Re: news item: Introduction of app-alternatives/coreutils

Eli Schwartz <[email protected]>
Newsgroups gmane.linux.gentoo.devel
Message-ID <[email protected]>
On 3/22/26 8:16 PM, Michael Orlitzky wrote:
> On 2026-03-20 18:29:18, Eli Schwartz wrote:
>> GNU defaults are not currently expected to ever change. The proposal is
>> valid insomuch as Gentoo supports choice, including the choice to use
>> terrible, racy, buggy software like uutils. That is opt-in.
> 
> Is there any reason to think that these are secure? If I may presume
> to be typical, I am not willing to spend four hours compiling a 50
> megabyte "ls" to see if it has the same security issues that GNU
> coreutils already fixed.
> 
> (If anyone wants to check if the recursive chown/chgrp is depth-first,
> it sure doesn't look like it.)


Well, I'm sure you are aware this is entirely the wrong question to ask
-- instead we should ask whether we KNOW they are insecure, ref. the
security vulnerability Qualys discovered in uutils rm on which
oss-security thread you commented. :)

(the snap-confine one, for the record)

You are broadly correct -- I don't trust the codebase an inch to avoid
other such issues.


-- 
Eli Schwartz
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQTnFNnmK0TPZHnXm3qEp9ErcA0vVwUCacCZMwUDAAAAAAAKCRCEp9ErcA0vV80C
AP9ZvcmSWNmAzh28jDd70cFhy0MWU5X5mpkuJ4SE4IkWLgEA87CdTc+91MGRdRD9Ei02bzHsls9p
7u7SB/V90ARPzQk=
=iLj1
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.