Re: Re: php-pear .rpm install format
| From: | Stig S. Bakken | Date: | Wed, 09 Oct 2002 22:42:17 +0000 |
| Subject: | Re: Re: php-pear .rpm install format | ||
| References: | 1 2 3 4 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-9973@lists.php.net to get a copy of this message | ||
On Thu, 2002-10-10 at 00:11, Manuel Lemos wrote:
> Hello,
>
> On 10/08/2002 03:47 AM, Stig S. Bakken wrote:
> >>>Hi guys, I was wondering to know how to install pear from rpm?
> >>>
> >>>Will this be available?
> >>>
> >>>That's because it is more flexible to install, it checks dependencies,
> >>>increase file security, etc.
> >>
> >>Yes, that has been proposed by several people. It would make it easier
> >>for PHP/PEAR to have greater acceptance among platforms that use the RPM
> >>format.
> >>
> >>It also addresses the problem of the lack of cryptographic integrity
> >>that is currently not addressed by PEAR packages. Soon or later we will
> >>see the security bug busters claiming that anybody can hack the PEAR
> >>hackers and cause major security havoc because PEAR installer could not
> >>realized if a package have been hacked.
> >>
> >>Some people seem to reject the idea because they claim that RPM is not a
> >>natural format in all platforms. So it isn't tar.gz but that did not
> >>prevented from developing a basic tar archiver replacement.
> >>
> >>Adopting RPM would indeed avoid the need to re-invent the wheel. It is a
> >>natural format for shipping packages with all the features that are needed.
> >
> >
> > The PEAR package format is designed to be wrapped in other package
> > formats, such as RPM. Somebody just has to make a "pear2rpm" tool.
>
> Yes, it would make PEAR packages has greater acceptance in Linux
> distributions.
>
>
> > PEAR does also have support for package signatures (see "pear sign"
> > command), but we have a logistical problem in making sure everyone
> > supports some form of PGP signature verification. Signature
> > verification is not implemented yet, but I'll add that before PHP 4.3 /
> > PEAR 1.0.
>
> No, PEAR authors should not be allowed to sign. It should be something
> central off the PEAR site where the private key is safe, so all packages
> get the same certification. If you allows individuals to sign packages,
> they can hack other author packages and replace hacked versions in the
> main site just like somebody just did to sendmail.
That depends entirely which keys you sign with, and which keys the
installer is configured to trust.
> > And finally, the PEAR package format is _not_ re-inventing the wheel. A
>
> If you know apt-get working with RPM packages, you realize that PEAR
> remote downloading of packages is the same concept.
Sure, and like I said it should not be a big issue to wrap PEAR packages
in .rpm, .deb or maybe even svr4 .pkg formats.
- Stig
--
Stig Sæther Bakken, Fast Search & Transfer ASA, Trondheim, Norway
http://pear.php.net/wishlist.php/ssb