[Xorg] Egbert moves us back to HEAD

Roland Mainz roland.mainz at nrubsig.org
Fri Apr 23 18:15:20 PDT 2004


Keith Packard wrote:
> > Erm... I did not get any commit emails... how was the merge done ? Dark
> > magic ? :)
> 
> Yes indeed.  The fine syncmail script doesn't work when you commit changes
> through the file system, it only appears to work when you use ssh.

So someone can change the CVS repository and noone else will notice it ?
Nice... ;-(

> Egbert kludged around this by temporarily disabling the commit mails.

Does that mean when the service gets enabled again we will see commit
emails for all changes ?

> I think this could be fixed by using temporary files instead of pipes in
> the syncmail script, but that's always fraught with peril of symlink
> attacks.

Generally I think there should be some discussion whether a more secure
OS like Trusted Solaris (e.g. no omnipotent "root", a secure filesystem
etc., C2-grade security) should be used for the Freedesktop core
services... that would help to either eliminate or isolate issues like
that and their impact on other services.

----

Bye,
Roland

-- 
  __ .  . __
 (o.\ \/ /.o) roland.mainz at nrubsig.org
  \__\/\/__/  MPEG specialist, C&&JAVA&&Sun&&Unix programmer
  /O /==\ O\  TEL +49 2426 901568 FAX +49 2426 901569
 (;O/ \/ \O;)




More information about the xorg mailing list