On Sun, 11 May 1997, Joey Hess wrote:

> Lars Wirzenius:
> > They might not understand enough about shell scripts (or Perl, or
> > whatever the script is written in) and whatever tools the script uses
> > to make an informed decision of whether the script is safe. With the
> > current scheme, they only have to trust gzip, tar, patch, and chmod,
> And all of debian/rules. And debmake or anoy other programs called by it. 
> They are planning on building this package, right?

IMHO this is where we ought to be looking to improve our source packaging
system. At least we should allow building as a non-root user as soon as
possible (using the new GNU tar).

