Gentoo Archives: gentoo-dev

From: Luca Barbato <lu_zero@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: Re: [experiment] Sunrise try 2
Date: Sun, 02 Jul 2006 20:31:24
Message-Id: 44A82BCF.2000103@gentoo.org
In Reply to: [gentoo-dev] Re: Re: [experiment] Sunrise try 2 by Stefan Schweizer
1 Stefan Schweizer wrote:
2 >
3 > Serverside checks are overkill imo since we check that later ourselves when
4 > reviewing. It is also harder to implement in general and especially now
5 > because the administrator of the server, jokey, has exams this week.
6 >
7
8 Nope, you need them to avoid "smart stupid" situation:
9 - smart enough to circumvent the checks
10 - stupid enough to commit something that doesn't pass the checks
11
12 or just because I'm paranoid and you may add $bad_stuff in the global
13 scope, bypass the checks clientside and let people have fun once they
14 fetch the stuff..
15
16 just a check that prevents commands in global scope and/or shutting down
17 sandbox is a must.
18
19 lu
20
21 --
22
23 Luca Barbato
24
25 Gentoo/linux Gentoo/PPC
26 http://dev.gentoo.org/~lu_zero
27
28 --
29 gentoo-dev@g.o mailing list