From: Ben Giddings Date: 2003-07-29T00:02:16+09:00 Subject: Re: install questions On Mon July 28 2003 9:43 am, Hal E. Fulton wrote: > 1. Automatic installation of dependencies. > In the absence of a good mechanism for > handling dependencies (in install.rb or > raa-install or elsewhere) -- we could always > handle it explicitly. Supposing an app X > needed libraries Y and Z -- we could write > pre_setup.rb so that it in effect did this: > - check for Y and Z > - prompt user: perform auto-install? > - try to install over net (via raa-install > or whatever) > What do you think? I'm not completely sure I understand the question. Are you saying that if install.rb / raa-install doesn't automatically install the needed dependencies, that something else would, and if so, what? From a user-interface point of view, I like the way it works for Perl's CPAN, so that model might be a good place to start. I think there are some tweaks to the way that CPAN works that would be useful, but overall it makes installing big, complex packages with cascading dependencies pretty easy. Some of the key CPAN features include: * a number of different mirrors so you can choose one close to you * remembering settings so that next time it behaves the way you like * searching mechanisms > 2. A separate issue: I've been trying to think > what might be involved in writing an install > for a CGI (something I've never done). Some > issues are: > - How do we know what server is being used? > - How do we find the CGI directory? > - What about naming issues, e.g., Apache sometimes > wants a .cgi extension? > - File/directory ownership and permissions: How to > make everything accessible as needed without > introducing security holes? Knowing what server is being used: * Do a 'ps' to find out what services are running and try to match against common web servers * Search for typical default install directories / config files * Ask the user Finding the CGI directory: * If the server is Apache, finding this from the config file is relatively easy, and finding the config file shouldn't be too hard either ben% grep ScriptAlias /etc/httpd/conf/httpd.conf |grep -v "^#" ScriptAlias /cgi-bin/ "/var/www/cgi-bin/" As for other servers, I don't know. For naming issues, if I remember correctly, Apache only requires a .cgi extension if the script isn't in a CGI directory, and that's because it uses that extension as a MIME type that tells it to execute the file rather than sending its contents. I don't think a CGI installer should really try to handle this case. As for permissions, if the file is installed as executable in the CGI directory, it should be up to the user and the CGI writer to ensure that things are secure. I'm not sure I understand the issue here. Ben