[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: DM and pkg-perl (recap 1)



-=| gregor herrmann, Wed, Nov 28, 2007 at 11:26:17PM +0100 |=-
> A few thoughts:
> * It wouldn't prevent a malicious DM from adding him/herself later to
>   the Uploaders field; not that I think that would be a real problem,
>   changes are easily reverted (and DM status too).

I agree. I think that we should not assume there will be malicious
events we must defend against. It seems more probable to me
that such DM can simply forget that adding to Uploaders gives her some
right that weren't there before.

This means "extra caution when adding to Uploaders".

> * I'm not sure if it scales if many DMs should ask many DDs for the
>   inclusion; but that's probably more hypothetical.

See the proposal in my reply to Niko's mail. Should avoid bottlenecks in
the same way as we currently do for "sponsored" uploads.

> * If I were a DM I wouldn't be sure which packages to ask upload
>   rights for; but that's more of an "other people's problem" :)

For these which you are confident hacking and that you want to be able
to upload in the future. I guess everyone applies her own criteria here.

> * I think a short notice to the list after the change would be nice.

Sure.

> BTW: Might cleaning out the Uploaders field for all packages be a
> good idea?

I am not sure what does this give us. The DD introducing DM-Yes and/or
new Uploaders have to filter the list anyway.

-- 
dam            JabberID: dam@jabber.minus273.org

Attachment: signature.asc
Description: Digital signature


Reply to: