Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests
Date: Sat, 24 Jul 2021 15:16:32
1 Hi, everyone.
3 I've been asked to repost the idea of removing SHA512 hash from
4 Manifests, effectively limiting them to BLAKE2B.
6 The 'old' set of Gentoo hashes including SHA512 went live in July 2012.
7 In November 2017, we have decided to remove the two other hashes and add
8 BLAKE2B in their stead. Today, all Gentoo packages are using BLAKE2B
9 and SHA512 hashes.
11 To all extent, this is purely a cosmetic change. The benefit from
12 removing the additional hash is negligible, both from space perspective
13 and hashing speed perspective. The benefit from keeping two hashes is
14 also negligible.
16 Back during the 2017 discussion, Infra came to the conclusion that we're
17 going to keep SHA512 for a transition period, then remove it, and stay
18 with a single hash algorithm. In my opinion, we have kept it long
19 enough.
21 WDYT?
23 --
24 Best regards,
25 Michał Górny