|
|||||||||||
|
Re: [RFC] Alternative solution (was: r50470 - trunk/packages/kbd-chooser/debian)
From: Joey Hess <joeyh(at)debian.org>
Date: Tue Dec 18 2007 - 13:35:23 EST
Um, that's intended to be a standin for whatever is the name of the keymap file that d-i configures instead of console-* configuring. > Does not change the fact that the probability of anyone abusing that "hole" The number of times that people have used this reasoning and then gone on to have their security not-a-hole used in combination with some other security not-a-hole to exploit a system is somewhat larger than zero. My feeling is that the security community in general agrees with me -- I suspect we'd have no difficulty in getting a CVE number assigned for this security hole, aside perhaps from it not yet having been shipped in any released software. > That said, I totally agree that this is not something that should be Why is it better than simply testing for the keymap file's existance? > It would have been ever so nice if this discussion could have been taken I read the RFC immediatly after reading the commit message. It's holidays and I don't have a lot of time. I also prefer to have as little to do with console-* as possible.. > +# Avoid displaying console-data's keymap policy question I'm not sure what the resulting console-data/keymap/policy entry looks like in /var/cache/debconf/config.db. Does it have a sane template, or does copydb make it have debian-installer/dummy as the template? That would break later reconfiguration. Does it have the right owner? preseed's own base-installer script uses debconf-set-selections. echo "console-data console-data/keymap/policy seen true" | \ chroot /target debconf-set-selections -- see shy jo -- To UNSUBSCRIBE, email to debian-boot-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 03:48:09 EDT |
||||||||||
|
|||||||||||