Browse Source

default to --no-check for dpkg-source call

In bug #757534 the opposite direction was initially requested, but what
we did end up with was having a possibility to configure the options
passed to dpkg. The reasoning given their and in #724744 is specific why
apt doesn't need the checks to be performed by dpkg. In fact, what these
two reports show is that if those checks are run people end up being
confused about the requirement of them being run, so given the best case
those checks can do is do nothing (visibly) while the worst cases are
warnings and errors which are neither we are from a security point
better of with disabling them – as (as mentioned in the bugreports)
false positives for issues are really really bad in a security context.

Closes: 724744
tags/debian/1.4_beta3
David Kalnischkies 4 years ago
parent
commit
d20643cc0a
1 changed files with 1 additions and 1 deletions
  1. +1
    -1
      apt-private/private-source.cc

+ 1
- 1
apt-private/private-source.cc View File

@@ -520,7 +520,7 @@ bool DoSource(CommandLine &CmdL)
else
{
// Call dpkg-source
std::string const sourceopts = _config->Find("DPkg::Source-Options", "-x");
std::string const sourceopts = _config->Find("DPkg::Source-Options", "--no-check -x");
std::string S;
strprintf(S, "%s %s %s",
_config->Find("Dir::Bin::dpkg-source","dpkg-source").c_str(),


Loading…
Cancel
Save