> The process for getting unstable ebuilds from bugzilla to portage could
> even be automated to the extent that when an ebuild is put into
> bugzilla it gets auto committed to the tree but masked unstable.

I don't think that auto committing user submitted ebuilds is safe,
even if they are masked. For instance, someone could put something
malicious in global scope in the ebuild. Stuff in global scope gets
interpreted whenever the ebuild is sourced. More info on scope:
http://www.gentoolinux.org/proj/en/devrel/handbook/handbook.xml?part=3&chap=1#doc_chap3_sect4

-Thomas

-- 
gentoo-dev@gentoo.org mailing list

Reply via email to