Re: Patch Pilot Report 2011-05-25

2011-05-26 Thread Martin Pitt
Benjamin Drung [2011-05-26 18:48 +0200]: > All done except the following, because I can't change the status for it. > > > https://code.launchpad.net/~smoser/ubuntu/natty/sudo/lp-768625/+merge/58762 > > (mvo uploaded to proposed) Set to "merged". Martin -- Martin Pitt|

Re: Enabling the kernel's DMESG_RESTRICT feature

2011-05-26 Thread Kees Cook
On Wed, May 25, 2011 at 11:49:45AM -0700, Steve Langasek wrote: > On Tue, May 24, 2011 at 11:46:48AM -0700, Kees Cook wrote: > > In Oneiric, I'd like to change the default availability of yet another > > long-standing system debugging feature: dmesg. > > I think this is a bridge too far. dmesg is

Re: Enabling the kernel's DMESG_RESTRICT feature

2011-05-26 Thread Kees Cook
On Thu, May 26, 2011 at 04:41:04PM +0100, Matt Zimmerman wrote: > On Tue, May 24, 2011 at 11:46:48AM -0700, Kees Cook wrote: > > As we have continued to close kernel address leaks, the kernel syslog > > (dmesg) remains one of the last large places where information is being > > reported. As such, I

Re: Enabling the kernel's DMESG_RESTRICT feature

2011-05-26 Thread Kees Cook
On Wed, May 25, 2011 at 09:37:47PM +0200, Martin Pitt wrote: > Kees Cook [2011-05-25 12:05 -0700]: > > Currently, the upstream kernel folks have rejected filtering printk. > > That's not actually what I meant. Don't filter the outputs of printk() > with some regexps. I meant "just kill the printk(

Re: Enabling the kernel's DMESG_RESTRICT feature

2011-05-26 Thread Kees Cook
On Wed, May 25, 2011 at 09:36:16PM +0200, Martin Pitt wrote: > So if needed, you can implement attach_dmesg() with > attach_root_command_outputs(). Ah, perfect. That'll be the way to go, then. > But aside from that I do agree with Steve that it both seems a lot > safer as well as more convenient

Re: Enabling the kernel's DMESG_RESTRICT feature

2011-05-26 Thread Clint Byrum
Excerpts from Kees Cook's message of Wed May 25 10:01:12 -0700 2011: > On Wed, May 25, 2011 at 08:07:14AM -0400, Scott Kitterman wrote: > > On Tuesday, May 24, 2011 06:00:17 PM Clint Byrum wrote: > > > Excerpts from Kees Cook's message of Tue May 24 11:46:48 -0700 2011: > > > > One unresolved probl

ANNOUNCE: Linaro Plan Reviews (May 31st to June 8th)

2011-05-26 Thread Christian Robottom Reis
Hello there, Starting next Tuesday, May 31st, Linaro tech leads will be running a set of public phone calls to present official plans for our engineering units. Calls are daily at 15:00 UTC, and there are local dial-in numbers for most countries around the world. Schedule and details are liste

Re: Patch Pilot Report 2011-05-25

2011-05-26 Thread Benjamin Drung
Am Donnerstag, den 26.05.2011, 09:45 -0400 schrieb Stéphane Graber: > The following should be removed from the sponsor list: > [...] All done except the following, because I can't change the status for it. > https://code.launchpad.net/~smoser/ubuntu/natty/sudo/lp-768625/+merge/58762 > (mvo uploa

Re: Enabling the kernel's DMESG_RESTRICT feature

2011-05-26 Thread Matt Zimmerman
On Tue, May 24, 2011 at 11:46:48AM -0700, Kees Cook wrote: > As we have continued to close kernel address leaks, the kernel syslog > (dmesg) remains one of the last large places where information is being > reported. As such, I want to close this off from regular users so that > local kernel exploi

Patch Pilot Report 2011-05-25

2011-05-26 Thread Stéphane Graber
Hello, Commented: - bug 766559 (icedtea-web depending only on firefox): Not clear why we'd even depend on a browser for this, can't we just suggest them like in flashplugin-installer? (left a comment) Uploaded: - bug 787977 (indicator plugin for xfce when panel is vertical): Reviewed upstream f