[pacman-dev] makepkg security

Xyne xyne at archlinux.ca
Sat Jul 11 06:29:11 EDT 2009


> The original complaint was that when using makepkg -sic, the sudo 
> password is cached after dependency installation and malicious sudo 
> commands might be executed during build() as the password is cached.
> 
> My opinion on this is that we should not encourage people to use sudo, 
> Aaron suggested to move it here for further discussion. What do you think?

Couldn't you just add an option to kill sudo after dependency installation?


More information about the pacman-dev mailing list