From: Andreas Oberritter <obi@opendreambox.org>
To: Martin Jansa <martin.jansa@gmail.com>
Cc: openembedded-devel@lists.openembedded.org
Subject: Re: [PATCH][meta-oe] samba: disable services for sysvinit
Date: Sun, 29 Mar 2015 16:35:11 +0200 [thread overview]
Message-ID: <55180D9F.3020604@opendreambox.org> (raw)
In-Reply-To: <54F7B0BC.7010203@windriver.com>
Hi Martin,
On 05.03.2015 02:26, wenzong fan wrote:
> On 03/04/2015 07:02 PM, Andreas Oberritter wrote:
>> On 04.03.2015 10:43, wenzong fan wrote:
>>> On 03/04/2015 05:12 PM, Andreas Oberritter wrote:
>>>> Dear Wenzong Fan,
>>>>
>>>> On 04.03.2015 07:18, wenzong.fan@windriver.com wrote:
>>>>> From: Wenzong Fan <wenzong.fan@windriver.com>
>>>>>
>>>>> The smb, nmb, winbind services have been disabled for systemd system
>>>>> by default, disable them for sysvinit as well.
>>>>
>>>> why would anybody install these services without the desire for using
>>>> them? Did the patch disabling them for systemd get merged by mistake? I
>>>> remember Paul objecting to it.
>>>
>>> The samba is not a common service that required by system, especially in
>>> some security environment, it should be configured correctly first -
>>> This is why I incline to disable it by default.
>>
>> This doesn't convince me, as the line you're drawing between samba and
>> other services seems to be chosen arbitrarily.
>>
>> "git grep INITSCRIPT_PARAMS.*disable" shows no results in both
>> openembedded-core and meta-openembedded (dizzy). So samba will be the
>> first and only service that's disabled by default and requires manual
>> intervention by the user? Why don't you ship a safe configuration
>> instead?
>>
>> As Paul stated, the distro is responsible for correct configuration.
>> IMHO there's no reason to deviate from common behaviour just because
>> samba seems to be less safe than any other network service in your view.
>>
>
> Ok, thanks for your advises, I agree with you.
>
> Please maintainer ignore my patch.
>
>>> Yes, it did - this may give me some hints that it should be disabled ...
>>
>> Unfortunately I don't understand what you're referring to here.
>
> Sorry for the confusion, it answered you second question about if "the
> patch disabling them for systemd get merged by mistake?".
>
> Yes, the patch for systemd has been merged - It gives me hint that it's
> a proper behavior for samba, but looks it isn't ...
>
> Please refer to the commit: 20a624928c030fa13d8b7d45b4f4d7e1ac624f60
>
> It should be reverted now!
You applied this patch to jansa/master. Would you mind reverting
20a624928c030fa13d8b7d45b4f4d7e1ac624f60 instead, as discussed in this
thread?
Regards,
Andreas
next prev parent reply other threads:[~2015-03-29 14:35 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-03-04 6:18 [PATCH][meta-oe] samba: disable services for sysvinit wenzong.fan
2015-03-04 9:12 ` Andreas Oberritter
2015-03-04 9:43 ` wenzong fan
2015-03-04 11:02 ` Andreas Oberritter
2015-03-05 1:26 ` wenzong fan
2015-03-29 14:35 ` Andreas Oberritter [this message]
2015-03-29 22:40 ` Martin Jansa
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55180D9F.3020604@opendreambox.org \
--to=obi@opendreambox.org \
--cc=martin.jansa@gmail.com \
--cc=openembedded-devel@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox