[OpenIndiana-discuss] Repository semantics refinement
Reginald Beardsley
pulaskite at yahoo.com
Wed Sep 23 20:21:42 UTC 2026
I am undertaking an overhaul of the OI IPS repository operation. The following is as brief a statement of the absolutes of proper software repository management at enterprise scale as I can make.
I should be most interested in additional constraints anyone might wish to suggest or use cases that these would interfere with. My base operating environment case is big oil operations where failures can be fatal and requirements very dynamic and on time frames and in software environments that cannot allow a system update.
I am also getting concerned about so called "supply chain attacks" on repositories. Once I have implemented the framework for the listed items, adding additional safeguards is fairly simple. What I've outlined already blocks many such attacks. ZFS should cover the rest.
Have Fun!Reg
------------------------------------------------------------------------------------------------------------------------------------
The OI repositories should meet the following criteria:
1) Any package published in the repository in the interval between releases should be available indefinitely. Disk is cheap. Forcing a "pkg upgrade" to add one new package not installed when the system was built is not tolerable. Especially if you are on the end of a BW limited channel.
2) No package installed from the repository has missing files or dependencies.
3) No package installed from the repository modifies other packages.
4) No package modifies existing system configuration files without making a backup copy that does NOT overwrite a prior backup copy.
More information about the openindiana-discuss
mailing list