All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jesse Pollard <jesse@cats-chateau.net>
To: Russell Coker <russell@coker.com.au>, selinux@tycho.nsa.gov
Subject: Re: Fwd: Re: SE Linux packages of login, sshd, tar, stat, findutils, fileutils, and [xkg]dm
Date: Sat, 1 Dec 2001 07:11:11 -0600	[thread overview]
Message-ID: <01120107111100.13153@tabby> (raw)
In-Reply-To: <20011201090046.5F55316F80@lyta.coker.com.au>

On Saturday 01 December 2001 03:00, Russell Coker wrote:
> On Sat, 1 Dec 2001 01:46, Jesse Pollard wrote:
> > > > Yes.  Sun is the only vendor I've come across that ships packages
> > > > that mess with /usr/local.  They seem to think that a Sun package of
> > > > bash for Solaris 2.6 (distributed from a Sun web site) should install
> > > > to /usr/local/bin while a package for Solaris 8.0 (distributed on the
> > > > install CDs) should be in /bin. This sort of thing really sucks when
> > > > you are trying to manage a network.
> > >
> > > OpenBSD also does this. bash is in /usr/local/bin even though it's not
> > > a port or a 3rd party piece, but an official package.
> > >
> > > I agree on that not being good practice. I don't know that rationale
> > > for these, though.
> >
> > I can give a rationale, but can't promise it as the real one...
> >
> > These "packages" are NOT part of Solaris. They are "contributed" packages
> > that may not be upgraded, may not be patched, nor are they required to
> > even work.
> >
> > The /bin and friends are part of Solaris. If they cause security
> > problems, then Sun is obliged to provide patches/updates. Not so for
> > /usr/local. If theres a problem, you remove or don't install them.
> >
> > The stuff in /usr/local is not contractually maintained....
>
> When an important security related package such as syslogd has a bug that
> allows it to be killed by users (or remotely killed if listening to the
> network) it's still not serious enough for Sun to fix it.  Solaris 2.6
> syslogd has been known as buggy for years and Sun have announced plans to
> never fix it.
>
> I'm sure that the contrib packages will get updated when there's an
> upstream fix for a security issue.
>
> I can't see any difference between the packages for /bin and the packages
> for /usr/local/bin in this regard.  If anything the ones in /usr/local/bin
> have better support I think.

I don't believe sun is supporting 2.6 at all now.  You will have to update the
OS to get any fixes. Unless some volunteer at sun (or elsewere) updates the
the "contributed" packages they won't be updated at all.

The difference is that Sun doesn't pay employees to work on packages for 
/usr/local. They do pay for the core distribution.

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2001-12-01 13:11 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2001-11-29 17:08 Fwd: Re: SE Linux packages of login, sshd, tar, stat, findutils, fileutils, and [xkg]dm Flood Randy Capt AFCA/TCAA
2001-11-29 18:04 ` Jose Nazario
2001-11-29 19:48 ` Achim D. Brucker
2001-11-30 19:13 ` Russell Coker
2001-11-30 22:17   ` Tom
2001-12-01  0:46     ` Jesse Pollard
2001-12-01  9:00       ` Russell Coker
2001-12-01 13:11         ` Jesse Pollard [this message]
2001-12-17 16:48   ` Dale Amon
2001-12-17 20:30     ` Russell Coker
  -- strict thread matches above, loose matches on Subject: below --
2001-11-27 21:20 Russell Coker
2001-11-28 13:28 ` Stephen Smalley
2001-11-29 12:37   ` Russell Coker
2001-11-29 13:27     ` Stephen Smalley
2001-11-29 16:02       ` Russell Coker
2001-11-29 18:14         ` Stephen Smalley

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=01120107111100.13153@tabby \
    --to=jesse@cats-chateau.net \
    --cc=russell@coker.com.au \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.