Re: Package maintainer script policy.

>>"Raul" == Raul Miller <rdm@test.legislate.com> writes:

 >> Raul Miller wrote:
 >> > I think it should be a wishlist bug.  This is a required package,
 >> > and in a secure environment you'd like to be able to verify the
 >> > dpkg scripts before running them (or perform the steps by hand).
 Raul> Joey Hess <joey@kitenet.net> wrote:
 >> If you're ultra-paranoid, what's the difference between a postinst that is a
 >> binary (ie, libreadlineg2.deb) and a postinst that calls a binary that is
 >> contained in the package (ie, bash.deb)?
 >> We can't outlaw the second, so I see no reason to bother outlawing the
 >> first.

 Raul> The differences are frequency of use, and need.

	Excuse me? 
 Case 1) The postinst is binary, and can't be checked a priori
 Case 2) The postinst is a shell script that calls a binary included
         in the package, which again is not checkable easily.

	Where does frequency of use and need come into the picture?

