From owner-cvs-all@FreeBSD.ORG Mon Aug 16 15:53:36 2004 Return-Path: Delivered-To: cvs-all@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9AA7E16A4CE; Mon, 16 Aug 2004 15:53:36 +0000 (GMT) Received: from gw.celabo.org (gw.celabo.org [208.42.49.153]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2F57343D1D; Mon, 16 Aug 2004 15:53:36 +0000 (GMT) (envelope-from nectar@celabo.org) Received: from localhost (localhost [127.0.0.1]) by gw.celabo.org (Postfix) with ESMTP id 9C7455487F; Mon, 16 Aug 2004 10:53:35 -0500 (CDT) Received: from gw.celabo.org ([127.0.0.1]) by localhost (hellblazer.celabo.org [127.0.0.1]) (amavisd-new, port 10024) with SMTP id 42946-02; Mon, 16 Aug 2004 10:53:24 -0500 (CDT) Received: from lum.celabo.org (dhcp-207.celabo.org [10.0.1.207]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client CN "lum.celabo.org", Issuer "celabo.org CA" (verified OK)) by gw.celabo.org (Postfix) with ESMTP id 5EBF55485D; Mon, 16 Aug 2004 10:53:24 -0500 (CDT) Received: by lum.celabo.org (Postfix, from userid 1001) id 24F6A3F398F; Mon, 16 Aug 2004 09:59:01 -0500 (CDT) Date: Mon, 16 Aug 2004 09:59:01 -0500 From: "Jacques A. Vidrine" To: Oliver Eikemeier Message-ID: <20040816145901.GB5482@lum.celabo.org> Mail-Followup-To: "Jacques A. Vidrine" , Oliver Eikemeier , cvs-all@FreeBSD.org, cvs-ports@FreeBSD.org, ports-committers@FreeBSD.org References: <20040815162939.GB3559@lum.celabo.org> <59A4C7E0-EEE2-11D8-87C4-00039312D914@fillmore-labs.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <59A4C7E0-EEE2-11D8-87C4-00039312D914@fillmore-labs.com> X-Url: http://www.celabo.org/ User-Agent: Mutt/1.5.6i cc: cvs-ports@FreeBSD.org cc: cvs-all@FreeBSD.org cc: ports-committers@FreeBSD.org Subject: Re: cvs commit: ports/security/portaudit-db/database portaudit.txt portaudit.xlist portaudit.xml X-BeenThere: cvs-all@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: CVS commit messages for the entire tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 16 Aug 2004 15:53:36 -0000 [Hmm, it seems that the lists that contain FreeBSD developers was accidently dropped. Fixed.] On Sun, Aug 15, 2004 at 07:41:34PM +0200, Oliver Eikemeier wrote: > Jacques A. Vidrine wrote: > > >The commit message seems to be incomplete. The 670% increase in > >portaudit.xml seems to be largely a number of entries that are also in > >ports/security/vuxml/vuln.xml, although the text and references seem to > >be rewritten in most (all?) cases and different UUIDs have been > >assigned. > > Yup, they use the UUIDs they had assigned in portaudit, before they have > been re-added with different UUIDs to vuxml. > > >I'm not sure what portaudit.xml is for, but it seems a bit confusing to > >have some issues described differently in two different locations. > >Maybe > >you could clue me in as to what is going on? Seems like we need to > >normalize this data. > > Those entries are tested and work with portaudit. It seems like vuxml > has different requirements. You keep making this assertion, but you have not given any details. What gives? For example, why have you duplicated the following entry: in ports/security/vuxml/vuln.xml ``acroread uudecoder input validation error'' http://vuxml.freebsd.org/78348ea2-ec91-11d8-b913-000c41e2cdad.html in ports/security/portaudit-db/database/portaudit.xml ``Acrobat Reader handling of malformed uuencoded pdf files'' http://people.freebsd.org/~eik/portaudit/ab166a60-e60a-11d8-9b0a-000347a4fa7d.html What is it about the original entry that does not "work with portaudit"? This is particularly confusing because you somehow claim that the original entry is "superseded" by yours. http://people.freebsd.org/~eik/portaudit/78348ea2-ec91-11d8-b913-000c41e2cdad.html Why didn't you simply correct the original entry if there is a problem? What are you trying to accomplish, Oliver? I would really like to know because clearly this situation is not good for our community. Cheers, -- Jacques A Vidrine / NTT/Verio nectar@celabo.org / jvidrine@verio.net / nectar@FreeBSD.org