At the end of last year I wrote about jailexec, my Ansible connection plugin that manages FreeBSD jails by SSHing to the jail host and running everything through jexec. That article has a section called Security Design. It proudly explains the two-stage file transfer: upload to a temporary location on the host, then move it into the jail with privilege escalation.

 

Last month while sitting in a cafe, my friend Andrew showed me an article about a quirky new E Ink device that was launching (we're both huge fans of the technology). It was cheap enough to be impulse purchase material, so I went to order it. And on the checkout page, something happened which has literally never happened to me... ever... I saw a "you might also like" style sales pitch, and the product was actually so compelling that I bought it 😱 The company was basically nerd sniping me.

 

This whole thing started because of Stefano and his blog. His guide to installing Void Linux on an encrypted ZFS root with hibernation support was the thing that got me curious enough to actually try it — and, as these things go, curiosity turned into an afternoon spent repartitioning a laptop I use every day. My setup below is simpler than his (no LUKS-encrypted swap, no hibernation), because I just wanted ZFS-on-root dual-booted alongside my existing FreeBSD/GhostBSD/OpenBSD rEFInd menu, but the bones of the approach — and the credit for pointing me at zfsbootmenu in the first place — are his.

submitted 2 weeks ago by to c/freebsd@lemmy.ml
 

The standard answer to brute force costs a hundred megabytes of interpreter and twenty-seven regular expressions, to work out something the daemon already knew. There are three other answers, and two of them were running before I installed anything. The Bench Marker.

[–] [S] 1 point 4 months ago

I understand your point about FrankenDebian. Personally, I don’t think that’s the issue in these contexts.

I don’t have the answer to your question; you’ll need to check with the project leads.

Edit: I’m not familiar with backports-sloppy

  • source
  • parent
  • context
  • [–] [S] 3 points 4 months ago* (last edited 4 months ago) (2 children)

    As far as I can tell, it would seem so; let me explain:

    • backports are Debian Team official

    • extrepo is managed by Debian Team officially, since 2019/11, to offers packages not included on Stable, Testing; Debian Team is responsible for officially integrating unofficial third-party repositories to the Stable branch; the process involves checking and verifying that the third-party repository is ‘clean’—as far as possible—or, rather, free from malicious code or malware; The manager of a third-party repository is responsible for its contents.

    • Debian Fast Track is an alternative repository to package for Stable branch, officially, since 2018/12. See:

    • Fast Forward Debian is an initiative of Daniel Baumann — who is a Debian developer, his DDPO, since 2025/12; this is considered by Debian Team officially as Debian derivative distribution — which means that the DFSG must be strictly adhered to!

    extrepo, Debian Fast (Track|Forward] are managed on Debian Infrastructure!

    So, unless I am mistaken, it is safe to say that yes, these third-party projects meet the same standards and quality requirements as the official project.

  • source
  • parent
  • context
  • [–] [S] 3 points 4 months ago (4 children)

    There is no problem with using the backports repositories or apps. The point is that sometimes, even in the backports archive, certain software are no longer maintained; this is the case with tilde, for example, which is still maintained for Testing and Sid… or not at all.

    Instead of installing apps, the Debian team or certain team members have set up official system for managing software that has been ported, either because it is too recent or due to licensing issues, via the Fast (Track|Forward) and extrepo repositories.

    This is why you’ll find a number of packages in these ‘official’ repositories that are not, or are no longer, in the stable repositories.

    This doesn’t radically change your system, as the packages in these repositories are packaged for the stable branch.

    (I hope I’ve understood correctly and, above all, summarised the point well)

  • source
  • parent
  • context
  • view more: next ›