Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] integrity of stage files
Date: Sun, 09 Oct 2011 00:31:45
Message-Id: robbat2-20111009T003100-847412958Z@orbis-terrarum.net
In Reply to: Re: [gentoo-dev] integrity of stage files by Matt Turner
1 On Sat, Oct 08, 2011 at 08:21:44PM -0400, Matt Turner wrote:
2 > On Sat, Oct 8, 2011 at 6:43 PM, Robin H. Johnson <robbat2@g.o> wrote:
3 > > On Sat, Oct 08, 2011 at 02:45:02PM -0700, "Paweł Hajdan, Jr." wrote:
4 > >> I checked
5 > >> <http://www.gentoo.org/doc/en/handbook/handbook-x86.xml?part=1&chap=5>
6 > >> and the Handbook only mentions validating MD5 checksums.
7 > >>
8 > >> There are two possible issues:
9 > >>
10 > >> 1. Why are we using _only_ MD5 and SHA1 as the checksums? Shouldn't we
11 > >> be using something stronger?
12 > > Fixed in Catalyst now.
13 > > http://git.overlays.gentoo.org/gitweb/?p=proj/catalyst.git;a=commit;h=42b4f6608682cf03954918ecce7923330a1656fe
14 > > So when the stagebuilders update their Catalyst, they will be generated
15 > > with newer hashes.
16 >
17 > Well, almost.
18 >
19 > The changes you made are in the master branch (for catalyst-3), but
20 > since catalyst-3 isn't really going anywhere fast, you should
21 > cherry-pick your patches back to the catalyst_2 branch so they'll be
22 > available in the next 2.0.6.919 release.
23 Done already.
24
25 --
26 Robin Hugh Johnson
27 Gentoo Linux: Developer, Trustee & Infrastructure Lead
28 E-Mail : robbat2@g.o
29 GnuPG FP : 11AC BA4F 4778 E3F6 E4ED F38E B27B 944E 3488 4E85