4 ms·
That title had me worried, but the reality seems quite reasonable. I assumed the goal was to reduce usage of AUR, they've actually remove the ability to adopt
by delecti 2mo ago
That title had me worried, but the reality seems quite reasonable.
I assumed the goal was to reduce usage of AUR, they've actually remove the ability to adopt (take ownership of) orphaned packages. I'm sure there are legitimate uses of that functionality, but it also seems like a pretty big avenue for abuse.
- OJFord 2mo agoI've used it (not for abuse). It's simply volunteering to maintain the package after previous maintainer(s) have explicitly disowned it, knowing they no longer have time for it or don't care because they stopped using it, etc.
- gchamonlive 2mo agoProblem is that there is no KYC process before someone can adopt any orphaned package
- OJFord 2mo agoYeah, I don't disagree there should be more of a barrier, I remember being surprised I could just adopt things. Just explaining the intended use.
- yjftsjthsd-h 2mo agoThere's also no KYC process for creating one.
- OJFord 2mo agoThere is more risk in someone adopting something with established users though. Some people (cough) might be a bit less careful if they see something has tonnes of users, votes, comments; people actively using and liking the package.
- ameliaquining 2mo agoYeah, the security problems with unilateral adoption of orphaned packages by unprivileged users are fundamental and unfixable; the only remedy is to remove the feature. Whether it has legitimate use cases (which it sounds like it does) is irrelevant. I'm not sure why it took them so long to realize this and act accordingly, but I'm glad they now have.
- jolmg 2mo ago> I'm sure there are legitimate uses of that functionality To avoid package name pollution, e.g. having package foo, foo-newpackage, foo-newpackage-updated, etc. each by a new maintainer as the priors get abandoned.
- tremon 2mo agoWith a bit more structure, you could change that to: every package in AUR is actually registered as foo/maintainer under the hood, and installing the package without maintainer name pins it to the currently active version. Package adoption can then be formalized as a new maintainer publishing their own version of the package, and users of an already-installed package need to issue an explicit command to switch over to the new maintainer's version.
- Pay08 2mo agoOr, have actual user repos like a normal distro.
- ptx 2mo agoWhat do you mean? Their package manager allows you to add additional repositories, if that's what you want.
- yjftsjthsd-h 2mo agoHow is that different?
- jolmg 2mo agoThey do. There's a list of them on the Arch Wiki: https://wiki.archlinux.org/title/Unofficial_user_repositories https://wiki.archlinux.org/title/Unofficial_user_repositorie... The problem with user repos vs the AUR is that you're trusting the maintainer behind them instead of inspecting the PKGBUILD and fetched sources yourself.
- Pay08 2mo ago
- bee_rider 2mo agoIMO allowing package adoption makes sense in the responsible/intended use-case: AUR packages aren’t trusted, you have to read the PKGBUILD anyway, so the reputation of the contributor doesn’t matter. Removing adoption is admitting that there’s no way to prevent some users from blindly trusting a PKGBUILD. Which is probably the best choice, unfortunately.