Bug#318946: User expectations and shorewall

2005-09-16 Thread Martin Schulze
Lorenzo Martignoni wrote: > > If you can, please build an updated package, based on the version in > > sarge and woody if that's needed as well, and place them on a .debian.org > > host. > > I already have a fixed package. I only need to add the CVE ID. > > On which host of .debian.org should I u

Bug#318946: User expectations and shorewall

2005-09-16 Thread Lorenzo Martignoni
* Martin Schulze <[EMAIL PROTECTED]>: > Florian Weimer wrote: > > >> (Note that I have yet to test Lorenzo's new package.) > > > > > > Are you in a position to do so? > > > > Sure, but the question is if you want to rely on the results. You > > don't seem to trust my judgement on this matter, fo

Bug#318946: User expectations and shorewall

2005-09-15 Thread Martin Schulze
Florian Weimer wrote: > >> (Note that I have yet to test Lorenzo's new package.) > > > > Are you in a position to do so? > > Sure, but the question is if you want to rely on the results. You > don't seem to trust my judgement on this matter, for reasons I don't > know. I simply did not understan

Bug#318946: User expectations and shorewall

2005-09-06 Thread Lorenzo Martignoni
* Florian Weimer <[EMAIL PROTECTED]>: > * Lorenzo Martignoni: > > > The patch has been tested by me and by Paul Gear but further tests will > > be better, so your feedback will be very precious. > > Apart from the lack of CVE entry in the changelog, the package seems > to be fine. Both problem

Bug#318946: User expectations and shorewall

2005-09-06 Thread Florian Weimer
* Lorenzo Martignoni: > The patch has been tested by me and by Paul Gear but further tests will > be better, so your feedback will be very precious. Apart from the lack of CVE entry in the changelog, the package seems to be fine. Both problems are fixed. There is a surprising reduction of the

Bug#318946: User expectations and shorewall

2005-09-02 Thread Lorenzo Martignoni
* Florian Weimer <[EMAIL PROTECTED]>: > * Martin Schulze: > > >> > What was the behaviour pre-sarge? > >> > What is the behaviour post-sarge (or rather in sarge)? > >> > >> Do you mean "before and after the upstream security update"? The > >> terms pre-sarge/post-sarge do not make much sense to

Bug#318946: User expectations and shorewall

2005-09-02 Thread Florian Weimer
* Martin Schulze: >> > What was the behaviour pre-sarge? >> > What is the behaviour post-sarge (or rather in sarge)? >> >> Do you mean "before and after the upstream security update"? The >> terms pre-sarge/post-sarge do not make much sense to me in this >> context, I'm afraid. > > Ok, so when d

Bug#318946: User expectations and shorewall

2005-09-01 Thread Martin Schulze
Florian Weimer wrote: > * Martin Schulze: > > > What was the behaviour pre-sarge? > > What is the behaviour post-sarge (or rather in sarge)? > > Do you mean "before and after the upstream security update"? The > terms pre-sarge/post-sarge do not make much sense to me in this > context, I'm afrai

Bug#318946: User expectations and shorewall

2005-09-01 Thread Lorenzo Martignoni
* Florian Weimer <[EMAIL PROTECTED]>: > * Martin Schulze: > > > What was the behaviour pre-sarge? > > What is the behaviour post-sarge (or rather in sarge)? > > Do you mean "before and after the upstream security update"? The > terms pre-sarge/post-sarge do not make much sense to me in this > c

Bug#318946: User expectations and shorewall

2005-09-01 Thread Florian Weimer
* Martin Schulze: > What was the behaviour pre-sarge? > What is the behaviour post-sarge (or rather in sarge)? Do you mean "before and after the upstream security update"? The terms pre-sarge/post-sarge do not make much sense to me in this context, I'm afraid. > What do you think is the vulnera

Bug#318946: User expectations and shorewall

2005-09-01 Thread Martin Schulze
Florian Weimer wrote: > * Martin Schulze: > > > So a summary would be to leave the package as it is in sarge, right? > > Based on the facts, I reach the opposite conclusion. The upstream > changes should be merged. However, since easy workarounds are > possible, we might get away without code c

Bug#318946: User expectations and shorewall

2005-09-01 Thread Martin Schulze
Florian Weimer wrote: > As far as I understand it, from the perspective of the security team, > it is not clear if the upstream change breaks existing user > configurations. Users might rely on the current behavior and use it > to deliberately weaken the filter policy. This is a reasonable > ques

Bug#318946: User expectations and shorewall

2005-09-01 Thread Florian Weimer
* Martin Schulze: > So a summary would be to leave the package as it is in sarge, right? Based on the facts, I reach the opposite conclusion. The upstream changes should be merged. However, since easy workarounds are possible, we might get away without code changes, if issuing the update Lorenz

Bug#318946: User expectations and shorewall

2005-09-01 Thread Florian Weimer
As far as I understand it, from the perspective of the security team, it is not clear if the upstream change breaks existing user configurations. Users might rely on the current behavior and use it to deliberately weaken the filter policy. This is a reasonable question because the existing docume