Your message dated Mon, 11 Jan 2016 05:26:57 +0000
with message-id <[email protected]>
and subject line Bug#808289: Removed package(s) from unstable
has caused the Debian Bug report #733741,
regarding upstart: implement additional security features
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
733741: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733741
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: upstart

Upstart should provide additional security features, such as isolating
processes from the network using network namespaces, restricting file
system access, preventing the processes to regain privileges, system
call filters, private /tmp and limiting device access.

See also this part of Russ' mail on -ctte:

Russ Allbery <[email protected]> writes:
> * Security defense in depth.  Both upstart and systemd support the basics
>   (setting the user and group, process limits, and so forth).  However,
>   systemd adds a multitude of additional defense in depth features,
>   ranging from capability limits to private namespaces or the ability to
>   deny a job access to the network.  This is just a simple matter of
>   programming on the upstart side, but it still contributes to the general
>   feature deficit; the capabilities in systemd exist today.  I'm sure I'm
>   not the only systems administrator who is expecting security features
>   and this sort of defense in depth to become increasingly important over
>   the next few years.
>
>   Here again, I think we have an opportunity for Debian to be more
>   innovative and forward-looking in what we attempt to accomplish in the
>   archive by adopting frameworks that let us incorporate the principles of
>   least privilege and defense in depth into our standard daemon
>   configurations.

Ansgar

--- End Message ---
--- Begin Message ---
Version: 1.11-5+rm

Dear submitter,

as the package upstart has just been removed from the Debian archive
unstable we hereby close the associated bug reports.  We are sorry
that we couldn't deal with your issue properly.

For details on the removal, please see https://bugs.debian.org/808289

The version of this package that was in Debian prior to this removal
can still be found using http://snapshot.debian.org/.

This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
[email protected].

Debian distribution maintenance software
pp.
Scott Kitterman (the ftpmaster behind the curtain)

--- End Message ---

Reply via email to