Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Maemo: Community

Bug in repositories/builder?

 

 

Maemo community RSS feed   Index | Next | Previous | View Threaded


twilight312 at gmail

Apr 28, 2012, 12:49 PM

Post #1 of 2 (91 views)
Permalink
Bug in repositories/builder?

http://talk.maemo.org/showthread.php?t=83948

This is another topic that covers - more specifically - recently
discovered (by mistake) security hole.

The most interesting thing, is that such nasty "trick" works for some
packages, but doesn't for other. I'm not knowledgeable enough here,
but it sounds buggy.

/Estel
_______________________________________________
maemo-community mailing list
maemo-community [at] maemo
https://lists.maemo.org/mailman/listinfo/maemo-community


maemo at javispedro

Apr 29, 2012, 5:29 AM

Post #2 of 2 (81 views)
Permalink
Re: Bug in repositories/builder? [In reply to]

On Sat, 28 Apr 2012 21:49:34 +0200, Piotr Jawidzyk wrote:

> http://talk.maemo.org/showthread.php?t=83948
>
> This is another topic that covers - more specifically - recently
> discovered (by mistake) security hole.

Not exactly a security hole, because there is no security at all on
extras-devel.

Out of curiosity: why are you thinking that this is critical for the CSSU?
Are you building packages there or similar?

One can add small trivial checks (like the one that is not in place for -
devel but it is in place -testing for conflicting packages). Yet this
would block accidental mistakes, but not block anyone trying to do
something with malicious purposes, which is outright impossible. Think
about the bazillion degrees of freedom a packager has. Provides, etc.


In OBS, you can manually (for a given project) select which other
projects you want to fetch build-dependencies from.

Javier.

_______________________________________________
maemo-community mailing list
maemo-community [at] maemo
https://lists.maemo.org/mailman/listinfo/maemo-community

Maemo community RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.