On Thu, 2008-06-12 at 14:48 +0200, Jindrich Novy wrote:

> Opinions?

One of the reasons why the mktemp option is appealing is because it is
not predictable, and helps lessen the security risks of knowing where
the buildroot is going to be and inserting malicious files. 

The only reason we use mktemp in there is because we couldn't make rpm
code changes to use the native glibc functions. As to rpm
--short-circuit, well, I honestly think we should think long and hard
about whether we want to keep it around.

~spot

_______________________________________________
Rpm-maint mailing list
[email protected]
https://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to