From: Paul Wise Date: Thu, 19 Mar 2015 04:59:06 +0000 (+0800) Subject: Do not use the apt-get --force-yes option as it is dangerous and insecure. X-Git-Url: https://git.adam-barratt.org.uk/?a=commitdiff_plain;h=5217ca6753299c68a6fab40041c89e0a6779dc78;hp=307566d8520cbdf3c2b060f10f31951905eae7bc;p=mirror%2Fdsa-puppet.git Do not use the apt-get --force-yes option as it is dangerous and insecure. This option causes apt's OpenPGP signature checks as well as other errors to be warned about but ignored. --- diff --git a/modules/schroot/files/setup-dchroot b/modules/schroot/files/setup-dchroot index 2632d1551..861c4a3e7 100755 --- a/modules/schroot/files/setup-dchroot +++ b/modules/schroot/files/setup-dchroot @@ -312,7 +312,7 @@ esac chroot "$rootdir" apt-get update -chroot "$rootdir" apt-get install -y --force-yes --no-install-recommends policyrcd-script-zg2 +chroot "$rootdir" apt-get install -y --no-install-recommends policyrcd-script-zg2 cat > "$rootdir/usr/local/sbin/policy-rc.d" << 'EOF' #!/bin/sh @@ -331,9 +331,9 @@ while true; do done EOF chmod +x "$rootdir/usr/local/sbin/policy-rc.d" -[ -z "$bare" ] && [ -z "$ubuntu" ] && chroot "$rootdir" apt-get install -y --force-yes --no-install-recommends locales-all -chroot "$rootdir" apt-get install -y --force-yes --no-install-recommends build-essential -[ -z "$bare" ] && chroot "$rootdir" apt-get install -y --force-yes --no-install-recommends zsh less vim fakeroot devscripts gdb +[ -z "$bare" ] && [ -z "$ubuntu" ] && chroot "$rootdir" apt-get install -y --no-install-recommends locales-all +chroot "$rootdir" apt-get install -y --no-install-recommends build-essential +[ -z "$bare" ] && chroot "$rootdir" apt-get install -y --no-install-recommends zsh less vim fakeroot devscripts gdb rm -f "$rootdir/etc/apt/sources.list" "$rootdir/etc/apt/sources.list.d/*" chroot "$rootdir" apt-get clean umount "$rootdir/dev" 2>/dev/null || true