[pacman-dev] [PATCH] makepkg: rework --skip-integ

Jeff jeff at kcaccess.com
Fri Oct 30 01:32:19 EDT 2009


On Thu, Oct 29, 2009 at 01:08:52PM -0400, Loui Chang wrote:
> 
> In both cases if you could omit checksums and makepkg could interpret
> that as "the packager doesn't really care about integrity, skip checks".
> 
> It could print a warning, and you don't need another fancy flag.

And I fear laziness would abound with the result that the end user will
be the one left holding the bag. The reality is that a missing checksum
will at least cause unnecessary questions of the form: "I got this
warning when installing <package>... Is it safe?". At worse, "replacing"
said package with a trojaned version would not be recognized soon
enough.

-- 
Jeff

My other computer is an abacus.



More information about the pacman-dev mailing list