Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Portage & Programming
  • Search

Brave Browser and a question about Gentoo Overlay QA[SOLVED]

Problems with emerge or ebuilds? Have a basic programming question about C, PHP, Perl, BASH or something else?
Post Reply
Advanced search
9 posts • Page 1 of 1
Author
Message
Budoka
l33t
l33t
Posts: 777
Joined: Sun Jun 03, 2012 9:26 am
Location: Tokyo, Japan

Brave Browser and a question about Gentoo Overlay QA[SOLVED]

  • Quote

Post by Budoka » Mon Jan 20, 2020 5:10 pm

Moderators, I wasn't sure if I should post this in the Unsupported Software subforum or this one. Please move to the appropriate subforum if this isn't where my question should be.

As best I can tell, Brave Broswer is currently not in portage. Based on the research I've done building from source is at best prohibitively challenging and at worst impossible.

I see that there is a Brave Overlay with a binary that can be installed which leads me to my question...

How safe is it to install from overlays from a security/privacy standpoint? The Gentoo Overlay Wiki states
The repository should be maintained with best effort not to cause issues to users using it. We reserve the right to remove repositories that are reported to pose a serious threat to our users.
But, are overlays actively monitored or is it reactive ie: Someone reports it and then it is removed. Or are they vetted in some way before being added? As much as I'd like to use this particular overlay I hesitate to do so because I use things such as my password manager in it. And quite honestly I was spooked by the author's email address which is at the domain name
@medicalcannab.is
Last edited by Budoka on Tue Jan 21, 2020 3:19 pm, edited 2 times in total.
Top
fedeliallalinea
Administrator
Administrator
User avatar
Posts: 31985
Joined: Sat Mar 08, 2003 11:15 pm
Location: here
Contact:
Contact fedeliallalinea
Website

  • Quote

Post by fedeliallalinea » Mon Jan 20, 2020 6:03 pm

There are some automatically QA check but I don't know what is exactly are.
You can check the SRC_URI in ebuild if download in official site, you can also download manually program and put it in distfiles directory and then run emerge if checksum from downloaded program differ from that in Manifest file the is a problem.
And quite hoenstly I was spooked by the author's email address which is at the domain name:

Code: Select all

@medicalcannab.is	
Where you see that in metadata.xml I see jpizarrocallejas@gmail.com
Questions are guaranteed in life; Answers aren't.

"Those who would give up essential liberty to purchase a little temporary safety,
deserve neither liberty nor safety."
- Ben Franklin
https://www.news.admin.ch/it/nsb?id=103968
Top
Budoka
l33t
l33t
Posts: 777
Joined: Sun Jun 03, 2012 9:26 am
Location: Tokyo, Japan

  • Quote

Post by Budoka » Mon Jan 20, 2020 6:35 pm

fedeliallalinea wrote:There are some automatically QA check but I don't know what is exactly are.
You can check the SRC_URI in ebuild if download in official site, you can also download manually program and put it in distfiles directory and then run emerge if checksum from downloaded program differ from that in Manifest file the is a problem.
And quite honestly I was spooked by the author's email address which is at the domain name:

Code: Select all

@medicalcannab.is	
Where you see that in metadata.xml I see jpizarrocallejas@gmail.com
Thanks for the reply. When I look at the overlay info that is the address that appears.
layman -i brave-overlay

* brave-overlay
* ~~~~~~~~~~~~~
* Source : https://gitlab.com/jason.oliveira/brave-overlay.git
* Contact : Jason Oliveira <jason.oliveira@medicalcannab.is>
* Type : Git; Priority: 50
* Quality : experimental
*
* Description:
* Brave Overlay
*
* Link:
* https://gitlab.com/jason.oliveira/brave-overlay
*
* Feed:
* https://gitlab.com/jason.oliveira/brave ... aster.atom
Top
Ant P.
Watchman
Watchman
Posts: 6920
Joined: Sat Apr 18, 2009 7:18 pm
Contact:
Contact Ant P.
Website

  • Quote

Post by Ant P. » Mon Jan 20, 2020 6:54 pm

You're more concerned about the overlay author's email address than the concept of a chromium wrapper funded by a cryptocurrency that derives its value from proactive advertising to its users?
Top
Budoka
l33t
l33t
Posts: 777
Joined: Sun Jun 03, 2012 9:26 am
Location: Tokyo, Japan

  • Quote

Post by Budoka » Mon Jan 20, 2020 7:17 pm

Ant P. wrote:You're more concerned about the overlay author's email address than the concept of a chromium wrapper funded by a cryptocurrency that derives its value from proactive advertising to its users?
LOL. That's cute.

But in all seriousness, Brave aside, that doesn't answer my underlying question about the security/integrity of installing binaries from overlays vs compiling from portage.
Top
Hu
Administrator
Administrator
Posts: 24380
Joined: Tue Mar 06, 2007 5:38 am

  • Quote

Post by Hu » Tue Jan 21, 2020 3:48 am

Based on the "Reserve the right" language, I expect, and suggest you act as if, the reviews are not scheduled on any particular timeline, not required as a condition of membership, and not exhaustive enough to uncover cleverly hidden hostile content. Based on those qualifiers, I would then say that you should not install critical software from an overlay unless you have a good reason to trust that maintainer specifically (e.g. if it is a well respected Gentoo developer who uses an overlay for his/her highly experimental packages, or a longtime community contributor with years of trustworthy activity to his/her name).
Top
Budoka
l33t
l33t
Posts: 777
Joined: Sun Jun 03, 2012 9:26 am
Location: Tokyo, Japan

  • Quote

Post by Budoka » Tue Jan 21, 2020 3:17 pm

Hu wrote:Based on the "Reserve the right" language, I expect, and suggest you act as if, the reviews are not scheduled on any particular timeline, not required as a condition of membership, and not exhaustive enough to uncover cleverly hidden hostile content. Based on those qualifiers, I would then say that you should not install critical software from an overlay unless you have a good reason to trust that maintainer specifically (e.g. if it is a well respected Gentoo developer who uses an overlay for his/her highly experimental packages, or a longtime community contributor with years of trustworthy activity to his/her name).
Thank you. That is prudent advice and was my initial inclination. But I realized that, in addition to tons of other stuff, the Gentoo Overlay system is something I am just not familiar with thus my question.
Top
Juippisi
Developer
Developer
User avatar
Posts: 783
Joined: Fri Sep 30, 2005 3:51 pm
Location: /home

  • Quote

Post by Juippisi » Tue Jan 21, 2020 5:50 pm

fedeliallalinea wrote:There are some automatically QA check but I don't know what is exactly are.
It's basically just checking that sourcing the overlay isn't broken. So no ebuild QA checks are run on overlays.
But in all seriousness, Brave aside, that doesn't answer my underlying question about the security/integrity of installing binaries from overlays vs compiling from portage.
I'd say portage is much more secure because there are a lot more eyes, and every commit is made public via git web browser and gentoo-commits mailing list. When it comes to overlays, you should audit the ebuilds before installing. It's the same everywhere, like with Arch Linux's AUR. I'm not aware of any misuse from Gentoo overlays, but doesn't mean there aren't any.
Top
fedeliallalinea
Administrator
Administrator
User avatar
Posts: 31985
Joined: Sat Mar 08, 2003 11:15 pm
Location: here
Contact:
Contact fedeliallalinea
Website

  • Quote

Post by fedeliallalinea » Tue Jan 21, 2020 5:54 pm

Juippisi wrote:
fedeliallalinea wrote:There are some automatically QA check but I don't know what is exactly are.
It's basically just checking that sourcing the overlay isn't broken. So no ebuild QA checks are run on overlays.
OK thank you for information, I thought there was a minimum of automatic QA check.
Questions are guaranteed in life; Answers aren't.

"Those who would give up essential liberty to purchase a little temporary safety,
deserve neither liberty nor safety."
- Ben Franklin
https://www.news.admin.ch/it/nsb?id=103968
Top
Post Reply

9 posts • Page 1 of 1

Return to “Portage & Programming”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy