Gentoo Archives: gentoo-dev

From: Doug Goldstein <cardoe@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: RFC: lzma tarball usage
Date: Thu, 08 May 2008 13:44:00
Message-Id: 4823039E.4020008@gentoo.org
In Reply to: Re: [gentoo-dev] Re: RFC: lzma tarball usage by Ciaran McCreesh
1 Ciaran McCreesh wrote:
2 > On Thu, 08 May 2008 09:32:34 -0400
3 > Doug Goldstein <cardoe@g.o> wrote:
4 >
5 >> Ciaran McCreesh wrote:
6 >>
7 >>> On Thu, 08 May 2008 09:17:08 -0400
8 >>> Doug Goldstein <cardoe@g.o> wrote:
9 >>>
10 >>>> It's troubling to me that projects are using lzma when it's on disk
11 >>>> format isn't even final and the project has security issues.
12 >>>>
13 >>> You mean projects like 'GNU tar'?
14 >>>
15 >>>
16 >> As far as I know Ciaran, all GNU projects have switched or are in the
17 >> process of switching to lzma over bzip2. I believe the issue in
18 >> question which prompted this original e-mail was due to coreutils.
19 >> But I could be wrong.
20 >>
21 >
22 > You miss my point. GNU tar sometimes changes its on disk format (and
23 > will be doing so again at some point for xattrs), and it's had security
24 > issues.
25 >
26 >
27 Fair enough. However, newer GNU tar's are able to untar the older
28 formats. If you read the lzma changelogs, it appears to imply that newer
29 ones won't be able to read older formats. The changelog specifically
30 states if a user they are handling the issue "gracefully" by telling the
31 user to upgrade or downgrade their lzma.
32 --
33 gentoo-dev@l.g.o mailing list

Replies

Subject Author
Re: [gentoo-dev] Re: RFC: lzma tarball usage James Cloos <cloos@×××××××.com>