Re: Re: package validation (was Re: [PEAR-QA] Re: PHP_Beautifier-0.0.6.1
| From: | Stefan Neufeind | Date: | Fri, 04 Jun 2004 22:17:52 +0000 |
| Subject: | Re: Re: package validation (was Re: [PEAR-QA] Re: PHP_Beautifier-0.0.6.1 | ||
| References: | 1 | Groups: | php.pear.qa |
| Request: | Send a blank email to pear-qa+get-1376@lists.php.net to get a copy of this message | ||
On 4 Jun 2004 at 13:35, Greg Beaver wrote:
> Tomas V.V.Cox wrote:
>
> > Stefan Neufeind wrote:
> >
> >> On 4 Jun 2004 at 14:32, Tomas V.V.Cox wrote:
> >>
> >>
> >>> Stefan Neufeind wrote:
> >>>
> >>>
> >>> I didn't know that was even supported by the installer, maybe the
> >>> solution is just to restrict version numbers to three digits in
> >>> package.xml validation.
> >>
> >>
> >>
> >> Yes, to strictly restrict - no more and not less then three (afaik we
> >> had a two-digit-number recently as well). Volunteers that have maybe
> >> already worked on the package.xml-validation? Sounds like a quickfix
> >> to me ...
> >
> >
> > Well, is not trivial at all, remember that pear is not PEAR only. The
> > goal of pear (the pear cmd) is to be an universal installer for software
> > written in php, so we can't enforce our rules. Even with channels
> > comming fast this point will become worse.
> >
> > The pear installer needs urgently, apart of a decent DTD validation, one
> > of these two:
> >
> > a) Remove any PEAR coding standar rule that is hardcoded today.
> > b) Provide something like a plug-in system which validates the
> > package.xml fields according to the rules of each "channel" developers.
>
> You really need to check out the code in PEAR-1.4.0dev5.tgz, in
> particular PEAR_PackageFile and PEAR_ChannelFile classes. A package
> name validation regex is already in channel.xml and is fully supported
> by the installer.
>
> Far better than doing this in pre- and post- scripts is to leverage the
> existing power of polymorphism. Simply allow users to extend
> PEAR_PackageFile, and redefine the validation of package version. Most
> of this stuff should be server-side, and not in the pear packager, as
> things like this tend to change as the political decisions change.
Tomas, I was also thinking of doing this on the serverside. In my
understanding you were talking about the verify-step that takes place
when uploading a release.
> The only other alternative is to add a field to the channel.xml for
> describing version validation, which would be far more complex than I'm
> willing to deal with.
:-))
Stefan