1 |
On Fri, 12 Jan 2007 07:55:00 +0100 Harald van Dijk <truedfx@g.o> |
2 |
wrote: |
3 |
| When does upstream get to install arbitrary content on my computer? |
4 |
| Upstream's build system gets to write stuff to $D, but not to $ROOT |
5 |
| (malice aside). The move to $ROOT, and anything after that, is the |
6 |
| ebuild writer's and the package manager's responsibility. |
7 |
|
8 |
Well that's the point. We're talking malice here, and whether or not |
9 |
one should trust a build system that won't work with userpriv. If you |
10 |
don't trust the build system with non-userpriv, you shouldn't trust it |
11 |
at all. |
12 |
|
13 |
-- |
14 |
Ciaran McCreesh |
15 |
Mail : ciaranm at ciaranm.org |
16 |
Web : http://ciaranm.org/ |
17 |
Paludis, the secure package manager : http://paludis.pioto.org/ |