Re: news item: Introduction of app-alternatives/coreutils
Eli Schwartz <[email protected]>
| Newsgroups | gmane.linux.gentoo.devel |
|---|---|
| Message-ID | <[email protected]> |
On 3/22/26 8:16 PM, Michael Orlitzky wrote: > On 2026-03-20 18:29:18, Eli Schwartz wrote: >> GNU defaults are not currently expected to ever change. The proposal is >> valid insomuch as Gentoo supports choice, including the choice to use >> terrible, racy, buggy software like uutils. That is opt-in. > > Is there any reason to think that these are secure? If I may presume > to be typical, I am not willing to spend four hours compiling a 50 > megabyte "ls" to see if it has the same security issues that GNU > coreutils already fixed. > > (If anyone wants to check if the recursive chown/chgrp is depth-first, > it sure doesn't look like it.) Well, I'm sure you are aware this is entirely the wrong question to ask -- instead we should ask whether we KNOW they are insecure, ref. the security vulnerability Qualys discovered in uutils rm on which oss-security thread you commented. :) (the snap-confine one, for the record) You are broadly correct -- I don't trust the codebase an inch to avoid other such issues. -- Eli Schwartz
OpenPGP_signature.asc
(application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE----- wnsEABYIACMWIQTnFNnmK0TPZHnXm3qEp9ErcA0vVwUCacCZMwUDAAAAAAAKCRCEp9ErcA0vV80C AP9ZvcmSWNmAzh28jDd70cFhy0MWU5X5mpkuJ4SE4IkWLgEA87CdTc+91MGRdRD9Ei02bzHsls9p 7u7SB/V90ARPzQk= =iLj1 -----END PGP SIGNATURE-----