1 |
Well, yeah, I have the feeling that until I'm done with the verification |
2 |
(it's a work in progress, the problem is mostly in walking the entire |
3 |
tree a bit efficient) I can see if what we have actually makes sense. |
4 |
|
5 |
Thing is I once believed Portage checked manifest and all, but it seems |
6 |
not to do anything any more, so my idea of things being OK may have been |
7 |
false appearances because Portage no longer gives a ****. |
8 |
|
9 |
Fabian |
10 |
|
11 |
|
12 |
On 20-02-2018 20:25:33 +0100, Michael Weiser wrote: |
13 |
> Hi Fabian, |
14 |
> |
15 |
> On Fri, Feb 02, 2018 at 09:06:34PM +0100, Fabian Groffen wrote: |
16 |
> |
17 |
> > > does it make sense to look into using gemato for repo verification or is |
18 |
> > > there a reason this cannot work currently? |
19 |
> |
20 |
> > It should, but I didn't get around to it. |
21 |
> |
22 |
> I finally got around to trying gemato on my Mac. It sets off fine but |
23 |
> immediately fails on sys-apps/Manifest.gz: |
24 |
> |
25 |
> $ gemato verify -K /Users/michael/b/pubring.gpg /usr/local/gentoo/usr/portage/ |
26 |
> INFO:root:Refreshing keys from keyserver... |
27 |
> INFO:root:Keys refreshed. |
28 |
> INFO:root:Manifest timestamp: 2018-02-19 17:28:21 UTC |
29 |
> INFO:root:Valid OpenPGP signature found: |
30 |
> INFO:root:- primary key: 0204A8ABD003E57A9558850DBA08091EC6317B3C |
31 |
> INFO:root:- subkey: 0204A8ABD003E57A9558850DBA08091EC6317B3C |
32 |
> INFO:root:- timestamp: 2018-02-19 17:28:21 UTC |
33 |
> INFO:root:Verifying /usr/local/gentoo/usr/portage/... |
34 |
> ERROR:root:Manifest mismatch for sys-apps/Manifest.gz |
35 |
> BLAKE2B: expected: 304895d779741fedeaac05df18857d5b0c1afa23220e6e578bd7ddca53f6d4781751881f13c59c361f3a225c7c8290cfa2ae278c779ad4c68a938b9336ebc999, have: e2260c115b7886ac16e74a8c981f3830650c018aa2d1566947b7eee2463eb8c56a5d5be3d30f324b239b3f9899b1781fe6f11c3bfb482bebb8df48e09e15ef43 |
36 |
> SHA512: expected: 0985d753fcb39735651606c30dbe9335d6d82569ca0e6ac766f268f5fd8d3df40e9f2664c145c752bb9c7c09a06f7766bc9fdb42a37809e62ea6462743bde2c6, have: 9d60081f638b5678780c21f698f0ee56cd4fa4dfe3d89a6c38403a37bd6cd782181fe0368af597d316f110e82c61cc8770346007a2a63dad90b7bac555c277eb |
37 |
> |
38 |
> I can reproduce the discrepancy with sha512sum and b2sum. |
39 |
> |
40 |
> Is it possible that prefix's tree isn't fully rehashed and resigned |
41 |
> after changes? |
42 |
> |
43 |
> > Instead I want to use my own |
44 |
> > C-based tool, but I also didn't get around to getting it ready. |
45 |
> |
46 |
> Is it available somewhere to try out? |
47 |
> -- |
48 |
> Thanks, Michael |
49 |
> |
50 |
|
51 |
-- |
52 |
Fabian Groffen |
53 |
Gentoo on a different level |