Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 22 Jan 2025 07:43:09 +0900
From:      Tomoaki AOKI <junchoon@dec.sakura.ne.jp>
To:        Brandon Allbery <allbery.b@gmail.com>
Cc:        Tomek CEDRO <tomek@cedro.info>, Warner Losh <imp@bsdimp.com>, bob prohaska <fbsd@www.zefox.net>, Sulev-Madis Silber <freebsd-current-freebsd-org111@ketas.si.pri.ee>, freebsd-current@freebsd.org
Subject:   Re: /usr/src and /usr/ports not git directories ?
Message-ID:  <20250122074309.9062de69d8403c68a11cd79a@dec.sakura.ne.jp>
In-Reply-To: <CAKFCL4XCijAsNJJw%2Bx_K%2B0M5VAebXLLWKoT%2BECT6J4wwVFNfCQ@mail.gmail.com>
References:  <Z4vk3009iSwuzG4K@www.zefox.net> <Z4__B0EQM-ce0qPE@cell.glebi.us> <C509F94C-2AC2-414F-90C0-355C69869D72@ketas.si.pri.ee> <Z5AQ1GcwX_MZw69G@www.zefox.net> <CANCZdfoHUsZusqMg_gWN5mB9P3xByGv_GfELi9Dd63CHto1igw@mail.gmail.com> <CAFYkXjk7PPHNiTJftGo980DABOO0t-rK9t%2BoPnLY-5n%2B1qjEAg@mail.gmail.com> <CAKFCL4XCijAsNJJw%2Bx_K%2B0M5VAebXLLWKoT%2BECT6J4wwVFNfCQ@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tue, 21 Jan 2025 17:11:02 -0500
Brandon Allbery <allbery.b@gmail.com> wrote:

> I would offer a data point: the first thing I did was install sudo from a
> package. The second thing I did was replace it with a build from the ports
> package installed with 14.2-RELEASE… which _downgraded_ it. This seems bad
> for any security-impacting port.

Do you mean that you install sudo from official "latest" repo, then,
`make package` in security/sudo with ports tree provided as ports.txz
in installation media?

If so, it could be latest/quarterly issue.


> 
> On Tue, Jan 21, 2025 at 4:37 PM Tomek CEDRO <tomek@cedro.info> wrote:
> 
> > On Tue, Jan 21, 2025 at 10:29 PM Warner Losh wrote:
> > > (..)
> > > I think we should replace the populate /usr/src from a tarball with....
> > populate it
> > > with a tarball that represents a 1-deep checkout tree at the rev we
> > built the release
> > > from. This lets users have the source, has minimal overhead and also
> > lets users update
> > > or turn the shallow checkout into a deep one, etc. A shallow checkout is
> > quite a bit
> > > less than a full tree, though still more than just the raw files. I've
> > not done poking to
> > > see size comparisons.
> >
> > Still having tarball of src and ports snapshots in the full release
> > images is important to have, users could select which one they want to
> > use, that seems best solution :-)
> >
> > --
> > CeDeROM, SQ7MHZ, http://www.tomek.cedro.info
> >
> >
> 
> -- 
> brandon s allbery kf8nh
> allbery.b@gmail.com


-- 
Tomoaki AOKI    <junchoon@dec.sakura.ne.jp>



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20250122074309.9062de69d8403c68a11cd79a>