From owner-freebsd-hackers Sat Dec 14 20:31: 6 2002 Delivered-To: freebsd-hackers@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9690237B401 for ; Sat, 14 Dec 2002 20:31:05 -0800 (PST) Received: from puffin.mail.pas.earthlink.net (puffin.mail.pas.earthlink.net [207.217.120.139]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1331C43EC2 for ; Sat, 14 Dec 2002 20:31:05 -0800 (PST) (envelope-from tlambert2@mindspring.com) Received: from [216.20.231.174] (helo=mindspring.com) by puffin.mail.pas.earthlink.net with asmtp (SSLv3:RC4-MD5:128) (Exim 3.33 #1) id 18NQQb-00020O-00; Sat, 14 Dec 2002 20:30:57 -0800 Message-ID: <3DFC0532.BE107961@mindspring.com> Date: Sat, 14 Dec 2002 20:29:38 -0800 From: Terry Lambert X-Mailer: Mozilla 4.79 [en] (Win98; U) X-Accept-Language: en MIME-Version: 1.0 To: Leo Bicknell Cc: freebsd-hackers@FreeBSD.ORG Subject: Re: How can I post a pr when my IP can't be reverse-resolved? References: <3DFA09A2.C5B0103B@mindspring.com> <20021213190634.GA60400@ussenterprise.ufp.org> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit X-ELNK-Trace: b1a02af9316fbb217a47c185c03b154d40683398e744b8a4d97230bffc7c3b59a039a39376a0f12f350badd9bab72f9c350badd9bab72f9c350badd9bab72f9c Sender: owner-freebsd-hackers@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG Leo Bicknell wrote: > > Probably, the correct thing would be to accept the submission, > > and pend it for review, before it became active as a real PR. > > This would require that a human look at the pending PRs, and > > make a decision. > > Or, do the mailing-list confirm thing. Receive all pr's, send > e-mail back to the "from" asking for confirmation. If received > put into the queue, if not delete after n days. > > That way you could send a pr from a quite screwed up box with a > from of your normal e-mail, and then simply confirm it. This would have the same problem with people being able to pee in the PR pool, and specify mailing lists as the return address, and then respond to the query sent to the list with a forged reply. I think the only thing that will work is a human review with a posting latency. Everything else has a security race in it. -- Terry To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-hackers" in the body of the message