LWN.net Logo

Fedora 12 to remove unprivileged package installation

Fedora 12 to remove unprivileged package installation

Posted Nov 20, 2009 4:11 UTC (Fri) by mmcgrath (guest, #44906)
Parent article: Fedora 12 to remove unprivileged package installation

A couple of things about this in case this article turns into another thread of doom.

1) Fedora has no policy at present regarding what actions a user should be able to take without root access and I suspect most if not all other distributions don't have a written policy either. Though one may be in the works for us.

2) The package maintainers introduced this early on in the F12 lifecycle. That no one caught it and complained is a fault of the lifecycle, not the maintainers.

3) Fedora 12 was released on Tuesday, it's now Thursday and problem has been taken care of and all of us (not just in Fedora) will be giving second thoughts to things like this in the future. Kudos for the quick response, I'd like to think we're all better for it.


(Log in to post comments)

Fedora 12 to remove unprivileged package installation

Posted Nov 20, 2009 4:16 UTC (Fri) by rahulsundaram (subscriber, #21946) [Link]

On 2), noone caught this before because Rawhide packages are unsigned making PackageKit prompt for password and also because those of who choose to retain the authorization while entering the password for the first time wouldn't notice the difference after an upgrade. So it's not the fault of the lifecycle. Maintainers are certainly responsible for announcing and documenting the changes properly.

Fedora 12 to remove unprivileged package installation

Posted Nov 20, 2009 6:41 UTC (Fri) by pabs (subscriber, #43278) [Link]

Uhh, unsigned packages doesn't sound good.

Fedora 12 to remove unprivileged package installation

Posted Nov 20, 2009 6:56 UTC (Fri) by rahulsundaram (subscriber, #21946) [Link]

Just to be clear, Rawhide is the development branch of Fedora.

Fedora 12 to remove unprivileged package installation

Posted Nov 22, 2009 11:40 UTC (Sun) by pabs (subscriber, #43278) [Link]

I knew that before my post :)

Fedora 12 to remove unprivileged package installation

Posted Nov 20, 2009 6:55 UTC (Fri) by bojan (subscriber, #14302) [Link]

> 2) The package maintainers introduced this early on in the F12 lifecycle. That no one caught it and complained is a fault of the lifecycle, not the maintainers.

Question: did official release notes of Fedora 12 (i.e. on the day it came out) have information about this or not?

Fedora 12 to remove unprivileged package installation

Posted Nov 20, 2009 6:58 UTC (Fri) by rahulsundaram (subscriber, #21946) [Link]

No. If you read Owen Taylor's mail, that has been made explicit. A release note update pushed as soon as soon as we were aware of the changes needed to revert it.

Fedora 12 to remove unprivileged package installation

Posted Nov 20, 2009 7:05 UTC (Fri) by bojan (subscriber, #14302) [Link]

> No.

Right. I think that may be half the problem here. If it was in release notes, more people would pick it up before the release.

Fedora 12 to remove unprivileged package installation

Posted Nov 20, 2009 7:09 UTC (Fri) by rahulsundaram (subscriber, #21946) [Link]

Yes, which is my point if you read

http://lwn.net/Articles/362998/

Fedora 12 to remove unprivileged package installation

Posted Nov 20, 2009 7:26 UTC (Fri) by bojan (subscriber, #14302) [Link]

Yeah, that's the thing I wasn't sure of, whether there actually was something in the notes or not, because the documents are on the web and they are subject to change. I don't remember seeing anything, but I didn't read every single line (I upgraded a few days before the official release).

Thanks for the confirmation.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds