NetBSD Problem Report #35281
From firstname.lastname@example.org Tue Dec 19 15:26:51 2006
Received: from mail.netbsd.org (mail.netbsd.org [188.8.131.52])
by narn.NetBSD.org (Postfix) with ESMTP id 109BA63BA6D
for <gnats-bugs@gnats.NetBSD.org>; Tue, 19 Dec 2006 15:26:51 +0000 (UTC)
Date: Tue, 19 Dec 2006 10:26:50 -0500 (EST)
Subject: pkg-vulnerabilities can be garbage collected
>Synopsis: pkg-vulnerabilities can be garbage collected
>Arrival-Date: Tue Dec 19 15:30:00 +0000 2006
>Last-Modified: Tue Dec 19 16:00:02 +0000 2006
>Originator: Perry E. Metzger
>Release: NetBSD 4.99.3
Perry E. Metzger email@example.com
"Ask not what your country can force other people to do for you..."
System: NetBSD hackworth 4.99.3 NetBSD 4.99.3 (HACKWORTH) #0: Fri Oct 27 14:05:48 EDT 2006 perry@hackworth:/usr/obj/sys/arch/i386/compile/HACKWORTH i386
The "pkg-vulnerabilities" file contains lines that effectively can be
summarized as "don't use versions of a package below version X". When
there are lots of lines with a strict "<" relation, all but the last
one are effectively redundant.
Currently, policy is to keep all lines, vis:
# Note: NEVER remove entries from this file; this should document *all*
# known package vulnerabilities so it is entirely appropriate to have
# multiple entries in this file for a single package.
I would propose that this is not strictly necessary. For any package
with multiple "<" lines, only two really need be kept -- the most
recent one, and the last one before, with the vulnerability listed
changed to some sort of indicator of "multiple vulnerabilities". Why
keep a second line? Just so people are aware that the most recent vuln
is not the only one.
However, there is no reason to have five or eight or fifteen or in
some cases over 30 lines for a given package. No real security purpose
is served by this, and it often ends up clogging the user's email if
they're running the nightly vuln audit so much that they can't really
figure out what's in need of fixing.
Also, the longer the file is, the more of a burden it is on our
machines for large numbers of users to be downloading it nightly, and
right now the file is (by my calculations) something like twice as
large as it needs to be.
From: "Jeremy C. Reed" <firstname.lastname@example.org>
Subject: Re: pkg/35281: pkg-vulnerabilities can be garbage collected
Date: Tue, 19 Dec 2006 09:59:13 -0600 (CST)
Maybe add an option to only display the latest two vulnerabilities for
Keeping all in list makes it convenient for end-user to know if any of the
vulnerabilities are of concern and also for pkgsrc developers so they can
quickly see if some issues have been resolved or not.
By the way, the custom audit-packages I use sorts the output with | sort
-f so is easier to read.
$NetBSD: query-full-pr,v 1.36 2007/11/24 03:27:39 kano Exp $
$NetBSD: gnats_config.sh,v 1.8 2006/05/07 09:23:38 tsutsui Exp $
Copyright © 1994-2007
The NetBSD Foundation, Inc. ALL RIGHTS RESERVED.