[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Debian needs more buildds. It has offers. They aren't beingaccepted.

* Wouter Verhelst (wouter@grep.be) [040219 12:25]:
> On Thu, Feb 19, 2004 at 05:10:27AM +0100, Goswin von Brederlow wrote:
> [...ftp-master being restricted...]
> > Why not move wanna-build off ftp-master then? All it needs is the
> > quinn-diff output for accepted/autobuild and the main archive and
> > thats easily transfered through a strictly controled ssh connect, by
> > mail, via http or any number of other ways.

> Because it takes time to set up, manage, and stuff like that. The
> archive scripts are probably already complex enough to not have to add
> that extra complexity.
> Also, injecting quinn-diff output into a local wanna-build is a lot
> faster than rsync'ing, scp'ing, or wget'ing it over to another system,
> and injecting it into the database there.

The discussion today told me that restricting access to w-b for
buildds is done as a security measurement (as the ssh-access could be
abused after a break-in in a buildd). Please tell me if this is wrong,
as I'm not really knowing much about this system.

If this is the case, it should be IMHO be considered to change the
interface to w-b from now via command line (means: access via ssh is
necessary) to something via a SMTP-like protocol.

Of course, this change is not too easy, but if it would lower the risk
of problems on ftp-master and would make it more easy to add new
buildds, than we should do that change (and I'm willing to put time in
that if necessary).

   PGP 1024/89FB5CE5  DC F1 85 6D A6 45 9C 0F  3B BE F1 D0 C5 D1 D9 0C

Reply to: