Re: Re: [Zynot-pkgmgr] Repoteus: Zynot Tree Vision

jesse <[email protected]> 14 Jul 2003 22:15:08 -0700
Newsgroups gmane.linux.zynot.zynaut
Message-ID <[email protected]>
--===============81919378294100653==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature";
	boundary="=-zVLPEkzHlDLnXNwi81vi"


--=-zVLPEkzHlDLnXNwi81vi
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Mon, 2003-07-14 at 19:13, Will Reid wrote:
> On Monday 14 July 2003 15:37, Mark Guertin wrote:
> > On 7/14/03 4:24 PM, "jesse" <[email protected]> wrote:
> > > If they are isgned by our devs who are on your keyring .. then you
> > > should be able to trust. Esp if it's got 2 or more valid sigs.
> > >
> > > Over any  distrib medium a package that had this requirement would be
> > > considered pristine. You would be able to check those sigs agains
> > > keyservers as well as your local copy of the pubkeys.you could trust
> > > that package if all those check were ok.
> > >
> > > If random joe-schmo  builds a binary and pops it on p2portage signed.=
 It
> > > doesnt give it any more credability in the eyes of porteous. ( not pa=
rt
> > > of or keysystem ).
> >
> > That given I would still never allow this on my system, signed or not
> > signed.  Also this would divert a lot of dev attention from working on =
the
> > distro proper.. Instead they would be building (and yielding TONS of em=
ails
> > from users if they signed the builds as good and they are not).  I know
> > this from experience doing this stuff with Gentoo.
> >
> > IMO this is something we should still avoid for now.
> >
> > If you haven't noticed I have problems with the whole concept of p2p
> > distribution of anything for an operating system, and I am not alone on
> > this stuff.
> >
> > If p2p ever gets implemented I for one will want HUGE guarantees that t=
he
> > option not only be able to be disabled, but that there also be a versio=
n of
> > the pkgmgr that this option literally does not even exist in.  One user
> > turning on something like this unchecked can have massive repercussions=
 on
> > a large LAN.  It goes against the grain in corporate environment in a v=
ery
> > big way here.
> >
> > Potentially this could make M$ email virii look tame from a security
> > standpoint...if one signed pkg gets compromised and distributed as trus=
ted
> > (signed) into a p2p system.  With p2p you have zero control after it ha=
s
> > gotten into nodes, that compromised build could live forever, revoking =
or
> > no.  At least on (semi) controlled mirrors we can properly revoke it if=
 the
> > need should ever arise.
> >
> > Mark
> >
> >
> > _______________________________________________
> > Zynaut mailing list
> > [email protected]
> > http://lists.zynot.org/mailman/listinfo/zynaut
>=20
> 	Just gonna add my thoughts.  I have a feeling that p2p implementation wi=
ll be=20
> so much extra design, coding, and implementation getting it to work that =
it=20
> should be put off for now.  And I agree there should be an option to disa=
ble=20
> the filesharing when p2p source file sharing is implemented.  Being on di=
alup=20
> I suffer whenever I have to upload a file.  Normally I end up lagging out=
,=20
> the file stalls, and all the time was wasted anyway.  My internet connect=
ion=20
> would be virtually unusable if multiple cable users tried to download X o=
r=20
> KDE from me (even in part).  And they'd likely never know, and I wouldn't=
=20
> have fun trying to figure out why google's front page takes 5 minutes to=20
> load. =20
>=20
> 	I would REALLY like to see binary packages available.  Not for every pac=
kage=20
> in the tree, but the base install (X and a few common WM also) at the lea=
st. =20
> Also it would be nice to have different CFLAGS for them.  Again, not=20
> everything.  i586, Pentium2, and Athlon for x86 would make many people ha=
ppy. =20
> You can always run `nice -n 19 emerge -e world` in a screen or VC once yo=
u're=20
> in X and going about your thing and want "better" CFLAGS and never notice=
=20
> your box was working.  A 6 hour base install on the average speed box is=20
> enough to scare a lot of users away when they find out that's without Xfr=
ee. =20
> Basically the run down of how I think things will/should/could look soon:
> Stage1 - Build it all yourself.
> Stage2 - You have a compiler and a few libraries.
> Stage3 - Working Non-X box (sans kernel)
> Stage4 - Working X box with your choice of WM available as a seperate bin=
ary=20
> to keep the stage tarball size down (also no precompiled kernel)
> Stage5 - Quick Install, bloated, bubblie crap that people new to the dist=
ro=20
> want to give it a quick try.  X, KDE/Gnome, desktop apps a plenty, prebui=
lt=20
> modularized kernel.  Basically whatever the devs can stuff in a 640/700MB=
=20
> ISO. =20
>=20
> 	Yes, the "stage5" I recommend will be very large and use up much bandwid=
th,=20
> but most users will likely avoid ever downloading it.  Only those that ne=
ed=20
> it to just get their box up and running quickly to try out Zynot (or what=
ever=20
> it will be called then) will pick this install method.  We could even loo=
k at=20
> something like jidgo (which debian uses to make CD-r and DVD-r ISOs) to=20
> create the "stage5" installer CDs on the fly from multiple source servers=
. =20
> The problem with jidgo is its complicated usage.  Ok  I'm starting to ran=
t,=20
> so I'll stop on this unless anyone requests more out of me. :)
>=20
> 	This is probably getting way off-topic, but the last thing I'd like to=20
> suggest is a GUI installer.  If anyone can point me to the right place to=
=20
> read up and learn how to code widgets I'd like to get involved in a gtk2=20
> installer project that will make people think they're installing somethin=
g=20
> officially better than RedHat because it's prettier and even easier ;) to=
=20
> install.
>=20
> --Will (Sif/SanityInFlux - if you didn't know)
>=20
dialog and sh make for really quick gui installers ( think redhat 5.2
6.2 )=20

Im doing a dialog installer for a contract right now. Its really pretty
simple to do once the helper functions are written, but unfortunatly it
wont be OSS..=20

Gtk/kde installers IMHO are just eyecandy.. :P
=20
> _______________________________________________
> Zynaut mailing list
> [email protected]
> http://lists.zynot.org/mailman/listinfo/zynaut

--=-zVLPEkzHlDLnXNwi81vi
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQA/E43c4rKvBkfUvb0RAgrwAJwLdEnAt55g9LS3X1CLIqjiwUj/ewCcD1F2
PAV9XnRe/l/OSQ4a2FD9A4k=
=j4sl
-----END PGP SIGNATURE-----

--=-zVLPEkzHlDLnXNwi81vi--


--===============81919378294100653==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Zynaut mailing list
[email protected]
http://lists.zynot.org/mailman/listinfo/zynaut

--===============81919378294100653==--