RPM

Comment 1 for bug 651483

Revision history for this message
In , Wade (wade-redhat-bugs) wrote :

Description of problem:

This may seem a little ranty sorry in advance.

Sysadmins rely on rpm -V for confidence in their system, not only to figure out
if they have been hacked, but also to understand what has changed for backup and
change control understanding.

In the RHEL 5 lifecycle, multi-arch, sloppy programming and prelinking has made
the rpm verify command useless to most sysadmins, it can no longer be relied on
as a measure of change in a system.

The breakage comes in both initial package deployment and package updating,
attacking each package would be a mammoth job for any single person. So I ask,
because I honestly have no idea, how do we make this useful again for end users ?

If we don't plan to make it useful, we might as well remove it from the RPM
package and accept that we don't plan to track packages individual file changes.

So, where to from here ?