1 |
Ciaran McCreesh wrote: |
2 |
> On Thu, 08 May 2008 09:32:34 -0400 |
3 |
> Doug Goldstein <cardoe@g.o> wrote: |
4 |
> |
5 |
>> Ciaran McCreesh wrote: |
6 |
>> |
7 |
>>> On Thu, 08 May 2008 09:17:08 -0400 |
8 |
>>> Doug Goldstein <cardoe@g.o> wrote: |
9 |
>>> |
10 |
>>>> It's troubling to me that projects are using lzma when it's on disk |
11 |
>>>> format isn't even final and the project has security issues. |
12 |
>>>> |
13 |
>>> You mean projects like 'GNU tar'? |
14 |
>>> |
15 |
>>> |
16 |
>> As far as I know Ciaran, all GNU projects have switched or are in the |
17 |
>> process of switching to lzma over bzip2. I believe the issue in |
18 |
>> question which prompted this original e-mail was due to coreutils. |
19 |
>> But I could be wrong. |
20 |
>> |
21 |
> |
22 |
> You miss my point. GNU tar sometimes changes its on disk format (and |
23 |
> will be doing so again at some point for xattrs), and it's had security |
24 |
> issues. |
25 |
> |
26 |
> |
27 |
Fair enough. However, newer GNU tar's are able to untar the older |
28 |
formats. If you read the lzma changelogs, it appears to imply that newer |
29 |
ones won't be able to read older formats. The changelog specifically |
30 |
states if a user they are handling the issue "gracefully" by telling the |
31 |
user to upgrade or downgrade their lzma. |
32 |
-- |
33 |
gentoo-dev@l.g.o mailing list |