Merge ~nexusprism/grub/+git/ubuntu:f2fs-support into ~ubuntu-core-dev/grub/+git/ubuntu:ubuntu

Proposed by Alexander Koskovich
Status: Rejected
Rejected by: Julian Andres Klode
Proposed branch: ~nexusprism/grub/+git/ubuntu:f2fs-support
Merge into: ~ubuntu-core-dev/grub/+git/ubuntu:ubuntu
Diff against target: 12 lines (+1/-0)
1 file modified
debian/build-efi-images (+1/-0)
Reviewer Review Type Date Requested Status
Julian Andres Klode Disapprove
Review via email: mp+440193@code.staging.launchpad.net
To post a comment you must log in.
Revision history for this message
Julian Andres Klode (juliank) wrote :

You can file a bug if you want that filesystem, and then it can be discussed and handed to security to review if that's something that we decide we want, but this doesn't work for merges.

It seems unlikely that this is something we want, we should try to tighten down what we support further, not add more options. In fact, there probably shouldn't be any options.

These all pose massive security risks.

review: Disapprove
Revision history for this message
Alexander Koskovich (nexusprism) wrote :

Can you explain why this would be a massive security risk? I saw in the linked bug that you mentioned it increases the attack surface, but couldn't that be argued for any kernel module as well, for example? Is it specifically because these need to be signed?

Revision history for this message
Alexander Koskovich (nexusprism) wrote :

Created a bug and linked to merge request.

There was an error fetching revisions from git servers. Please try again in a few minutes. If the problem persists, contact Launchpad support.

Preview Diff

[H/L] Next/Prev Comment, [J/K] Next/Prev File, [N/P] Next/Prev Hunk
The diff is not available at this time. You can reload the page or download it.

Subscribers

People subscribed via source and target branches