#917094 lintian: systemd-service-file-missing-hardening-features doesn't actually help

#917094#5
Date:
2018-12-22 14:20:22 UTC
From:
To:
Is lintian really an advertising medium for various package features?

This seems like something that would be better a subject of a blog post on
planet.d.o than a lintian tag.  I know it's just experimental, but I get to
see it 11 times if I go through the long version of my lintian report and it
is a bit overwhelming.  As discussed in other bugs, to much nonsense from
lintian makes it less useful overall.

I think this check should either be updated into some more specific checks for
specific conditions where packages can make use of some of these features or
removed.  As is, all it tells me is some day maybe I should carve out more
time to learn about systemd.

Scott K

#917094#10
Date:
2018-12-22 15:42:17 UTC
From:
To:
tags 917094 + moreinfo
thanks

Scott Kitterman wrote:

Come now, that's an unfortunately combative way of phrasing this. I
would agree if Lintian was suggesting a feature that was unrelated to
security and, perhaps, if it was arduous to implement.

However we are surely not really providing an "advertising" platform
for GCC's own hardening features when binaries are missing those,
something that is often rather complicated to achieve if upstream's
build system is uncooperative.

I don't necessarily disagree, but do you have any specific conditions
in mind at this stage?

Please do note that the experimental nature of this tag is precisely
so we can iron-out problems; requesting its almost-immediate removal
upon seeing potential false-positives when it is clearly marked as
such seems premature and suboptimal at this stage.


Regards,

#917094#17
Date:
2018-12-22 18:02:51 UTC
From:
To:
I didn't intend to be combative.  Sorry.  It isn't necessarily suggesting anything arduous to implement, I feel the research to decide what needs implementing probably is.

True, but I also recall a significant discussion within Debian about those hardening features.  I don't view those checks as particularly being about gcc.  They are about things that the project has some consensus is a good idea.

Not knowing much about this, I don't.

I didn't intend to argue for immediate removal.  I think it needs to evolve into something more useful and I get that will take time.

Scott K