Gentoo Archives: gentoo-council

From: Donnie Berkholz <dberkholz@g.o>
To: Roy Marples <uberlord@g.o>
Cc: gentoo-council@l.g.o
Subject: Re: [gentoo-council] Council meeting summary for 8 November 2007
Date: Fri, 09 Nov 2007 08:06:06
Message-Id: 20071109080555.GX5516@supernova
In Reply to: Re: [gentoo-council] Council meeting summary for 8 November 2007 by Roy Marples
1 On 07:53 Fri 09 Nov , Roy Marples wrote:
2 >
3 > On Thu, 2007-11-08 at 14:25 -0800, Donnie Berkholz wrote:
4 > > Here is the summary from today's council meeting. The complete log will
5 > > show up at http://www.gentoo.org/proj/en/council/ shortly.
6 >
7 >
8 >
9 > > Baselayout-2: uberlord will continue to maintain it
10 > > ---------------------------------------------------
11 >
12 > > lu_zero asked whether we had anything to do about baselayout-2 since
13 > > uberlord resigned. He's continuing to maintain it in a git repository
14 > > and will remain upstream for it. More details will emerge over time.
15 >
16 > > kingtaco raised the question of trusting external releases and hosts.
17 > > Some responses suggested that using git may prevent the malicious
18 > > host,
19 > > because of the possibility of GPG-signed tags. He mentioned the
20 > > possibility of the infra team hosting Gentoo-critical repositories
21 > > with
22 > > access by non-Gentoo developers. It's just an idea at this point, but
23 > > he's going to talk to the rest of the infra team.
24 >
25 > They should be treated in the same way as any other package. Or do you
26 > trust a gentoo dev MORE than say a gcc/glibc/kernel/bash/foo dev? If so,
27 > why?
28 > More to the point, if said dev then joins Gentoo, do you implicitly
29 > trust that dev more?
30
31 I brought up that point during the meeting, if you read the log you'll
32 see it. =)
33
34 > As I've gone the other way, do you now trust me less? I'd like to know
35 > why also :)
36
37 I don't hold this opinion, but people could bring up later resentment at
38 Gentoo for not being able to get your way, etc.
39
40 I think we successfully directed any paranoia away from you and in the
41 direction of whether wherever a git repo would get hosted is less
42 trustable than Gentoo infra.
43
44 Could you tell us a bit about what you're thinking for where to host the
45 repo?
46
47 Thanks,
48 Donnie
49 --
50 gentoo-council@g.o mailing list

Replies