Re: RFC: Removing WITHOUT_CAPSICUM and WITHOUT_CASPER from 14.x

Gordon Bergling <[email protected]>
Newsgroups gmane.os.freebsd.architechture
Message-ID <[email protected]>
Hi Colin,

On Thu, Feb 16, 2023 at 04:53:43AM +0000, Colin Percival wrote:
> Hi FreeBSD architects,
> 
> I'd like to remove WITHOUT_CAPSICUM and WITHOUT_CASPER for FreeBSD 14.x.
> 
> The rationale for this is threefold:
> 
> 1. They doesn't serve any useful purpose and merely weakens security;
> 
> 2. They're an anomaly among WITH/WITHOUT options -- most WITHOUT_* options
> take the form "don't build/install <components>" rather than having
> effects across the entire tree.
> 
> 3. They're a pain for release engineering, because approximately nobody ever
> tests FreeBSD with WITHOUT_CAPSICUM or WITHOUT_CASPER set, but they're the
> sort of option which can easily break the build due to having affects all
> over the tree.
> 
> If nobody objects, my plan is to get rid of the WITHOUT_ build options first
> and leave MK_{CAPSICUM,CASPER} set unconditionally to "yes"; then sweep the
> tree (mostly a matter of running unifdef) after 14.x is branched.

I would think that this a good idea, besides from the release engineering point
of view I can't think about a business case where security measures should be
disabled.

--Gordon
signature.asc (application/pgp-signature, 618 B)
-----BEGIN PGP SIGNATURE-----

iQGTBAEBCgB9FiEEYbWI0KY5X7yH/Fy4OQX2V8rP09wFAmPt6SxfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYx
QjU4OEQwQTYzOTVGQkM4N0ZDNUNCODM5MDVGNjU3Q0FDRkQzREMACgkQOQX2V8rP
09x8HggAtS99Oxwq+aJc7xbyFWPR12QaSzNU+ZHj0XcE/+pcsSP838lzjYJovlhO
36lRTz973HHfpNaoRc/gWADWiyNrqRxoqKBUvBK36UmwBLlpW5I65yaoXlIwg4HC
JoRmGs8EqPV6+ENcfmc+G2ueoKFeBN/D3o0+OairSaYpqZ9ram9ezeghnowE0Db2
XYdUb2BhGqdyzZdapKfUFGLNmrVJmRVj4ibm1Cs4il+H/MZjfTV+F5HQjPJuYOzG
hYt3juaLXuagwH6nqshmOz7nNmSu6cMcNFrZTpRwFqopwy13tkwLReLk9vH+j3iE
gIgGrPAZdVdwCSEd5e5C83024KNcQQ==
=HqYv
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.