Comment 9 for bug 235653

Revision history for this message
Steve Langasek (vorlon) wrote :

Hi Chuck,

I have doubts whether this particular bug warrants an update. My understanding from reading the patch is that the reason the acl fails to work as intended is not because the sense of the acl is inverted, but because the acl matches no addresses instead of all addresses.

So since denying appears to be the default, it seems that the only case broken by this is giving all IP addresses access to nut. Is this ever really a good idea? Or have I overlooked some other reason that this makes sense?

If the only use case this breaks is something which is simply a bad security policy, I don't see this as justifying pushing a new SRU on its own and requiring people to re-download the package.