[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#405997: should executables be permitted to update themselves?



This one time, at band camp, Sam Morris said:
> On Sun, 14 Jan 2007 00:26:15 -0500, Michael Gilbert wrote:
> > is there a policy on whether an executable is permitted to update itself?  i
> > personally believe that in order to maintain the security of the system, apt
> > and apt alone should be used to install software updates.  recently i
> > submitted a bug on azureus about how it should not urge users to install
> > updates outside of apt (http://bugs.debian.org/405997), which was quickly
> > closed by the maintainer.  his reasoning was that users should be given the
> > choice of using apt or the built-in updater.  was this bug handled
> > correctly?
> 
> How does the azureus package work around the fact that only root can write
> to the package files?

It saves the new .jar to ~/.azureus, which is first in the search path.
This also prevents you from using the shipped .jar in the deb.
-- 
 -----------------------------------------------------------------
|   ,''`.                                            Stephen Gran |
|  : :' :                                        sgran@debian.org |
|  `. `'                        Debian user, admin, and developer |
|    `-                                     http://www.debian.org |
 -----------------------------------------------------------------

Attachment: signature.asc
Description: Digital signature


Reply to: