Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

2008-11-12 Thread demerphq
2008/11/13 chromatic <[EMAIL PROTECTED]>: > On Wednesday 12 November 2008 22:36:31 demerphq wrote: > >> > I really, really, really don't want PAUSE modifying my stuff after it's >> > uploaded. Oh god the mysterious bugs. And then there's the fact that >> > the code I've put my name and signature

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

2008-11-12 Thread chromatic
On Wednesday 12 November 2008 22:36:31 demerphq wrote: > > I really, really, really don't want PAUSE modifying my stuff after it's > > uploaded.  Oh god the mysterious bugs.  And then there's the fact that > > the code I've put my name and signature on is not the same code as is > > being distribu

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

2008-11-12 Thread demerphq
2008/11/13 Michael G Schwern <[EMAIL PROTECTED]>: > Jonathan Rockway wrote: >> * On Wed, Nov 12 2008, David Golden wrote: >>> On Wed, Nov 12, 2008 at 3:17 PM, demerphq <[EMAIL PROTECTED]> wrote: IMO if the toolchain is to work this should happen at PAUSE (if it can detect this problem IMO

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

2008-11-12 Thread Michael G Schwern
Andreas J. Koenig wrote: >> On Wed, 12 Nov 2008 19:13:40 -0800, Michael G Schwern <[EMAIL >> PROTECTED]> said: > > > Now that the CPAN shells and archiving modules are handling it at their > end, I > > think the PAUSE filter should be removed. It's not PAUSE's job to be the > code

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

2008-11-12 Thread Michael G Schwern
David Golden wrote: > On Wed, Nov 12, 2008 at 3:17 PM, demerphq <[EMAIL PROTECTED]> wrote: >> I rather strongly object to this change. > > I totally understand -- but keep in mind that this was in response to > someone flagging this as a potential (if highly unlikely) security > hole, forwarding i

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

2008-11-12 Thread Michael G Schwern
Jonathan Rockway wrote: > * On Wed, Nov 12 2008, David Golden wrote: >> On Wed, Nov 12, 2008 at 3:17 PM, demerphq <[EMAIL PROTECTED]> wrote: >>> IMO if the toolchain is to work this should happen at PAUSE (if it can >>> detect this problem IMO it should just damn well fix it itself) or at >>> extra

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

2008-11-12 Thread Jonathan Rockway
* On Wed, Nov 12 2008, David Golden wrote: > On Wed, Nov 12, 2008 at 3:17 PM, demerphq <[EMAIL PROTECTED]> wrote: >> IMO if the toolchain is to work this should happen at PAUSE (if it can >> detect this problem IMO it should just damn well fix it itself) or at >> extraction. > > It *is* being fixed

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

2008-11-12 Thread demerphq
2008/11/12 David Golden <[EMAIL PROTECTED]>: > On Wed, Nov 12, 2008 at 3:17 PM, demerphq <[EMAIL PROTECTED]> wrote: >> I rather strongly object to this change. > > I totally understand -- but keep in mind that this was in response to > someone flagging this as a potential (if highly unlikely) secur

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

2008-11-12 Thread David Golden
On Wed, Nov 12, 2008 at 3:17 PM, demerphq <[EMAIL PROTECTED]> wrote: > I rather strongly object to this change. I totally understand -- but keep in mind that this was in response to someone flagging this as a potential (if highly unlikely) security hole, forwarding it to some security-watchdog sit

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

2008-11-12 Thread demerphq
2008/10/1 Andreas J. Koenig <[EMAIL PROTECTED]>: >> On Tue, 30 Sep 2008 17:11:00 -0500, Jonathan Rockway <[EMAIL PROTECTED]> >> said: > > >> Anyway, I think the average CPAN author doesn't > >> really know or care about that, sadly. > >> See also > > > FWIW, this is true. I have never