Re: Re: php-pear .rpm install format
| From: | Manuel Lemos | Date: | Wed, 09 Oct 2002 22:11:50 +0000 |
| Subject: | Re: Re: php-pear .rpm install format | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-9972@lists.php.net to get a copy of this message | ||
Hello,
On 10/08/2002 03:47 AM, Stig S. Bakken wrote:
Yes, it would make PEAR packages has greater acceptance in Linux distributions.The PEAR package format is designed to be wrapped in other package formats, such as RPM. Somebody just has to make a "pear2rpm" tool.Hi guys, I was wondering to know how to install pear from rpm? Will this be available? That's because it is more flexible to install, it checks dependencies, increase file security, etc.Yes, that has been proposed by several people. It would make it easier for PHP/PEAR to have greater acceptance among platforms that use the RPM format. It also addresses the problem of the lack of cryptographic integrity that is currently not addressed by PEAR packages. Soon or later we will see the security bug busters claiming that anybody can hack the PEAR hackers and cause major security havoc because PEAR installer could not realized if a package have been hacked. Some people seem to reject the idea because they claim that RPM is not a natural format in all platforms. So it isn't tar.gz but that did not prevented from developing a basic tar archiver replacement. Adopting RPM would indeed avoid the need to re-invent the wheel. It is a natural format for shipping packages with all the features that are needed.
PEAR does also have support for package signatures (see "pear sign" command), but we have a logistical problem in making sure everyone supports some form of PGP signature verification. Signature verification is not implemented yet, but I'll add that before PHP 4.3 / PEAR 1.0.No, PEAR authors should not be allowed to sign. It should be something central off the PEAR site where the private key is safe, so all packages get the same certification. If you allows individuals to sign packages, they can hack other author packages and replace hacked versions in the main site just like somebody just did to sendmail.
And finally, the PEAR package format is _not_ re-inventing the wheel. AIf you know apt-get working with RPM packages, you realize that PEAR remote downloading of packages is the same concept.
separate format, with package contents and meta-information easily separately available, was a conscious design decision, made from the reasoning that other package formats are in practice too bound to their native operating system, and that it's better to provide something portable that these package systems can wrap. I have no immediate desire to port RPM to Windows ME or Darwin, breaking the problem up makes much more sense.Nor I suggested you to do so. -- Regards, Manuel Lemos