[Xorg] Egbert moves us back to HEAD
Roland Mainz
roland.mainz at nrubsig.org
Fri Apr 23 18:15:20 PDT 2004
Keith Packard wrote:
> > Erm... I did not get any commit emails... how was the merge done ? Dark
> > magic ? :)
>
> Yes indeed. The fine syncmail script doesn't work when you commit changes
> through the file system, it only appears to work when you use ssh.
So someone can change the CVS repository and noone else will notice it ?
Nice... ;-(
> Egbert kludged around this by temporarily disabling the commit mails.
Does that mean when the service gets enabled again we will see commit
emails for all changes ?
> I think this could be fixed by using temporary files instead of pipes in
> the syncmail script, but that's always fraught with peril of symlink
> attacks.
Generally I think there should be some discussion whether a more secure
OS like Trusted Solaris (e.g. no omnipotent "root", a secure filesystem
etc., C2-grade security) should be used for the Freedesktop core
services... that would help to either eliminate or isolate issues like
that and their impact on other services.
----
Bye,
Roland
--
__ . . __
(o.\ \/ /.o) roland.mainz at nrubsig.org
\__\/\/__/ MPEG specialist, C&&JAVA&&Sun&&Unix programmer
/O /==\ O\ TEL +49 2426 901568 FAX +49 2426 901569
(;O/ \/ \O;)
More information about the xorg
mailing list