From owner-svn-ports-head@freebsd.org Wed Oct 4 11:49:34 2017 Return-Path: Delivered-To: svn-ports-head@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 320E1E36F9E; Wed, 4 Oct 2017 11:49:34 +0000 (UTC) (envelope-from theraven@FreeBSD.org) Received: from theravensnest.org (xvm-110-62.dc2.ghst.net [46.226.110.62]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "theravensnest.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id A88FC83000; Wed, 4 Oct 2017 11:49:33 +0000 (UTC) (envelope-from theraven@FreeBSD.org) Received: from c124.sec.cl.cam.ac.uk (c124.sec.cl.cam.ac.uk [128.232.18.124]) (authenticated bits=0) by theravensnest.org (8.15.2/8.15.2) with ESMTPSA id v94BbtPN087335 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Wed, 4 Oct 2017 11:37:55 GMT (envelope-from theraven@FreeBSD.org) Content-Type: text/plain; charset=us-ascii Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\)) Subject: Re: svn commit: r450898 - head/security/vuxml From: David Chisnall In-Reply-To: <20171003191620.GA99159@exodus.zi0r.com> Date: Wed, 4 Oct 2017 12:37:54 +0100 Cc: Cy Schubert , Mathieu Arnold , "ports-committers@freebsd.org" , "svn-ports-all@freebsd.org" , "svn-ports-head@freebsd.org" Content-Transfer-Encoding: quoted-printable Message-Id: <31BE1638-3115-4F25-810C-5CB91626E480@FreeBSD.org> References: <20171003185229.GA91081@exodus.zi0r.com> <201710031914.v93JESd2007316@slippy.cwsent.com> <20171003191620.GA99159@exodus.zi0r.com> To: Ryan Steinmetz X-Mailer: Apple Mail (2.3273) X-BeenThere: svn-ports-head@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the ports tree for head List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 04 Oct 2017 11:49:34 -0000 On 3 Oct 2017, at 20:16, Ryan Steinmetz wrote: >=20 >=20 > On (10/03/17 12:14), Cy Schubert wrote: >> In message <20171003185229.GA91081@exodus.zi0r.com>, Ryan Steinmetz = writes: >>>=20 >>>=20 >>> On (10/03/17 11:36), Cy Schubert wrote: >>> >Really? >>> > >>> >Looking at the code it's a 1m size limit. Put yourself in = sizelimit.conf and >>> you get 10x that, unless you put a size after your name. >>>=20 >>> Typo--is a transaction size limit that was triggered. >>=20 >> Yes. >>=20 >> Why delete the old entries? It's history. >>=20 >> Maybe we shouldn't keep the vuxml database in the ports tree, instead >> hosting the vuxml file on github instead of the port itself??? Just a >> thought. >>=20 >=20 > We (ports-secteam) were addressing a problem (people couldn't commit = new entries). >=20 > There is some investigative work going on now that will give us more = options in terms of dealing with growth. >=20 > More information will surface in the near future. In retrospect, it seems that putting this as a single file in the ports = tree was a bad idea, and the correct solution is to have individual XML = fragments that can be assembled into both one huge file of everything = and a smaller one for vulnerabilities in ports that have been shipped in = the last year. David