[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Alternative plan for DDP

On Tue, Feb 03, 2004 at 10:46:21PM +0100, Osamu Aoki wrote:
> joy's (I think) cron script to check out CVS 
>  Step 1: checkout from alioth.debian.org (source1)
>  Step 2: export from cvs.debian.org      (source2)
>  Step 3: copy source2 over source1 with cp -af
>  Build like he does now using Makefile in parent directory.

Important hint: every script/makefile must use '-f Makefile' explicitly in 
make invocation to avoid the default name overriding by malicious
use of GNUmakefile. That's mandatory IMHO. Setting of MAKEFILES could
also be considered to avoid this kind of potential abuse.

The point is not considering alioth cvs more trustable than needed.
That's also my concern about having scripts cvs mantained on alioth,
of course.

Francesco P. Lovergine

Reply to: