‹ BackHN Continuity

Thread

OpenBSD Developers Reject Uutils Coreutils

31 points · 42 comments · pjmlp

  1. bewareofscams · · focus · HN ↗
    My account is banned, so for whomever with [showdead] on:

    It's unfortunate that the supposed pillar of security dismisses Rust on dubious grounds. Yes, there is agenda coming from Ubuntu. And yet, Rust IS the secure alternative to C/C++ (alternative is a misnomer, it's better than the latter on all fronts), so OpenBSD dismissal is very superficial.

    1. ninjin · · focus · HN ↗
      I think the security argument for carrying an alternative set of Posix-like utilities to Gnu Core Utilities is rather weak. These would mostly have been used to build other ports, or are you suggesting that this would harden the ports build systems (which already use privsep at that)? If so, I would take the lower maintenance burden any day and just wait for the Linux ecosystem to make up their mind as to whether Uutils becomes the new standard or not.
      1. JdeBP · · focus · HN ↗
        Of course, on OpenBSD it is GNU Core Utilities themselves that already are the alternative suite of SUS utilities. So it's an argument for carrying alternatives to the alternatives.
    2. sdcfgy · · focus · HN ↗
      On paper yes but it introduces different problems. The trade off isn’t one that everyone universally believes is worth it.
    3. yjftsjthsd-h · · focus · HN ↗
      Couple things:

      Comparing uutil's CVEs per year against GNU coreutils paints a very poor picture. I haven't checked OpenBSD coreutils, but I suspect it's even more ahead. Rust doesn't appear to be a silver bullet.

      Even if rust uutils was more secure, I don't think it's available on all OpenBSD platforms, which really caps how useful it can be.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.