[Popcon-developers] Re: Reverting some popcon changes
Petter Reinholdtsen
pere at hungry.com
Sun Jan 8 14:09:11 UTC 2006
[Bill Allombert]
> Hello Petter,
>
> I plan to revert several changes you made:
Would it not be better to fix the problems instead of just removeing
the code?
> * Implemented sending of compressed MIME emails when recommended
> package mime-construct is installed. Disabled until the server
> side is implemented. (Debian bug #149425)
>
> Unless you intend to implement the server side soon, this is just
> cruft that make the script more complex than what is required.
Why do I need to do it soon? I plan to implement the server side
unless someone else beat me to it, but will probably not have time for
it in the near future.
> * Rewrote popularity-contest to use dpkg-awk if dpkg-query is
> missing. This make it compatible with dpkg versions before 1.10,
> getting it to work on woody, sarge, etch and sid. Drop
> versioned dependency on dpkg because of this.
>
> Since sarge is released we do not need the versioned dependency on
> dpkg anyway and backporting to woody is a bad idea since that cause
> woody installation to pretend beiing sarge. This is just useless cruft
> inside the popularity-contest script.
I still use the new popularity-contest on woody, and want the package
to work both in woody, sarge and etch. Because of this, I fail to see
how it is useless cruft. What do you mean by "woody installation to
pretend beiing sarge".?
> * The ubuntu versions are included in the source package as
> popcon-submit-ubuntu.cgi and popcon-upload-ubuntu.
>
> Given the Ubuntu version has a security hole we should not include it.
Do you have an URL to the bug report for this issue? Is it fixed in
the ubuntu package?
> * Add support in popcon-submit.cgi to save directly to disk instead
> of sending emails.
>
> This is cause the same security problem.
I use the direct save feature in the debian-edu popularity-contest
collector, and thus want to keep that script in the package. What is
the BTS number for this issue? I was unable to find any.
Btw, yes, I will probably have time to upload a new package today.
I'll have a look at the CVS.
Cc to the popcon mailing list, to get the archive updated with the
current plans.
Friendly,
--
Petter Reinholdtsen
More information about the Popcon-developers
mailing list