Re: Packages built with unchecked dependencies

2008-07-27 Thread Roger Leigh
On Thu, Jul 24, 2008 at 09:19:24AM +0100, Enrico Zini wrote: > Then I tried sbuild to build using my schroot setup, and found that by > default it disables signature checking. So I stopped using sbuild until > I find a way to reenable it. Just to follow up: - sbuild initially copied what the bui

Re: Packages built with unchecked dependencies

2008-07-25 Thread Enrico Zini
On Fri, Jul 25, 2008 at 10:08:57AM +0100, Enrico Zini wrote: > It seems that you can't, in my version of sbuild, unless you patch the > code. ...and if you want to patch the code, you can actually do it using the patch that I've just prepared and sent at http://bugs.debian.org/cgi-bin/bugreport.

Re: Packages built with unchecked dependencies

2008-07-25 Thread Enrico Zini
On Fri, Jul 25, 2008 at 10:57:40AM +0200, Peter Palfrader wrote: > On Thu, 24 Jul 2008, Enrico Zini wrote: > > and found that not even our buildds check signatures > The reason they do this is that they build from incoming > (queue/accepted). And incoming is not signed. I asked Ryan and Joerg > i

Re: Packages built with unchecked dependencies

2008-07-25 Thread Enrico Zini
On Fri, Jul 25, 2008 at 09:49:00AM +1000, Brian May wrote: >> Am I the only one that feels very, very uncomfortable about this? > Yes. Errr... I mean... No! It also makes me uncomfortable too. If there > is some good reason, I don't know what it is. Even if the network path > was completely tr

Re: Packages built with unchecked dependencies

2008-07-25 Thread Peter Palfrader
On Thu, 24 Jul 2008, Enrico Zini wrote: > and found that not even our buildds check signatures The reason they do this is that they build from incoming (queue/accepted). And incoming is not signed. I asked Ryan and Joerg if that could be changed a few weeks ago and they said they'd look into it

Re: Packages built with unchecked dependencies

2008-07-24 Thread Raphael Geissert
Enrico Zini wrote: > Hello, > Hi,Hhi > > Am I the only one that feels very, very uncomfortable about this? Nope: http://thread.gmane.org/gmane.linux.debian.devel.general/121242 > > > Ciao, > > Enrico > -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trou

Re: Packages built with unchecked dependencies

2008-07-24 Thread Brian May
Enrico Zini wrote: Then I tried sbuild to build using my schroot setup, and found that by default it disables signature checking. So I stopped using sbuild until I find a way to reenable it. [...] and found that not even our buildds check signatures, and since I understand that they don't a