Bug#1093650: Prebuilt binaries in QEMU source

2025-01-20 Thread Michael Tokarev
20.01.2025 23:53, Michael Tokarev wrote: 20.01.2025 23:49, Heinrich Schuchardt wrote: Hello Michael, I can understand that a maintainer cares about keeping his package buildable but system security is of even higher importance. The xz package has demonstrated the security impact of including

Bug#1093650: Prebuilt binaries in QEMU source

2025-01-20 Thread Michael Tokarev
20.01.2025 23:49, Heinrich Schuchardt wrote: Hello Michael, I can understand that a maintainer cares about keeping his package buildable but system security is of even higher importance. The xz package has demonstrated the security impact of including binaries of unchecked origin. Why do we

Bug#1093650: Prebuilt binaries in QEMU source

2025-01-20 Thread Heinrich Schuchardt
On 1/20/25 21:29, Michael Tokarev wrote: 20.01.2025 23:22, Heinrich Schuchardt wrote: Package: qemu-system-riscv Version: 1:9.2.0+ds-5 Severity: nomal The https://salsa.debian.org/qemu-team/qemu contains pre-built binaries. Binaries should always be built from source. What's the point in f

Bug#1093650: Prebuilt binaries in QEMU source

2025-01-20 Thread Michael Tokarev
20.01.2025 23:22, Heinrich Schuchardt wrote: Package: qemu-system-riscv Version: 1:9.2.0+ds-5 Severity: nomal The https://salsa.debian.org/qemu-team/qemu contains pre-built binaries. Binaries should always be built from source. What's the point in filing this bug report? Do you have a solu

Bug#1093650: Prebuilt binaries in QEMU source

2025-01-20 Thread Heinrich Schuchardt
Package: qemu-system-riscv Version: 1:9.2.0+ds-5 Severity: nomal The https://salsa.debian.org/qemu-team/qemu contains pre-built binaries. ./linux-user/ppc/vdso-64le.so ./linux-user/ppc/vdso-32.so ./linux-user/ppc/vdso-64.so ./linux-user/x86_64/vdso.so ./linux-user/hppa/vdso.so ./linux-user/loong