Gentoo Archives: gentoo-dev

From: Matt Turner <mattst88@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] integrity of stage files
Date: Sun, 09 Oct 2011 00:22:38
Message-Id: CAEdQ38E-dDbgUkNzhuCSp9Sgzv+QaJUCAQ3pbUrHEqJPeu03kg@mail.gmail.com
In Reply to: Re: [gentoo-dev] integrity of stage files by "Robin H. Johnson"
1 On Sat, Oct 8, 2011 at 6:43 PM, Robin H. Johnson <robbat2@g.o> wrote:
2 > On Sat, Oct 08, 2011 at 02:45:02PM -0700, "Paweł Hajdan, Jr." wrote:
3 >> I checked
4 >> <http://www.gentoo.org/doc/en/handbook/handbook-x86.xml?part=1&chap=5>
5 >> and the Handbook only mentions validating MD5 checksums.
6 >>
7 >> There are two possible issues:
8 >>
9 >> 1. Why are we using _only_ MD5 and SHA1 as the checksums? Shouldn't we
10 >> be using something stronger?
11 > Fixed in Catalyst now.
12 > http://git.overlays.gentoo.org/gitweb/?p=proj/catalyst.git;a=commit;h=42b4f6608682cf03954918ecce7923330a1656fe
13 > So when the stagebuilders update their Catalyst, they will be generated
14 > with newer hashes.
15
16 Well, almost.
17
18 The changes you made are in the master branch (for catalyst-3), but
19 since catalyst-3 isn't really going anywhere fast, you should
20 cherry-pick your patches back to the catalyst_2 branch so they'll be
21 available in the next 2.0.6.919 release.
22
23 Matt

Replies

Subject Author
Re: [gentoo-dev] integrity of stage files "Robin H. Johnson" <robbat2@g.o>