Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #908736

Bug#813471: Seeking seconds for patch to permit some network access to localhost

From Sean Whitton <spwhitton@spwhitton.name>
Newsgroups linux.debian.bugs.dist, linux.debian.policy
Subject Bug#813471: Seeking seconds for patch to permit some network access to localhost
Date 2018-07-22 12:30 +0200
Message-ID <wejMJ-8qa-5@gated-at.bofh.it> (permalink)
References <weiQG-7NG-5@gated-at.bofh.it> <qXHD4-2bY-21@gated-at.bofh.it> <wejjH-7Zi-1@gated-at.bofh.it> <qXHD4-2bY-21@gated-at.bofh.it> <wejjH-7Zi-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Hello Niels,

On Sun 22 Jul 2018 at 09:33AM GMT, Niels Thykier wrote:

> The proposed text is awkward for me because I basically read it as:
>
> ""
> For packages in the main archive, no required targets may attempt
> network access, [... exception ...], via the loopback interface.
> """
>
> Which is not at all what I expected to read given the subject.

I don't follow what's awkward about this; please say more.

> Secondly, my reading of the text enables you to start tor and then talk
> with that (and it is not quite clear whether the exception also applies
> to the started service).

Good point.

I think the simplest way to address this is to say that the requirement
applies recursively.

> Maybe something like:
>
> """
> For packages in the main archive, no required targets may attempt
> network access (either directly or via services started by the build) on
> any interface except for the loopback interface.
> """

This text does not address Paul's point that package builds should not
talk to unrelated services on the host.

Given that I don't follow what you mean by awkward, I don't think I know
what you are trying to achieve with this new text, so I'll wait for a
reply to my first question.

-- 
Sean Whitton

Back to linux.debian.bugs.dist | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

Bug#813471: Seeking seconds for patch to permit some network access to localhost Sean Whitton <spwhitton@spwhitton.name> - 2018-07-22 11:30 +0200
  Bug#813471: Seeking seconds for patch to permit some network access to localhost David Bremner <david@tethera.net> - 2018-07-22 11:50 +0200
  Bug#813471: Seeking seconds for patch to permit some network access to localhost Niels Thykier <niels@thykier.net> - 2018-07-22 12:00 +0200
    Bug#813471: Seeking seconds for patch to permit some network access to localhost Sean Whitton <spwhitton@spwhitton.name> - 2018-07-22 12:30 +0200
      Bug#813471: Seeking seconds for patch to permit some network access to localhost Niels Thykier <niels@thykier.net> - 2018-07-22 12:50 +0200
        Bug#813471: Seeking seconds for patch to permit some network access to localhost Sean Whitton <spwhitton@spwhitton.name> - 2018-07-23 01:50 +0200
          Bug#813471: Seeking seconds for patch to permit some network access to localhost David Bremner <bremner@debian.org> - 2018-07-23 03:10 +0200
          Bug#813471: Seeking seconds for patch to permit some network access to localhost Niels Thykier <niels@thykier.net> - 2018-07-23 21:30 +0200
        Bug#813471: Seeking seconds for patch to permit some network access to localhost Paul Wise <pabs@debian.org> - 2018-07-23 05:30 +0200
          Bug#813471: Seeking seconds for patch to permit some network access to localhost Ian Jackson <ijackson@chiark.greenend.org.uk> - 2018-07-23 21:30 +0200
            Bug#813471: Seeking seconds for patch to permit some network access to localhost Paul Wise <pabs@debian.org> - 2018-07-24 02:10 +0200
  Bug#813471: Seeking seconds for patch to permit some network access to localhost Osamu Aoki <osamu@debian.org> - 2018-07-23 18:00 +0200

csiph-web