Re: [gentoo-dev] Manifest2 hashes, take n+1-th: one hash to decide them all

2017-10-25 Thread Paweł Hajdan , Jr .
On 25/10/2017 14:32, Hanno Böck wrote: > Good security includes reducing complexity. Tough (as evident by this > thread) it's a thought many people find hard to accept. > > This thread is going into a completely different direction and I find > that worriesome. We have two non-problems ("what if se

Re: [gentoo-dev] [RFC] GLEP 65 v2: Post-install QA checks (now with post-merge checks)

2017-10-25 Thread Michał Górny
Here's v2.0.1 with suggestions from mjo applied. ReST: https://dev.gentoo.org/~mgorny/tmp/glep-0065.rst HTML: https://dev.gentoo.org/~mgorny/tmp/glep-0065.html --- GLEP: 65 Title: Post-install QA checks Author: Michał Górny Type: Standards Track Status: Draft Version: 2 Created: 2014-10-26 Last-

Re: [gentoo-dev] Manifest2 hashes, take n+1-th: one hash to decide them all

2017-10-25 Thread Hanno Böck
Hi, On Wed, 25 Oct 2017 02:40:58 + "Robin H. Johnson" wrote: > At that point, and this is a serious proposal: > The package manager shall decide which hashes to check, but is > required to check at least one hash. The choice may be 'fastest', > 'most secure', or any local factor. Sorry to c

Re: [gentoo-dev] [RFC] GLEP 65 v2: Post-install QA checks (now with post-merge checks)

2017-10-25 Thread Michael Orlitzky
On 10/25/2017 03:18 AM, Michał Górny wrote: >>> ... >>> The QA checks can inspect the installation image or live system >>> respectively, >> >> Respective to what? > > To the type of check, as explained later? If you want to help, then > please be specific instead of asking questions and expectin

Re: [gentoo-dev] [RFC] GLEP 65 v2: Post-install QA checks (now with post-merge checks)

2017-10-25 Thread Michał Górny
W dniu wto, 24.10.2017 o godzinie 17∶57 -0400, użytkownik Michael Orlitzky napisał: > On 10/17/2017 02:12 PM, Michał Górny wrote: > > > > Abstract > > > > > > ... > > The QA checks can inspect the installation image or live system > > respectively, > > Respective to what? To the type