015 19:28:22 +0200 Michał Górny wrote: If this is not the case, and */* abi_x86_32 in package.use really does something

Re: [gentoo-dev] Last rites: app-emulation/emul-linux-x86*

2015-03-29 Thread Pacho Ramos
El sáb, 28-03-2015 a las 23:03 +0100, Michał Górny escribió: # Michał Górny mgo...@gentoo.org (14 Sep 2014) # on behalf of gx86-multilib project multi...@gentoo.org # Mask emul-linux-x86 packages along with unported old versions # of reverse dependencies for removal in 60 days, bug #544876. #

Re: [gentoo-dev] Cluster tinderbox poc

2015-03-29 Thread Pacho Ramos
El sáb, 28-03-2015 a las 17:20 +0100, Magnus Granberg escribió: Hi As some of you may know, I have been working on code for a tinderbox with frontend support. I think its time to move it to a offcial project. The Proof-Of-Concept (poc) is almost ready, but it still have alot of the

Re: [gentoo-dev] Last rites: app-emulation/emul-linux-x86*

2015-03-29 Thread James Le Cuirot
On Sun, 29 Mar 2015 12:13:32 +0200 Pacho Ramos pa...@gentoo.org wrote: app-emulation/emul-linux-x86-jna-20140508-r1 Why do we need to keep app-emulation/emul-linux-x86-jna-20140508-r1 to simply end up rdepending on =virtual/libffi-3.0.13-r1[abi_x86_32(-)] ? Also, no package in the tree

Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks

2015-03-29 Thread Hanno Böck
On Sun, 29 Mar 2015 23:35:54 +0600 Vadim A. Misbakh-Soloviov m...@mva.name wrote: Despite of all you're talking about is right from paranoid point of view, I'd, anyway, say DO NOT DO THAT, because you propose to revoke the right of choice from the users. A right of choice from the user only

Re: [gentoo-dev] multilib and different CFLAGS for 32 and 64bit ABIs

2015-03-29 Thread Matt Turner
On Sun, Mar 29, 2015 at 11:58 AM, Matthias Schwarzott z...@gentoo.org wrote: Hi there! I updated my ~amd64 system recently to new hardware (Intel Core i3-4160). Since then valgrind did no longer work for 32bit programs because -march=native did choose instructions that valgrind does not

Re: [gentoo-dev] multilib and different CFLAGS for 32 and 64bit ABIs

2015-03-29 Thread Matthias Schwarzott
On 29.03.2015 20:58, Matthias Schwarzott wrote: Hi there! I updated my ~amd64 system recently to new hardware (Intel Core i3-4160). Since then valgrind did no longer work for 32bit programs because -march=native did choose instructions that valgrind does not support in 32bit mode (even

Re: [gentoo-dev] multilib and different CFLAGS for 32 and 64bit ABIs

2015-03-29 Thread Anthony G. Basile
On 03/29/15 15:07, Matt Turner wrote: On Sun, Mar 29, 2015 at 11:58 AM, Matthias Schwarzott z...@gentoo.org wrote: Hi there! I updated my ~amd64 system recently to new hardware (Intel Core i3-4160). Since then valgrind did no longer work for 32bit programs because -march=native did choose

Re: [gentoo-dev] multilib and different CFLAGS for 32 and 64bit ABIs

2015-03-29 Thread Davide Pesavento
On Sun, Mar 29, 2015 at 9:12 PM, Matthias Schwarzott z...@gentoo.org wrote: On 29.03.2015 20:58, Matthias Schwarzott wrote: Hi there! I updated my ~amd64 system recently to new hardware (Intel Core i3-4160). Since then valgrind did no longer work for 32bit programs because -march=native did

[gentoo-dev] rfc: add-on files handling improvements

2015-03-29 Thread William Hubbs
All, I want to start a discussion about our add-on files practice and try to improve it. I agree it is reasonable to install bash completions unconditionally, because bash is part of the base requirement for Gentoo. However, I do not agree that we should continue installing add-on files for

Re: [gentoo-dev] Re: [gentoo-user] Re: This nite's switch to full multilib

2015-03-29 Thread Davide Pesavento
On Sun, Mar 29, 2015 at 8:23 PM, Rich Freeman ri...@gentoo.org wrote: I think we really need to either stabilize 4.8.6, or backport qtchooser/multilib/etc to the current stable version. Backporting is not an option. The introduction of multilib support in qt4 required extensive changes to the

Re: [gentoo-dev] Last rites: app-emulation/emul-linux-x86*

2015-03-29 Thread James Le Cuirot
On Sun, 29 Mar 2015 17:49:50 +0200 Michał Górny mgo...@gentoo.org wrote: Michał, as already discussed with Pacho [1], emul-linux-x86-jna can just go away entirely. Nothing requires it and it doesn't make any sense without emul-linux-x86-java though I note that isn't in the list either; I

Re: [gentoo-dev] rfc: add-on files handling improvements

2015-03-29 Thread Matthias Maier
Thoughts? One point in favor of the current practice (installing add-on files unconditionally) is the fact that you can basically do it for free - you neither have to depend on additional packages, nor is the presence of the add-on files a penalty in download time or storage. Further, a lot of

Re: [gentoo-dev] Re: [gentoo-user] Re: This nite's switch to full multilib

2015-03-29 Thread Rich Freeman
On Sun, Mar 29, 2015 at 5:56 PM, Davide Pesavento p...@gentoo.org wrote: On Sun, Mar 29, 2015 at 8:23 PM, Rich Freeman ri...@gentoo.org wrote: qt is a pretty significant package to have break with multilib, and trying to run qt-5 on a stable system is already a nightmare with the qtchooser

Re: [gentoo-dev] rfc: add-on files handling improvements

2015-03-29 Thread William Hubbs
On Mon, Mar 30, 2015 at 12:11:34AM +0200, Matthias Maier wrote: Thoughts? One point in favor of the current practice (installing add-on files unconditionally) is the fact that you can basically do it for free - you neither have to depend on additional packages, nor is the presence of the

Re: [gentoo-dev] rfc: add-on files handling improvements

2015-03-29 Thread Rich Freeman
On Sun, Mar 29, 2015 at 7:28 PM, William Hubbs willi...@gentoo.org wrote: On Mon, Mar 30, 2015 at 12:11:34AM +0200, Matthias Maier wrote: Thoughts? One point in favor of the current practice (installing add-on files unconditionally) is the fact that you can basically do it for free - you

Re: [gentoo-dev] Review: Apache AddHandler news item

2015-03-29 Thread Sebastian Pipping
Next round: * Recipe for handling \.(php|php5|phtml|phps)\. manually added * AddType (with similar problems) mentioned, too * Typo momment fixed (* Internel revision bump to 3, will be committed as revision 1) (* Date bumped to today) (* Links renumbered due to new link [2])