Pacman-5.0 Released
allanmcrae.com
allanmcrae.com
>Do not start an open source project if you need praise, warmth and love from your fellow human beings. [ https://news.ycombinator.com/item?id=11053810 ]
>Folks forget that most FOSS work is volunteer & berating the hackers who make it won't help one bit. [ https://news.ycombinator.com/item?id=11054809 ]
I'd say:
> don't post anything publicly if you want only [warm fuzzy feelings]"
Only pacupg does, according to this. pacaur, cower, apacman, packer, and all the others (https://wiki.archlinux.org/index.php/AUR_helpers) don't.
I bloody well hope it asks before running unverified code off the internet with root permission!
It's sad that makepkg still uses MD5 by default in this day and age because "it's faster".
MD5 is good enough for that, and makepkg supports GPG for actual verification.
They should be using SHA-256, or Blake 2 if they think the extra seconds spent verifying matter, but insisting on using MD5 is pretty much going out of your way to increase your attack surface. There is no reason to use it in a modern system.
That's yaourt's problem, not makepkg's or the AUR's.
> They should be using SHA-256, or Blake 2 if they think the extra seconds spent verifying matter, but insisting on using MD5 is pretty much going out of your way to increase your attack surface.
It doesn't matter what algorithm you use, file hashes are not a security feature. Use GPG!
> It doesn't matter what algorithm you use
Of course it matters, they have different guarantees. A secure hash would at least guarantee that the file you get is the same one the packager got, MD5 doesn't. They are refusing to use strictly better alternatives out of pure stubbornness.
XferCommand = /usr/bin/printf 'Downloading ' && echo %u | awk -F/ '{printf $NF}' && printf '...' && /usr/bin/aria2c -q --allow-overwrite=true -c --file-allocation=none --log-level=error -m2 --max-connection-per-server=2 --max-file-not-found=5 --min-split-size=5M --no-conf --remote-time=true --summary-interval=0 -t5 -d / -o %o %u && echo ' Complete!'
It's fast, but doesn't have download progress. I had another one, which printed several lines of output per file (but did have progress!).My point is, the fact that you can make pacman download stuff quickly as-is, doesn't mean that inbuilt support wouldn't be beneficial for everyone who doesn't know how their downloading program works back-to-front.
I believe gentoo's emerge also has support (though I'm not as sure here as I typically have the downloads happen in the background while building).
The overall goal here is to more effectively utilize the available bandwidth on the client side even when there are limitations a given server.
It's great that we can customize how to download 1 package at a time. But there is room for improvement.
[1] https://wiki.archlinux.org/index.php/powerpill
Personally though, I've never had an issue with the performance of `pacman`. Even without parallel downloads I've found `pacman` generally outperforms most other package management tools I've used.
It pulls down all the updated packages but doesn't install. The packages are then ready for update when you are.
Sidenote: I am having trouble finding the link to an explanation what this really is. any help?
This is a package management tool for ArchLinux. Similar to 'yum' for RHEL. Or Debians 'apt-*', 'dpkg' tools.
It's great, it has a wonderful collection of libs, sometimes it can feel a little bit too cutting edge, but after the stagnation of Mingw I'm not complaining about that.
"Pacman" is abbreviated from "package manager" while "Pac-Man" is derived from "Puck Man", named so because the yellow avatar looked like a hockey puck. (the reason for the name change is quite interesting too[1]).
While it's true that the ArchLinux devs do play on the name similarities (there's even an easter egg to turn the `pacman` progress bar into a little Pac-Man eating up ASCII pills[2]), I think most people who might confuse the two wouldn't be familiar with the package manager anyway. And those who are familiar with `pacman` are likely technical enough to tell the difference.
[1] Renamed because of worries that some US audiences might vandalise the Puck into Fuck.
[2] Put 'ILoveCandy' (without quotes) under the [options] in /etc/pacman.conf
a) Arch Linux isn't selling pacman. b) I don't believe Namco still own a registered trademark for Pacman. And they probably don't make enough money from it for them to win a lawsuit about it (trademarks require a reasonable commercial interest in order to be protected).
So there almost certainly isn't a legal issue. IANAL.
[1] https://www.ipo.gov.uk/tmcase/Results/4/EU004977906
[2] https://www.ipo.gov.uk/tmcase/Results/4/EU000361600
https://www.youtube.com/watch?v=koLvoCMHCrI
From what I've heard on the inside, Raw Thrills has been actively working on new Pacman games based on the original 1980 source code given to them by Namco.
TLDR: They definitely still own the trademark and they are still making money on it.