On Sat, 25 Nov 2023 18:56:03 +0100 Christoph Anton Mitterer wrote:

> The most recent upgrade forces people to use
> update-smart-drivedb by doing it already in the postinst and not leaving it
> up to the user whether he wants to use such a tool.
> 
> Security-wise this is really a bad idea.
> 
> Downloader packages (i.e. packages that install further code from
> outside Debian) - and this effectively just that - are generally questionable.

You have missed the documentation of the --install option that the
postinst uses, it just copies the file from /usr to /var when the
/usr file is newer than the /var file, it does not download any files.

Previously the postinst was always force copying from /usr to /var,
now it only does the copying when the /usr file is newer.

I suggest that this bug be closed.

-- 
bye,
pabs

https://wiki.debian.org/PaulWise

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to