[Pkg-virtualbox-devel] Bug#553918: virtualbox-ose-source: Please, make dkms a recommendation.

Wolfgang Walter wolfgang.walter at stwm.de
Fri Nov 6 19:06:33 UTC 2009


Package: virtualbox-ose-source
Version: 3.0.10-dfsg-1
Severity: normal

virtualbox-ose-source now (without warning) uses dkms and calls it 
automatically.

This has several problems:

1) It builds (or at least tries to) the modules even if you do not want them 
for the kernel running on the machine. This is very common if you compile 
kernels and modules for several machines on a special machine.

2) It therefor runs as root. And it even does if /lib/modules/<installed 
kernel>/source points to a non privileged build directory which is a security 
problem.

3) If you built a different kernel  in /lib/modules/<installed kernel>/source/ 
you may get a problem.

virtualbox-ose-source should not depend on dkms. If dkms is not installed 
virtualbox-ose-source should not call it.

If dkms ist installed virtualbox-ose-source should ask if the user wishes to 
build the modules automatically at installation time or if he preferes to do 
so manually. (Maybe this should be a option for dkms itself).

For compatibility virtualbox-ose-source could install a traditional *.tar.bz2 
in /usr/src, btw.


Regards,
-- 
Wolfgang Walter





More information about the Pkg-virtualbox-devel mailing list