[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Scripts that run insecurely-downloaded code




Am 02.05.2020 02:53, schrieb Paul Wise:
On Fri, May 1, 2020 at 8:18 PM Rebecca N. Palmer wrote:

This is already policy (and enforced by blocking network access) for
official Debian package builds: dependencies must be installed by the
package manager, not the build script.

Correction: the debian.org buildds do not at this time block any
network access. The main issue is that schroot does not support it and
it has been orphaned and unmaintained for years. You might be thinking
of pbuilder, which does do this by default.

I still remember the times when xchroot was a candidate and schroot did not yet exist. I still used to maintain it with features like Xorg-chroot and chroot as user (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721447, https://www.elstel.org/xchroot/). The problem about it that time was that it was not yet GPLv3.


Reply to: