Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 4 Oct 2017 12:37:54 +0100
From:      David Chisnall <theraven@FreeBSD.org>
To:        Ryan Steinmetz <zi@FreeBSD.org>
Cc:        Cy Schubert <Cy.Schubert@komquats.com>, Mathieu Arnold <mat@FreeBSD.org>,  "ports-committers@freebsd.org" <ports-committers@freebsd.org>, "svn-ports-all@freebsd.org" <svn-ports-all@freebsd.org>, "svn-ports-head@freebsd.org" <svn-ports-head@freebsd.org>
Subject:   Re: svn commit: r450898 - head/security/vuxml
Message-ID:  <31BE1638-3115-4F25-810C-5CB91626E480@FreeBSD.org>
In-Reply-To: <20171003191620.GA99159@exodus.zi0r.com>
References:  <zi@FreeBSD.org> <20171003185229.GA91081@exodus.zi0r.com> <201710031914.v93JESd2007316@slippy.cwsent.com> <20171003191620.GA99159@exodus.zi0r.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On 3 Oct 2017, at 20:16, Ryan Steinmetz <zi@FreeBSD.org> wrote:
>=20
>=20
> On (10/03/17 12:14), Cy Schubert wrote:
>> In message <20171003185229.GA91081@exodus.zi0r.com>, Ryan Steinmetz =
writes:
>>>=20
>>>=20
>>> On (10/03/17 11:36), Cy Schubert wrote:
>>> >Really?
>>> >
>>> >Looking at the code it's a 1m size limit. Put yourself in =
sizelimit.conf and
>>> you get 10x that, unless you put a size after your name.
>>>=20
>>> Typo--is a transaction size limit that was triggered.
>>=20
>> Yes.
>>=20
>> Why delete the old entries? It's history.
>>=20
>> Maybe we shouldn't keep the vuxml database in the ports tree, instead
>> hosting the vuxml file on github instead of the port itself??? Just a
>> thought.
>>=20
>=20
> We (ports-secteam) were addressing a problem (people couldn't commit =
new entries).
>=20
> There is some investigative work going on now that will give us more =
options in terms of dealing with growth.
>=20
> More information will surface in the near future.

In retrospect, it seems that putting this as a single file in the ports =
tree was a bad idea, and the correct solution is to have individual XML =
fragments that can be assembled into both one huge file of everything =
and a smaller one for vulnerabilities in ports that have been shipped in =
the last year.

David




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?31BE1638-3115-4F25-810C-5CB91626E480>