> - #5 AFAICS this set[uh]id is all just prep code (see setuid below)

Yeah I mean it's bindings for the standard library/system calls,
obviously setuid and friends are in those crates, but as long as we
don't call them we'll be fine. It's the same for all Rust packages.

> - #6 @security: I have to accept the statement littered all over
d/rules "dh-cargo-built-using is horribly broken ..." but at the end of
the day I'm unsure how in this flux the seucrity team tracks things

It's a bit confusing but we have a patched cargo-built-using and cargo
script. This is cleaner in the packaging repo which imports them from
the dh-cargo package and then patches them in logical commits - and
these are hooked into the build.

> - #9 You need to decide what to do about libupki-openssl-dev and
libupki-dev.

I don't quite remember what the goal is for them. What does it mean for
a -dev package to be in main? Probably that we support people building
against it externally. Which I think we do want.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166514

Title:
  [MIR] upki

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/upki/+bug/2166514/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to