On Wednesday, 07 February 2007 at 19:18, Jesse Keating wrote: > On Wednesday 07 February 2007 11:12, Dominik 'Rathann' Mierzejewski wrote: [...] > > > or even worse, insert some small thing in a package that gets pulled into > > > most buildroots that will further taint any more builds. Could be hard > > > to detect until it is far far too late. > > > > It would be stopped at the sign-and-push stage at worst. I'm sure there are > > many eyes following the cvs commits list. It would be spotted quite fast > > IMHO. > > You can prevent messages from being posted to cvs commits. So why isn't that fixed already? > > > With proper barriers in place, > > > the most damage a rouge user can do is to their own > > > package, or to any packages foolishly left wide open. > > > > I don't really mind the ACLs as much as I do mind having to go through > > another approval (for CVS import) after my package has ALREADY been > > APPROVED. > > You don't. Once your package is approved, appropriate people are notified and > setup the location so that you can do your import and build. What is so > difficult about this? Oh really? Since when? The Contributors page still says (after my package is APPROVED): ---cut--- Identify Yourself as the Owner of the Package Place your requests in the 'New Package' section at: * Extras/CVSSyncNeeded with: 1. The name of the package 2. Your bugzilla account e-mail address 3. A list of who, if anyone, should also be CC'd on bug reports 4. A pointer to the review ticket This will be used to set up the proper records in the owners database, which is used for access to build the package, bugzilla population, and other features. Once this is done, you may then import the package. ---cut--- This wasn't necessary before (I could just add myself to owners.list) and THAT's what I have issues with. Now I have to wait until someone manually add something I used to be able to add myself. And I'm NOT notified when this is done (or am I?). And no, subscribing to CVSSyncNeeded changes is NOT an option. Regards, R. -- Fedora Extras contributor http://fedoraproject.org/wiki/DominikMierzejewski Livna contributor http://rpm.livna.org MPlayer developer http://mplayerhq.hu "Faith manages." -- Delenn to Lennier in Babylon 5:"Confessions and Lamentations" -- Fedora-maintainers mailing list Fedora-maintainers@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-maintainers -- Fedora-maintainers-readonly mailing list Fedora-maintainers-readonly@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-maintainers-readonly