Proposal: rpm-4.2.2 should refuse to build as root

Willem Riede wrrhdev at riede.org
Wed Dec 31 15:36:29 UTC 2003


On 2003.12.31 10:09, Panu Matilainen wrote:
> On Wed, 31 Dec 2003, Chris Ricker wrote:
> 
> > On Wed, 31 Dec 2003, Warren Togami wrote:
> > 
> > > Proposal
> > > ========
> > > rpm-4.2.2 in rawhide and all future versions should refuse to install 
> > > SRPMS & build packages as root by default.  Optionally add a .rpmmacro 
> > > option to re-enable it, but only mention that option for advanced users 
> > > on rpm.org to really discourage its use.
> > 
> > I disagree. Save your personal policy decisions for yourself -- don't make 
> > them everyone's.
> 
> Building rpm's as root IS incredibly bad idea which should be discouraged. 
> Even worse when no buildroot is used - once you've seen a package 
> which (re)moves stuff in /usr/lib during build...

True. But, the spirit of *nix is "Here's a rope. Now, you can do useful things
with it, or you can hang yourself with it. Up to you."

Users who want to be protected against themselves can go run "that other OS".
I don't want Fedora to go in that direction.

Regards, Willem Riede.





More information about the devel mailing list