Re: Installing 3rd party packages, apt URIs

Kevin Krammer <[email protected]>
Newsgroups gmane.comp.kde.debian
Message-ID <[email protected]>
On Monday 19 January 2004 21:14, Marcin Pawlik wrote:
> On Mon, Jan 19 at 20:09, Kevin Krammer wrote:
>
> [...]
>
> >> Yes, you can specify different sources.list file location.
> >
> > Very good, didn't know that.
> > So it would be possible to create a temporary sources.list file, merge
> > in the base file, add a new source and proceed with apt-get update &&
> > apt-get install package
> >
> > Will have to play with that :)
>
> I haven't tried it but according to the manual
> apt-get update -o Dir::Etc::SourceList=/path/to/the/file
> should work.

Thank you!

> > True, but this is already happing. A lot of people use unofficial
> > repositories, that's why a service like apt-get.org was really sought
> > for by many.
>
> To add the repository they have to become root and edit the system file.
> They know this is not a normal and safe operation. If you provide more
> convenient option where the users are still aware that what they doing
> is dangerous, it's acceptable.

They will still need to enter the root password for launching the application.

Of course however this would be implemented should always have security as a 
top priority.

> > I'd say there could be two modes. The URL is processed and the checks
> > if the package can be install run.  The user gets a list of what will
> > happen, like running apt-get -u (optinally including -s) If the user
> > confirms, the package and dependencies are installed.  Then the
> > program could ask something like "Do you want to add this resource to
> > your permanent source list. You can then get updates as if it where a
> > system package but it might also introduce problems because it is an
> > unproofed source" <Make permanent> <Discard>
>
> I think that it would be better if instead of permanently adding it to
> the default location another one is created for those repositories. This
> way the package manager could easily switch between the "default" and
> "unsafe repositories" modes offering possibility to use them only when
> user wants to do so. But technically this is only a cosmetic change and
> probably analogous behavior could be achieved with some wise package pin
> settings.

No, I think this is a good idea.
Especially because you can have the default file for manual editing and just 
rewrite the other whenever necessary.

And if the applications does something wrong during writing, it only destroyes 
the "unsafe" file. The application could even store the additional sources in 
a different format and generate the "unsafe" file when needed.

Cheers,
Kevin

-- 
Kevin Krammer <[email protected]>
Qt/KDE Developer, Debian User
www.mrunix.de - Unix/Linux programming forum
www.qtforum.org - Qt programming forum

_______________________________________________
kde-debian mailing list
[email protected]
https://mail.kde.org/mailman/listinfo/kde-debian
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQBADD4snKMhG6pzZJIRAgsUAJ0R/DXr8gAOHsCi9ixtDr7OJV4dngCdGzJl
U2SmizmodeTX1eA1KOx2544=
=E7A1
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.