Re: Re: php-pear .rpm install format

From: Date: Wed, 09 Oct 2002 22:42:17 +0000
Subject: Re: Re: php-pear .rpm install format
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-9973@lists.php.net to get a copy of this message
On Thu, 2002-10-10 at 00:11, Manuel Lemos wrote: > Hello, > > On 10/08/2002 03:47 AM, Stig S. Bakken wrote: > >>>Hi guys, I was wondering to know how to install pear from rpm? > >>> > >>>Will this be available? > >>> > >>>That's because it is more flexible to install, it checks dependencies, > >>>increase file security, etc. > >> > >>Yes, that has been proposed by several people. It would make it easier > >>for PHP/PEAR to have greater acceptance among platforms that use the RPM > >>format. > >> > >>It also addresses the problem of the lack of cryptographic integrity > >>that is currently not addressed by PEAR packages. Soon or later we will > >>see the security bug busters claiming that anybody can hack the PEAR > >>hackers and cause major security havoc because PEAR installer could not > >>realized if a package have been hacked. > >> > >>Some people seem to reject the idea because they claim that RPM is not a > >>natural format in all platforms. So it isn't tar.gz but that did not > >>prevented from developing a basic tar archiver replacement. > >> > >>Adopting RPM would indeed avoid the need to re-invent the wheel. It is a > >>natural format for shipping packages with all the features that are needed. > > > > > > The PEAR package format is designed to be wrapped in other package > > formats, such as RPM. Somebody just has to make a "pear2rpm" tool. > > Yes, it would make PEAR packages has greater acceptance in Linux > distributions. > > > > PEAR does also have support for package signatures (see "pear sign" > > command), but we have a logistical problem in making sure everyone > > supports some form of PGP signature verification. Signature > > verification is not implemented yet, but I'll add that before PHP 4.3 / > > PEAR 1.0. > > No, PEAR authors should not be allowed to sign. It should be something > central off the PEAR site where the private key is safe, so all packages > get the same certification. If you allows individuals to sign packages, > they can hack other author packages and replace hacked versions in the > main site just like somebody just did to sendmail. That depends entirely which keys you sign with, and which keys the installer is configured to trust. > > And finally, the PEAR package format is _not_ re-inventing the wheel. A > > If you know apt-get working with RPM packages, you realize that PEAR > remote downloading of packages is the same concept. Sure, and like I said it should not be a big issue to wrap PEAR packages in .rpm, .deb or maybe even svr4 .pkg formats. - Stig -- Stig Sæther Bakken, Fast Search & Transfer ASA, Trondheim, Norway http://pear.php.net/wishlist.php/ssb

« previous php.pear.dev (#9973) next »