-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Brian Harring wrote:
> On Mon, Aug 22, 2005 at 11:59:54PM +0200, Marius Mauch wrote:
> 
>>On 08/22/05  Brian Harring wrote:
>>
>>
>>>On Mon, Aug 22, 2005 at 11:33:23PM +0200, Marius Mauch wrote:
>>>
>>>>Theoretical discussions about this are pointless IMO without
>>>>numbers/facts to back things up.
>>>
>>>I'd posit theroetical discussions about this are pointless without 
>>>getting ebuild dev's to give a yay/nay on whether they want it or not;
>>>
>>>not much for trying to force it down their throats if they don't want 
>>>it (more work, essentially).
>>
>>That too. But providing them with some numbers will certainly have an
>>effect on their decision (especially if it shows that it doesn't really
>>affect them ;)
> 
> Rather hard to back it up though, without specialized knowledge in 
> (effectively) the whole tree- either we do it, or we ask nicely those 
> who are supposed to have such knowledge :)
> 
> I can rattle off a couple of env vars that screw things up, but how 
> many of us are aware that an exported ARCH screws with kernel builds 
> fex?
> 
> I'd punt it to them, and find out what they think (tiz the route I 
> took when I brought this up last).
> 
> Explicit whitelisting is great for getting closer to deterministic 
> builds, but it's a helluva overhead on a side note.
> ~harring

I'm kinda with genone on implementing both ( since they are similar ).
If it's decided that blacklisting is easier to maintain, I can always
make up my own whitelist for pkg-foo and apply it and if it works submit
it as a bug ( or even some other whitelist database? ) and thus can
gaurentee that my package was built 'correctly'(TM).  I think this would
be important in fex, an enterprise distribution type deal where the
build env is important to some.  Put the whitelists in the tree and have
them --excluded by default, so only the users that use them have to
downlaod them.

Regardless I'd like to see what actual people who write and manage
ebuilds think, I've only written a few and I don't have much experience
in that area.  ( Spanky, solar, etc... the crazy ones ) :)

- -Alec Warner (antarus)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iQIVAwUBQwpTUmzglR5RwbyYAQKPOA/+PbhtDYbbasHP9ZDa2SwTN+YVQRfXEfBt
QwqjmtmdSyGSsLJL7C5PtASL/lLUK0z6uI2LmCniHctvIzvHd7/dAZO8deq4Hqcb
18CgXZucwqvGnLhPIC23Z7CTXb3dUf60WTbwjkP4vTmywRtWr3eOqGIZ03pgjrBr
GDtb+onEGn8lSMxdqRuUxCvFnyz+QIaX2ysOahH/qKRIcJXh4w/zFQrDy+9olSpy
CAkaZLrOplRKZSSkz5i/W1dpKioa7fa3FXD43a7uWXzoRsLNxivyhNqtJJ34rnPI
UexjElpelGlnw4zdDGzq5waYDpwUPfme8vz4pHEZ0MtqGQZ7OCsl3Pnz5q44Z7Vd
cwN5+limQGN0dg55kYgbx+pOm0TRi5u9iAHMdlLojxD9e29AeGpRijeaWfm6ZuRk
MEQrBJMFkhm4BaOuZ8+lcmaso1SxsfdQnlEnwXBVnjt2uoqy/G14wGPxye+gb3tL
kUqBhB+DNH8RMO6Sgu+DDTsLT2vx7w7MV7XMQorBD6g4nvIxdl5OR13sI0Yo+gnt
RF6BlM7eShMrx9aYx9Xr97F9XuBH8tIOKzpSqPK+O/cevJVVu6IwSU8VyPW2o0Rr
rKCwS04vrYSwkfpvNgChNHSqhk08NKcBIQD4sLvrMZpp70OyGXgMTvryUxjzgejA
Tb1Woep3gYk=
=Q3sT
-----END PGP SIGNATURE-----
-- 
[email protected] mailing list

Reply via email to