Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-25 Thread Sean Whitton
control: tag -1 -patch +pending Hello Paul, Ian, It looks like we have a clear consensus that my patch is fine, but while it might be that there is further loosening of the restriction on network access that should be done in addition to my patch, we do not know exactly what yet. So I'm applying

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-24 Thread Ian Jackson
Paul Wise writes ("Re: Bug#813471: Seeking seconds for patch to permit some network access to localhost"): > Sean and I discussed this at DebCamp and he mentioned that udeb > building packages have an exception from (most?) of policy, so we > probably do not need this particul

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-23 Thread Paul Wise
On Mon, 2018-07-23 at 20:16 +0100, Ian Jackson wrote: > LGTM. It might be worth saying "the apt repository (both source and > binaries)". There are both packages which fetch .debs explicitly, and > packages which fetch sources explicitly (yes, this is not very good, > but consensus in a discussi

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-23 Thread Ian Jackson
Paul Wise writes ("Bug#813471: Seeking seconds for patch to permit some network access to localhost"): > For clarity, how about we separate the two types of network access? > > In addition, d-i relies on access to the apt repo for the system. > I can imagine other uses

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-23 Thread Niels Thykier
Sean Whitton: > Here is a revised patch; David, hopefully you will renew your second. > >> diff --git a/policy/ch-source.rst b/policy/ch-source.rst >> index 9e7d79c..890c479 100644 >> --- a/policy/ch-source.rst >> +++ b/policy/ch-source.rst >> @@ -278,7 +278,8 @@ non-interactive. It also follows t

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-23 Thread Osamu Aoki
On Sun, Jul 22, 2018 at 05:19:14PM +0800, Sean Whitton wrote: > control: tag -1 +patch > > Hello, > > Here is a patch, for which I am seeking seconds, that tries to capture > the points raised by Osamu, Guillem and Paul without getting into > legalese -- Bill has a point. In particular, I think

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-22 Thread Paul Wise
On Sun, 2018-07-22 at 10:41 +, Niels Thykier wrote: > Basically I read "No required target may attempt network access via the > loopback interface (except if/when ...).". To me that implies /only/ > the loopback interface is restricted by that sentence (i.e. any other > network interface is n

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-22 Thread David Bremner
Sean Whitton writes: > > Here is a revised patch; David, hopefully you will renew your second. > >> diff --git a/policy/ch-source.rst b/policy/ch-source.rst >> index 9e7d79c..890c479 100644 >> --- a/policy/ch-source.rst >> +++ b/policy/ch-source.rst >> @@ -278,7 +278,8 @@ non-interactive. It also

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-22 Thread Sean Whitton
[dropping some CCs] Hello, On Sun 22 Jul 2018 at 10:41AM GMT, Niels Thykier wrote: > Basically I read "No required target may attempt network access via the > loopback interface (except if/when ...).". To me that implies /only/ > the loopback interface is restricted by that sentence (i.e. any o

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-22 Thread Niels Thykier
Sean Whitton: > Hello Niels, > > On Sun 22 Jul 2018 at 09:33AM GMT, Niels Thykier wrote: > >> The proposed text is awkward for me because I basically read it as: >> >> "" >> For packages in the main archive, no required targets may attempt >> network access, [... exception ...], via the loopback

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-22 Thread Sean Whitton
Hello Niels, On Sun 22 Jul 2018 at 09:33AM GMT, Niels Thykier wrote: > The proposed text is awkward for me because I basically read it as: > > "" > For packages in the main archive, no required targets may attempt > network access, [... exception ...], via the loopback interface. > """ > > Which

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-22 Thread Niels Thykier
Sean Whitton: > control: tag -1 +patch > > Hello, > > Here is a patch, for which I am seeking seconds, that tries to capture > the points raised by Osamu, Guillem and Paul without getting into > legalese -- Bill has a point. In particular, I think we can trust > package maintainers to interpret

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-22 Thread David Bremner
Sean Whitton writes: > control: tag -1 +patch > > Hello, > > Here is a patch, for which I am seeking seconds, that tries to capture > the points raised by Osamu, Guillem and Paul without getting into > legalese -- Bill has a point. In particular, I think we can trust > package maintainers to int

Bug#813471: Seeking seconds for patch to permit some network access to localhost

2018-07-22 Thread Sean Whitton
control: tag -1 +patch Hello, Here is a patch, for which I am seeking seconds, that tries to capture the points raised by Osamu, Guillem and Paul without getting into legalese -- Bill has a point. In particular, I think we can trust package maintainers to interpret "started by the build" sensibl