From mboxrd@z Thu Jan 1 00:00:00 1970 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on inbox.vuxu.org X-Spam-Level: X-Spam-Status: No, score=-3.4 required=5.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED,UNPARSEABLE_RELAY autolearn=ham autolearn_force=no version=3.4.4 Received: (qmail 16081 invoked from network); 28 Dec 2020 10:50:25 -0000 Received: from zero.zsh.org (2a02:898:31:0:48:4558:7a:7368) by inbox.vuxu.org with ESMTPUTF8; 28 Dec 2020 10:50:25 -0000 ARC-Seal: i=1; cv=none; a=rsa-sha256; d=zsh.org; s=rsa-20200801; t=1609152625; b=zhdOUQzEzzfYedsAVQ4fZNQmZmx9zSAXC7GeQMQVCl1baruOHvflnNJoGObQOyNjawmpO9uEtE uSbB0i404/WYgEKHyOTJKbndTjZBEYpjbKkRp7FrHuyExKx9dbRl/DWDPvDDhy32U/i9kRWJZj o1JaV07IgqGUIRoSnMrleFAbAzU8Bwcjz/GQ/PwrwUqavoHqJZ6fd+g2fUnVONQzFPnaWqTdks cLsJ23s5rK56b9b7Hz9XibX9ll1xlP5EiKDPeO7gp4G0u6kmnm8Ox6HFxJjqdd762nVGuFxuVS h/k/dpVXwTfCrniSCQVHSBkKpU2tDyGWExjUrog2K69F8g==; ARC-Authentication-Results: i=1; zsh.org; iprev=pass (out2-smtp.messagingengine.com) smtp.remote-ip=66.111.4.26; dkim=pass header.d=daniel.shahaf.name header.s=fm2 header.a=rsa-sha256; dkim=pass header.d=messagingengine.com header.s=fm1 header.a=rsa-sha256; dmarc=none header.from=daniel.shahaf.name; arc=none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed; d=zsh.org; s=rsa-20200801; t=1609152625; bh=Bmvl46DZMm/NK5TPv6OgY1SU/Yk0x7GbaqDJlthucZc=; h=List-Archive:List-Owner:List-Post:List-Unsubscribe:List-Subscribe:List-Help: List-Id:Sender:In-Reply-To:Content-Type:MIME-Version:References:Message-ID: Subject:To:From:Date:DKIM-Signature:DKIM-Signature:DKIM-Signature; b=TpBUonGQxr7dsWdNRanbR/Q6I5003mXEB0CCcypuUlSDfsO05jP69nbIhfCFK2WoNn9Lt7jK3z BkDtIxU2b0tU9H+aqMH89g29wHlsDxcG3jrpdRW0wczp6Pz5LcPO2kKTBWlpgD0uwoAGjQ+hFs 5+eMpYYtl5qN414Q6RIhgeY455qhreULd5UG9O+QlWXpUl/TzophKzNvGcBJKodaJAecJXEznO 39cslLKZr3fsY2QmEp7vox+Z0Lsjpa5xAxJkzNqyygRVoCD3OAt0Oij9OtF7L6g9bDx8OJkaE1 yqWCZs/DP/9OVdGq6RJPLM9Hc5P/GBooF2D0bFKd1DOrJw==; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=zsh.org; s=rsa-20200801; h=List-Archive:List-Owner:List-Post:List-Unsubscribe: List-Subscribe:List-Help:List-Id:Sender:In-Reply-To:Content-Type:MIME-Version :References:Message-ID:Subject:To:From:Date:Reply-To:Cc: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID; bh=rvsBDzx2SWT5CanmyF736ARAs9cZz9vxDCWo/X8gMMQ=; b=EDpzwyhk7ny21p0bEB4yaXM+Nj ILs25C34p6tvsLkVVqPhZAsU0n83/SSYr5HYsPh7CAUcpMmJIAHguWWsgrZHNRpYxmLQvxtNXznfE /gPHgcsbZusqTaVY36gutRj8ERuda1i4a+QmQUFbLJJFD1/zWReNBB0XCwYaSLrXoM2eB5h6UfFeT ZiWCNQsx6ggI3v4IzQjgrNaJZNcZU1pOfHKc4MClLHNTGFVKOC8lJo5EPGvf+IoYFZzAIv88tmjgM HhUULAGp34Q0wckxAkLjsdUUVXWm87lFg0Zjka5jRZ43JpMAwqTuiXaaCahSVgnSH2fXXga3Potv2 WuRw46yg==; Received: from authenticated user by zero.zsh.org with local id 1ktq6a-000Mx0-Vd; Mon, 28 Dec 2020 10:50:25 +0000 Authentication-Results: zsh.org; iprev=pass (out2-smtp.messagingengine.com) smtp.remote-ip=66.111.4.26; dkim=pass header.d=daniel.shahaf.name header.s=fm2 header.a=rsa-sha256; dkim=pass header.d=messagingengine.com header.s=fm1 header.a=rsa-sha256; dmarc=none header.from=daniel.shahaf.name; arc=none Received: from out2-smtp.messagingengine.com ([66.111.4.26]:53201) by zero.zsh.org with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) id 1ktq6Q-000Mno-CV; Mon, 28 Dec 2020 10:50:15 +0000 Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id 94D175C00D4; Mon, 28 Dec 2020 05:50:13 -0500 (EST) Received: from mailfrontend2 ([10.202.2.163]) by compute3.internal (MEProxy); Mon, 28 Dec 2020 05:50:13 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= daniel.shahaf.name; h=date:from:to:subject:message-id:references :mime-version:content-type:in-reply-to; s=fm2; bh=rvsBDzx2SWT5Ca nmyF736ARAs9cZz9vxDCWo/X8gMMQ=; b=ZkI7N6s3UsO8vNa6AwGTE0xcJIvPB9 dbXtXbESQ67BOT52HFwPcCIH4oBAKRWjpdg1CPbdIpmD6eQZyxkNMkedZxcFk4Yh he39Ftg54/Q5gjhVKG37hQWvRgUumHe/Nu0HfYoiNZzcbQJfR/44dUSwvND3b4Rs NIgd/d+rxqq8WY4xS4k1v1rsmdLlU8M2ZtER8cErWrw5wlBvFsmatll6BOsWzyjM 4gikpyFHCjzo/vJXWjDdz91Aa0hwvPSQDJoNZuUZ9z6Dkkd9p9gBHWw97c4wWPuW ZPJSNbTiRMTewkmIWky5AAaxYOj1aCKDXBUKGm+txbsLeReH4yRQ9pQw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=rvsBDz x2SWT5CanmyF736ARAs9cZz9vxDCWo/X8gMMQ=; b=Nm0owNbxNa/YCqC9B0XEAM GrS+7j0sBtZXL+VWwp7ghnX/F3xNYNGObnzm2FA4D0xl90am6+1+UkXGZWTwe3GR sTCSqrhLxl1UzsiX4d67BXT7VoCZtzQIW65KubXsYqkC5BzmR7XQ+vLPAk1P1vab O8CIdAlKTEaUOIcehCBvUfMmuJ0O1iBeQwNMHtKlOfG9n1NKiqCkqZ5KCMbaiFlZ uDOpl71HlKvqrZBUY58dSNWRV1Z+O2GnCkKLEqIphi7pZyAtLCpD27+NBDNsvjKL a3JK9+vIp3PYj9FibgdexDCbhSY6JVw1khqnCTKbO37fCk2wMhEKXQc5qTt5x2VA == X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedujedrvdduledgvddvucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpeffhffvuffkfhggtggujggfsehttd dttddtredvnecuhfhrohhmpeffrghnihgvlhcuufhhrghhrghfuceougdrshesuggrnhhi vghlrdhshhgrhhgrfhdrnhgrmhgvqeenucggtffrrghtthgvrhhnpeeuveekfeffueefhe efhfegffefvdeitdehtdegleejledviefhveejfeetgedvkeenucfkphepuddtledrieei rdekgedrudehleenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfh hrohhmpegurdhssegurghnihgvlhdrshhhrghhrghfrdhnrghmvg X-ME-Proxy: Received: from tarpaulin.shahaf.local2 (bzq-109-66-84-159.red.bezeqint.net [109.66.84.159]) by mail.messagingengine.com (Postfix) with ESMTPA id 1491D108005B for ; Mon, 28 Dec 2020 05:50:13 -0500 (EST) Received: by tarpaulin.shahaf.local2 (Postfix, from userid 1005) id 4D4DpW3gnwz4cv; Mon, 28 Dec 2020 10:50:11 +0000 (UTC) Date: Mon, 28 Dec 2020 10:50:11 +0000 From: Daniel Shahaf To: zsh-workers@zsh.org Subject: Re: Security Message-ID: <20201228105011.GD10030@tarpaulin.shahaf.local2> References: <9ukE0EnlTIntEcJ7b7nLSoq5E3XfeB-HtfyHk1Vmzoh_NojpSpL_amjhCixUBdb164pmStO4by1oduUBR0zCJpK0xGzrh2uz42flRXt96-8=@protonmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.10.1 (2018-07-13) X-Seq: 47768 Archived-At: X-Loop: zsh-workers@zsh.org Errors-To: zsh-workers-owner@zsh.org Precedence: list Precedence: bulk Sender: zsh-workers-request@zsh.org X-no-archive: yes List-Id: List-Help: List-Subscribe: List-Unsubscribe: List-Post: List-Owner: List-Archive: Archived-At: Phil Pennock wrote on Sun, Dec 27, 2020 at 16:48:54 -0500: > On 2020-12-25 at 16:06 +0000, Daniel Shahaf wrote: > > Sorry for the delay. It sounds like you emailed _only_ Oliver, so he > > might simply be on holiday. In any case, to avoid a single point of > > failure, please email the details to zsh-infra@zsh.org. Thanks! > > > > Note to -workers@: Folks who have dealt with previous security issues > > (or are otherwise trusted) and aren't already on -infra@ are welcome to > > join. Just send a subscription request the usual way. (And yes, > > a separate -security@ list might be a good idea, or at least an alias.) > > zsh-security@ now exists, we're kicking the tires. I set it to > closed-to-new-subscribers, so Daniel might clean up after me and open it > to let people ask in the usual way. I'm perfectly happy to let it stay as "Ask someone to add you manually", for the time being at least, due to shortage of brainwidth on my end. > (Sorry, I missed this thread before > and only saw it after closing out the stuff I had open for setup). > > The -infra list is intended to be boring. Several of the people you > want looking at security stuff are not subscribed and probably don't > want the spam of discussions about mailing-list bounce rates, > certificate renewals, etc. > > -Phil >