Re: R: Re: Calling autoconf in a spec.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sun, Jul 03, 2011 at 11:09:06PM -0400, Tom Lane wrote:
> Kevin Kofler <kevin.kofler@xxxxxxxxx> writes:
> > FWIW, I think we should actually run autoreconf -i -f in ALL specfiles as a 
> > matter of policy, even if we aren't changing anything,
> 
> To what end?  If you need to change configure.ac, that's one thing ...
> but if you don't, you're just uselessly exposing yourself to risks.

I suspect Kevin's concern is that someone stuffs some hidden shell
code into ./configure which isn't in configure.ac.  (Of the "send all
your private ssh keys to remote host" variety).

This concern has some legitimacy.  But OTOH someone could stuff the
same code into configure.ac or Makefile.am, and it's likely very few
people would notice.

Rich.

-- 
Richard Jones, Virtualization Group, Red Hat http://people.redhat.com/~rjones
Read my programming blog: http://rwmj.wordpress.com
Fedora now supports 80 OCaml packages (the OPEN alternative to F#)
http://cocan.org/getting_started_with_ocaml_on_red_hat_and_fedora
-- 
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/devel


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux