Gentoo Archives: gentoo-dev

From: Christel Dahlskjaer <christel@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Project Sunrise thread -- a try of clarification
Date: Fri, 09 Jun 2006 18:12:50
Message-Id: 1149879964.4234.37.camel@gaspode
In Reply to: Re: [gentoo-dev] Project Sunrise thread -- a try of clarification by Ciaran McCreesh
1 On Fri, 2006-06-09 at 02:08 +0100, Ciaran McCreesh wrote:
2 > On Fri, 09 Jun 2006 02:49:14 +0200 Markus Ullmann <jokey@g.o>
3 > wrote:
4 > | > No. It clearly says that you would be doing the basic QA checks and
5 > | > repoman checking on initial commit. You even said it right above
6 > | > where I commented!
7 > |
8 > | You're doing some witch hunting here... I said we keep an eye on
9 > | non-devs commits.
10 >
11 > How much do you want to bet that I couldn't sneak malicious code past
12 > you?
13 >
14 > And if you accept that I could do it, you're also admitting that quite
15 > a few other random people, some of whom don't share my own ethical
16 > objections to such a stunt, could also pull it off given sufficient
17 > time and effort...
18
19 I'd say that it's entirely possibly for some non-dev to sneak malicious
20 code into the tree as is now, just as it will be possible to do in an
21 overlay.
22
23 It's not like it's particulary difficult to have someone proxy for you,
24 and let's face it, if someone is willing to do so then they probably
25 can't be arsed checking that what they are committing is clean and
26 nice.. I mean, I trust you, right?

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] Project Sunrise thread -- a try of clarification Ciaran McCreesh <ciaran.mccreesh@×××××××××××××.uk>