Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

I came, I saw, I deleted all your files.


computers / alt.os.linux.slackware / Re: Heads-up Slackware-current users: CVE-2024-3094

SubjectAuthor
* Heads-up Slackware-current users: CVE-2024-3094Sylvain Robitaille
`* Re: Heads-up Slackware-current users: CVE-2024-3094Sylvain Robitaille
 `* Re: Heads-up Slackware-current users: CVE-2024-3094noel
  `* Re: Heads-up Slackware-current users: CVE-2024-3094Rich
   `* Re: Heads-up Slackware-current users: CVE-2024-3094Henrik Carlqvist
    +* Re: Heads-up Slackware-current users: CVE-2024-3094Sam
    |`* Re: Heads-up Slackware-current users: CVE-2024-3094Rich
    | `- Re: Heads-up Slackware-current users: CVE-2024-3094Mike Small
    `* Re: Heads-up Slackware-current users: CVE-2024-3094Sylvain Robitaille
     +- Re: Heads-up Slackware-current users: CVE-2024-3094Rich
     `* Re: Heads-up Slackware-current users: CVE-2024-3094Auric__
      `* Re: Heads-up Slackware-current users: CVE-2024-3094Sylvain Robitaille
       +* Re: Heads-up Slackware-current users: CVE-2024-3094Sam
       |`* Re: Heads-up Slackware-current users: CVE-2024-3094Sylvain Robitaille
       | +* Re: Heads-up Slackware-current users: CVE-2024-3094Sam
       | |`* Re: Heads-up Slackware-current users: CVE-2024-3094Sylvain Robitaille
       | | `* Re: Heads-up Slackware-current users: CVE-2024-3094Sam
       | |  +* Re: Heads-up Slackware-current users: CVE-2024-3094Rich
       | |  |`* Re: Heads-up Slackware-current users: CVE-2024-3094Sam
       | |  | `* Re: Heads-up Slackware-current users: CVE-2024-3094Rich
       | |  |  `- Re: Heads-up Slackware-current users: CVE-2024-3094Sam
       | |  `* Re: Heads-up Slackware-current users: CVE-2024-3094Rich
       | |   `* Re: Heads-up Slackware-current users: CVE-2024-3094Sam
       | |    `- Re: Heads-up Slackware-current users: CVE-2024-3094Rich
       | `- Re: Heads-up Slackware-current users: CVE-2024-3094Jerry Peters
       `* Re: Heads-up Slackware-current users: CVE-2024-3094Auric__
        `- Re: Heads-up Slackware-current users: CVE-2024-3094Sam

Pages:12
Re: Heads-up Slackware-current users: CVE-2024-3094

<uupsgg$1kess$2@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=2265&group=alt.os.linux.slackware#2265

  copy link   Newsgroups: alt.os.linux.slackware
Path: i2pn2.org!i2pn.org!news.chmurka.net!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: ric...@example.invalid (Rich)
Newsgroups: alt.os.linux.slackware
Subject: Re: Heads-up Slackware-current users: CVE-2024-3094
Date: Fri, 5 Apr 2024 22:04:00 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 22
Message-ID: <uupsgg$1kess$2@dont-email.me>
References: <cone.1712105075.947550.526329.1004@monster.email-scan.com> <slrnv0rokj.idr.syl@elvira.therockgarden.ca> <cone.1712231074.581965.412781.1004@monster.email-scan.com> <slrnv0u41k.lnl.syl@elvira.therockgarden.ca> <cone.1712272880.58423.479444.1004@monster.email-scan.com> <uup7q4$1fi8n$1@dont-email.me> <cone.1712354260.870546.883058.1004@monster.email-scan.com>
Injection-Date: Fri, 05 Apr 2024 22:04:01 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="3b8ed155215b6d4ec970ef050f5bcd80";
logging-data="1719196"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19C0kUbAHfNewmOz/TXa4Zr"
User-Agent: tin/2.6.1-20211226 ("Convalmore") (Linux/5.15.139 (x86_64))
Cancel-Lock: sha1:fiePmrE3rHNUcDMssk1UZxchIcI=
 by: Rich - Fri, 5 Apr 2024 22:04 UTC

Sam <sam@email-scan.com> wrote:
> Rich writes:
>
>> It might also need a starting [main] (or some other name) to make it
>> fully valid, I've not tried running it through an ini parser. And,
>> ini
>
> There are other practical considerations. Yes, there are a couple of
> ini parsing libraries out there. Slackware has one, inih.
>
> But it's parse only.
>
> libyaml can read and create YAML files. That's important, since I
> need to autogenerate the configuration files for containers of all
> the imported initscripts. I don't write them out myself. I use
> libyaml to do it, so the formatting is guaranteed to be correct, and
> there's no uncertainty that libyaml won't be able to read it back.
> The example I gave was written via libyaml.

Ah, that does change the decision process of what to choose quite a
bit.

Re: Heads-up Slackware-current users: CVE-2024-3094

<cone.1712357816.379443.906015.1004@monster.email-scan.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=2266&group=alt.os.linux.slackware#2266

  copy link   Newsgroups: alt.os.linux.slackware
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: sam...@email-scan.com (Sam)
Newsgroups: alt.os.linux.slackware
Subject: Re: Heads-up Slackware-current users: CVE-2024-3094
Date: Fri, 05 Apr 2024 18:56:56 -0400
Organization: A noiseless patient Spider
Lines: 52
Message-ID: <cone.1712357816.379443.906015.1004@monster.email-scan.com>
References: <cone.1712231074.581965.412781.1004@monster.email-scan.com> <slrnv0u41k.lnl.syl@elvira.therockgarden.ca> <cone.1712272880.58423.479444.1004@monster.email-scan.com> <uup703$1f9nh$1@dont-email.me> <cone.1712353669.73362.883058.1004@monster.email-scan.com> <uupsbu$1kess$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed; delsp=yes; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Injection-Date: Fri, 05 Apr 2024 22:56:58 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="895f2020e2b4f0877b530a3da4b04ee9";
logging-data="1745381"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18IYjWA/gmuBAo3Tx0gieXF"
Cancel-Lock: sha1:vyGTP+0HdcsHzSvbt/t2ftGaFwc=
X-Mailer: https://www.courier-mta.org/cone/
X-Shameless-Plug: https://github.com/svarshavchik
Content-Disposition: inline
 by: Sam - Fri, 5 Apr 2024 22:56 UTC

Rich writes:

> Sam <sam@email-scan.com> wrote:
> > Rich writes:
> >
> >> Sam <sam@email-scan.com> wrote:
> >> > I distinctly recall this being one of the original sales pitches for
> >> > systemd: finally you can stop services reliably, and no more
> >> > headaches with rogue processes still churning and creating havoc.
> >>
> >> One of the earliest 'sales pitches' for systemd was "faster bootups"
> >> with the 'dependency based startup" systemd brought along.
> >
> > I do recall that too.
> >
> >> I seem to recall the "clean shutdown of services/daemons" part being
> >> tacked on later when "faster bootups" didn't gain the requisite
> >> traction.
> >
> > Then, I suppose, my identical sales pitch won't gain much traction either.
> > Especially since the imported initscripts' containers' serial sequencing
> > gets diligently replicated.
>
> Well, you are not starting with "faster booting" and then pivoting when
> it turns out that "faster booting" is not a big enough incentive to
> jump to your new system.

Given that it takes me seven seconds to boot Slackware 15, as is, I doubt
that there's a lot to be squeezed from that lemon. But it's there.

> But you are also fighting against the huge installed base of current
> systemd, and that will be difficult to dislodge (just as classic init
> took some time for systemd to dislodge) because for most, if what they
> have now works, they don't see a reason to switch.

I have no big illusions in that regard. And this is precisely why I picked
Slackware. It is quite feasible to take Slackware, and easily swap out init
without much of an effort. Either clone https://github.com/svarshavchik/vera
and build from source or download the precompiled slackware64 package and
use installpkg. Execute one command. Reboot. To go back to sysvinit execute
one command, reboot, execute a 2nd command. Now things are what they were
before, nothing has changed. I haven't verified every preinstalled service
in Slackware or in an additional package, but

This would be much harder with other systemd based distributions.

> Now, maybe you have an angle with Slackware, but for that you'd need to
> be conversing wth Patrick rather than us.

Maybe at some point I'll try. But that conversation would probably be much
more productive once I have a larger track record to point to.

Pages:12
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor