On Fri, 12 Jan 2007 07:55:00 +0100 Harald van Dijk <[EMAIL PROTECTED]>
wrote:
| When does upstream get to install arbitrary content on my computer?
| Upstream's build system gets to write stuff to $D, but not to $ROOT
| (malice aside). The move to $ROOT, and anything after that, is the
| ebuild writer's and the package manager's responsibility.

Well that's the point. We're talking malice here, and whether or not
one should trust a build system that won't work with userpriv. If you
don't trust the build system with non-userpriv, you shouldn't trust it
at all.

-- 
Ciaran McCreesh
Mail                                : ciaranm at ciaranm.org
Web                                 : http://ciaranm.org/
Paludis, the secure package manager : http://paludis.pioto.org/

Attachment: signature.asc
Description: PGP signature

Reply via email to