Gentoo Logo
Gentoo Spaceship

Installation:
Gentoo Handbook
Installation Docs

Documentation:
Home
Listing
About Gentoo
Philosophy
Social Contract

Resources:
Bug Tracker
Developer List
Discussion Forums
Gentoo BitTorrents
Gentoo Linux Enhancement Proposals
IRC Channels
Mailing Lists
Mirrors
Name and Logo Guidelines
Online Package Database
Security Announcements
Staffing Needs
Supporting Vendors
View our CVS

Graphics:
Logos and themes
Icons
ScreenShots

Miscellaneous Resources:
Gentoo Linux Store
Gentoo-hosted projects
IBM dW/Intel article archive




List Archive: gentoo-dev
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-dev@g.o
From: Ryan Hill <dirtyepic@g.o>
Subject: Re: RFC: lzma tarball usage
Date: Thu, 8 May 2008 19:04:10 -0600
On Thu, 08 May 2008 09:17:08 -0400
Doug Goldstein <cardoe@g.o> wrote:

> Ryan Hill wrote:
> > The new lzma-utils codebase uses liblzma, written in C.  It's at the
> > alpha stage but supposedly supports encoding/decoding the current
> > lzma format "well enough" (;P).  It probably has some fun bugs to
> > find and squish.
> >
> > http://sf.net/mailarchive/forum.php?thread_name=200804251652.58484.lasse.collin%40tukaani.org&forum_name=lzmautils-announce

> According to the mailing list this change was done to fix security
> holes in the format and also resulted in a slightly different format
> that's incompatible with the previous verion. So lzma 5.x and higher
> will be a different on disk format. It's troubling to me that
> projects are using lzma when it's on disk format isn't even final and
> the project has security issues.

The current format is fine.  It's the new format that has
design/security issues.  Yes the formats are incompatible, but so
are .tar.lzma and .7z, which are both lzma.  Either way I was just
offering it as a data point.  I have no real opinion one way or the
other.


-- 
fonts, gcc-porting,                               by design, by neglect
mips, treecleaner,                        for a fact or just for effect
wxwidgets @ gentoo     EFFD 380E 047A 4B51 D2BD C64F 8AA8 8346 F9A4 0662
Attachment:
signature.asc (PGP signature)
References:
RFC: lzma tarball usage
-- Mart Raudsepp
Re: RFC: lzma tarball usage
-- Ryan Hill
Re: Re: RFC: lzma tarball usage
-- Doug Goldstein
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: Re: RFC: lzma tarball usage
Next by thread:
Re: RFC: lzma tarball usage
Previous by date:
Council meeting summary for 8 May 2008
Next by date:
Lenght of version components [was: Council meeting summary for 8 May 2008]


Updated Jun 17, 2009

Donate to support our development efforts.

Gentoo Centric Hosting: vr.org

VR Hosted

Tek Alchemy

Tek Alchemy

SevenL.net

SevenL.net

php|architect

php|architect

Copyright 2001-2007 Gentoo Foundation, Inc. Questions, Comments? Email www@gentoo.org.