From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: <9front-bounces@9front.inri.net> X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on inbox.vuxu.org X-Spam-Level: X-Spam-Status: No, score=-0.6 required=5.0 tests=DKIM_ADSP_CUSTOM_MED, DKIM_INVALID,DKIM_SIGNED,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.4 Received: from 9front.inri.net (9front.inri.net [168.235.81.73]) by inbox.vuxu.org (Postfix) with ESMTP id 6E8C72C60D for ; Sat, 24 Aug 2024 23:28:10 +0200 (CEST) Received: from mail-lf1-f46.google.com ([209.85.167.46]) by 9front; Sat Aug 24 17:25:35 -0400 2024 Received: by mail-lf1-f46.google.com with SMTP id 2adb3069b0e04-53438aa64a4so2209909e87.3 for <9front@9front.org>; Sat, 24 Aug 2024 14:25:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1724534733; x=1725139533; darn=9front.org; h=content-transfer-encoding:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=kjOpy3VuIr3aWkHcL8GVMYCTFtQYZgqgMHe8QcxpJOY=; b=IbTeZSOL1ZR3HEx3oS27mljFJ52NhoAvUEXbzBbBf332bBgI4Cg6cPBh5u/ny5igJa lPOLrqVEBewMiZJ5RWd0FBNs7lCJj1SvFiwiJx/75eNMSmLH9YgT2ACZIt4rV34gvXCo vlznEeWyGCYYwEBwlNLEwsWA4VVW7+jvaliM3FY7kE3F7Evkw32K/+knDqbJBINHPGK9 78dl+C5sAH0u8Lw/iYWjOrT6hPmsFZcZd13P0GjkHw9M9azbPIRxpz93r+0msfnmS1SB CVCpWiLfX1GIdmrgE5dYLg3wNOXxAnAZib08WzJwZ2N24ThMJFfva4illSnd9VFNpU8m Qt2A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1724534733; x=1725139533; h=content-transfer-encoding:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=kjOpy3VuIr3aWkHcL8GVMYCTFtQYZgqgMHe8QcxpJOY=; b=uUE1yODsof+2jttCauueDzhxeB//bMR0l0bTY+xJuH23QKtsV6wwWlubFXFlr3QTPf yXflXZqR2tdEY09UQ+L+FsiJc0ZOPHWCcPKwHzKBX+H8PZd6Ljvk1rEuEopVhc9Inf5J IgXmxczsi45S36jAe5Uu+cc8tzT6P/MPe5Mtc/Bm7B4rS/erwKkeNkiR9rxFqarKmmRN qKLXveVPztMY9D+WansOKwsyLmXeYVgXlUAzhQWaHnSaFdUxOdLtvsKqZ0H2wOAQcOfT Aou5EjQiiOmrm4Z/iXCRcBaSD5HruQ4PznuiA8N3l6mvNf/7j65m05CBypRm0Ym8gx8P g+9Q== X-Gm-Message-State: AOJu0Yx1jicBuAZvYehDUK8aBDzxw36x4SAa878k8uZTtk51vACcOBv8 ldNCc7IHHtU5mEC/fBl6y26Qh69WLoYGhyJvEyxbXCHhThKomPEimgWTjmME0a8hVZbZZnoqqZv 9QcDDaCCPLnd0wOAenovd4VGMgkSU/Q== X-Google-Smtp-Source: AGHT+IGQ7RClBh+XGfmr+J21muS71O6C1WSs+eKlpqi+EhVFqqWHVwMqNGXcusvGth4PRdr/Zmf+TkKxC7mOQyJS0fw= X-Received: by 2002:a05:6512:1394:b0:533:4bd0:df69 with SMTP id 2adb3069b0e04-53438868e52mr3981312e87.55.1724534732661; Sat, 24 Aug 2024 14:25:32 -0700 (PDT) MIME-Version: 1.0 References: <83dbbe63-a139-4dc6-af13-3abcafb9be6d@posixcafe.org> In-Reply-To: <83dbbe63-a139-4dc6-af13-3abcafb9be6d@posixcafe.org> From: adventures in9 Date: Sat, 24 Aug 2024 14:25:21 -0700 Message-ID: To: 9front@9front.org Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable List-ID: <9front.9front.org> List-Help: X-Glyph: ➈ X-Bullshit: non-blocking virtual replication-based XMPP standard blockchain Subject: Re: [9front] patch your shit Reply-To: 9front@9front.org Precedence: bulk hjfs does have the "experimental" warning XD On Sat, Aug 24, 2024 at 2:23=E2=80=AFPM Jacob Moody w= rote: > > hjfs is not the default install, our number of holes is fine. > > On 8/24/24 15:15, Willow Liquorice wrote: > > e https://9front.org/ > > /Only three remote holes in the default install, in a heck of a long ti= me!/ > > s/three/four > > w https://9front.org/ > > > > - Willow > > > > On 24/08/2024 20:08, hiro wrote: > >> some people did something that increases security apparently. so patch > >> your shit. > >> > >> ref: 07aa9bfeef55ca987d411115adcfbbd4390ecf34 > >> parent: b05c74e7cb160f152e2f2cc2f6e0677763f8d57e > >> author: Jacob Moody > >> date: Sat Aug 24 12:58:31 EDT 2024 > >> > >> lib9p: verify uname against returned AuthInfo from factotum (thanks hu= mm) > >> > >> Before this it was possible to Tauth and Tattach with one > >> user name and then authenticate with factotum using a different > >> user name. To fix this we now ensure that the uname matches the return= ed > >> cuid from AuthInfo. > >> > >> This security bug is still pending a cute mascot and theme song. > >> > >> > >> mein name ist hase. bye. >