Chris Bainbridge wrote:
> On 08/06/06, Jon Portnoy <[EMAIL PROTECTED]> wrote:
>> I do very much object to using any gentoo.org infrastructure or
>> subdomains to do so. If someone is going to tackle that, it should be
>> done outside of Gentoo proper. We don't need to be stuck maintaining and
>> supporting a semiofficial overlay.
> 
> There are already loads of semi-official overlays. Besides the stuff
> actually hosted by gentoo (random example
> http://dev.gentoo.org/~flameeyes/bzr/overlay/) there are official
> groups (again, not picking on anyone but exampes would be java, php,
> webapps...) with semi-official overlays. I don't know if the overlays
> are actually hosted on gentoo hardware, but when they're run by gentoo
> devs, publically available, and referred to in forums, bugzilla,
> mailing lists etc. then that at least makes them "semi-official".

These overlays are completely controlled by Gentoo developers, which is
what the overlays.gentoo.org was going to be, simply a single location
for all these developer controlled overlays. This project is an overlay
(un)controlled by random users, with no quality checks or any standards
of any kind. This is fine for non-gentoo hosted stuff (like BMG), but
hosting stuff like this on *.gentoo.org, and not having the use go
through hoops to use it is probably not a good idea from either a
security or QA standpoint.

Currently 3rd party ebuilds can live in bugzilla, and the use must
create their own overlay, and generate their own digests to use them.
Making a user put this extra work into encourages users to be more
careful, and hopefully look stuff over before using it. It also
reinforces that the package is _unsupported_, hence discouraging them
from filing any new bugs.

Having a "semi-official" overlay where users can contribute ebuilds will
open possible security problems (malicious commits) as well as be a
QA/bug triaging nightmare as developers will have to figure out whether
the ebuild the user is using came from the "official" overlay or the
official tree.
-- 
gentoo-dev@gentoo.org mailing list

Reply via email to