GNU bug report logs

#48146 Getting diverted to non-updated branches: a limitation of the authentication mechanism?

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #8 received at 48146@debbugs.gnu.org (full text, mbox, reply):

Received: (at 48146) by debbugs.gnu.org; 2 May 2021 04:10:00 +0000
From debbugs-submit-bounces@debbugs.gnu.org Sun May 02 00:10:00 2021
Received: from localhost ([127.0.0.1]:40176 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1ld3Qe-0000vF-DP
	for submit@debbugs.gnu.org; Sun, 02 May 2021 00:10:00 -0400
Received: from out1-smtp.messagingengine.com ([66.111.4.25]:55287)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <leo@famulari.name>) id 1ld3Qc-0000v9-MJ
 for 48146@debbugs.gnu.org; Sun, 02 May 2021 00:09:59 -0400
Received: from compute1.internal (compute1.nyi.internal [10.202.2.41])
 by mailout.nyi.internal (Postfix) with ESMTP id 65D815C008E;
 Sun,  2 May 2021 00:09:53 -0400 (EDT)
Received: from mailfrontend1 ([10.202.2.162])
 by compute1.internal (MEProxy); Sun, 02 May 2021 00:09:53 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name;
 h=date:from:to:cc:subject:message-id:references:mime-version
 :content-type:in-reply-to; s=mesmtp; bh=1PSugU2mDsXbSFpntfqdMcMr
 maH4dEOYoqxXaWTU57E=; b=DLUjoNYDt4SnnUb1HG0lvIDqCQWyIw6DaZVm4QPN
 9j9H1yyH+OoxMYerQuT2B9mmwhTFGXWvLFUxaIPfnV/jljoqwGkg7D7CDAN3RJb/
 DF38spE+cW02ScAGtRQWDZD28VSxMeHDwDasLfAnUaWR9CLKxEL4U6H1eukRCuwl
 uuo=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=cc:content-type:date:from:in-reply-to
 :message-id:mime-version:references:subject:to:x-me-proxy
 :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; bh=1PSugU
 2mDsXbSFpntfqdMcMrmaH4dEOYoqxXaWTU57E=; b=PfLstv95m+JdzOyHLXEwNb
 QJm/CKsZHjBP+ZKCK3qyV3Y3hEnBrFMK3Kv7CbU/3qz3TCGNs8y4QK7EMzVQhKdH
 JEQJLLDlqO1GJni5ws8kv9rtSPdN9ujTb5FMgAk9Zp+6qvryWxeqhbXoYQji+5WA
 3pzyEobr5YN5orh9WbAZ9BvPeKw0hDGcBqB4lkXlg5focjPkVC+k7hgXkuLGRejL
 m4DxkvTwfCEwmPzIhN5PYYmB/0zo0Z92yZYV492Je1Bl0qZXW9fUqZF6l7qMtm+w
 wvy7LZvm4a0blDU58S4WqWoE12j1xyCcriHdvbsxJ/aRErlq6/0JTpRwM8dLyPTw
 ==
X-ME-Sender: <xms:ECaOYLIdUSB5mNaI4oa0Ji8hpej7gJ7TlcBbt_LLe0Qa747_4az6fg>
 <xme:ECaOYPKsRafRo4WtsEmF09FbgeCdNxDN98MqiS2fAoJcQt7J11B-QEL5Ibsp64YrC
 M7mOD-OObaFHVrPiQ>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrvdefuddgtdduucetufdoteggodetrfdotf
 fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen
 uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne
 cujfgurhepfffhvffukfhfgggtuggjsehttdertddttddvnecuhfhrohhmpefnvghoucfh
 rghmuhhlrghrihcuoehlvghosehfrghmuhhlrghrihdrnhgrmhgvqeenucggtffrrghtth
 gvrhhnpeeiffekieejudefueefheeggfdtteethfevgefhtdehfefhfefgleeihfefkeel
 teenucffohhmrghinhepghhnuhdrohhrghdpthhhvghuphgurghtvghfrhgrmhgvfihorh
 hkrdhiohenucfkphepudeivddrvddujedrfeefrdduuddvnecuvehluhhsthgvrhfuihii
 vgeptdenucfrrghrrghmpehmrghilhhfrhhomheplhgvohesfhgrmhhulhgrrhhirdhnrg
 hmvg
X-ME-Proxy: <xmx:ECaOYDtnhBSpOyRt97vmnLsS4VqustuIUXW2SxAgm-GwHtpQGvcX-g>
 <xmx:ECaOYEZiZkpMyUbpFeafFyc4Rx1mHNqdyaDaJq8vELEJ-g0Zq4VvKw>
 <xmx:ECaOYCaArjIufqPwweYYEYgeuwTq-SQupTD0fy2Hts4CfvymYI4-Bw>
 <xmx:ESaOYA3MI5P7kOjIHMHdW5nsphIVHrfJb4M-S2ueyAO4P8yL3xipvQ>
Received: from localhost (d-162-217-33-112.ct.cpe.atlanticbb.net
 [162.217.33.112]) by mail.messagingengine.com (Postfix) with ESMTPA;
 Sun,  2 May 2021 00:09:52 -0400 (EDT)
Date: Sun, 2 May 2021 00:09:50 -0400
From: Leo Famulari <leo@famulari.name>
To: Maxime Devos <maximedevos@telenet.be>
Subject: Re: bug#48146: Getting diverted to non-updated branches: a
 limitation of the authentication mechanism?
Message-ID: <YI4mDjRZGFfLEzja@jasmine.lan>
References: <b3c137f53eb256d43267e2358874bd25e4686e32.camel@telenet.be>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <b3c137f53eb256d43267e2358874bd25e4686e32.camel@telenet.be>
X-Spam-Score: -0.7 (/)
X-Debbugs-Envelope-To: 48146
Cc: 48146@debbugs.gnu.org
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.7 (-)
On Sat, May 01, 2021 at 11:40:01PM +0200, Maxime Devos wrote:
> Tags: + security
> 
> Hi guix,
> 
> Consider the following situation:

Check this blog post and The Update Framework's concept of "indefinite
freeze attacks", which I think is what you are describing:

https://guix.gnu.org/en/blog/2020/securing-updates/
https://theupdateframework.io/ (check the "specification")




Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sun Dec 22 04:14:49 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.