Re: A proposal for a package management system

"Gilles Espinasse" <[email protected]>
Newsgroups gmane.comp.security.ipcop.devel
Message-ID <021901ccde5a$0d718c70$f9b5a8c0@pii350>
----- Original Message ----- 
From: "Olaf Westrik" <weizen_42-Yz37vSk3/[email protected]>
To: <[email protected]>
Sent: Sunday, January 29, 2012 12:18 AM
Subject: Re: [IPCop-devel] A proposal for a package management system


> On 2012-01-24 08:28, Gilles Espinasse wrote:
>
> > Yes package management is for me a priority on next version (not 2.0.x,
> > probably 2.1)
>
> What for?
>
Faster update first.
We have fix for 2.0.3 that could have been delivered one month ago.

> Updating IPCop is extremely easy for users. Info is passed via
> ipcop-announce, after which 1 or 2 clicks are needed in the GUI.
>
> Having only one IPCop makes it easy to know what exactly someone is
> running in case help is asked.
>
I don't want to make everything optional. Just some packages could be user
selected.

> Preparing IPCop updates is work, but easier in v2 than it was in v1.4.
> Making a lot of small packages does not make the work any easier/faster.
>
Some package have very small dependencies and could be updated faster with a
package management than with the update system delivered when ready.

> I see no reason to make 'IPCop modules' that can be installed on demand.
> IPCop is small enough, and we try hard enough to keep it small, so that
> it can be installed on modest hardware.
>
> If someone believes a package management is helpful for addons, I
> suggest reviving the addon-server-project-thing.
> Probably better find out why it failed though, before investing time.
> If someone wants to install addons, that's fine, but it has to be clear
> that there is no such thing as an "IPCop-approved-addon".
>
>
> Olaf
>
Or you may consider I want to kill the addon-server and only have only
rightfully packaged code installed.
We need some flexibility.
Addon-server is an answer but does not always allow me to view the code
include in an addon, so I consider that not good enought.

With a minimal package management, I want good add-on be pushed in the
official tree (even not everything may enter).

I know IPCop is a firewall and it is not good to have everything installed.
I dream of a way to qualify the security of any package installed and to
qualify the security of the overall installation. I know that may be hard to
agree on a security note for some package. Is squid a risk or a solution in
a security point of view? Probably both, it depend of the point of view, of
the risk you want to protect.

The security note could be changed when a security issue is published. That
way, we would not care if a user stay with an old version, he would know his
machine may be vulnerable to some issues. That still remain his choice to
upgrade and when.
I am afraid this security note does not exist in package management, so we
may have to create one system to do that.

Gilles


------------------------------------------------------------------------------
Try before you buy = See our experts in action!
The most comprehensive online learning library for Microsoft developers
is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3,
Metro Style Apps, more. Free future releases when you subscribe now!
http://p.sf.net/sfu/learndevnow-dev2
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.