Gentoo Archives: gentoo-dev

From: Allan Wegan <allanwegan@××××××××××.de>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Manifest2 hashes, take n+1-th: 3 hashes for the tie-breaker case
Date: Tue, 24 Oct 2017 21:33:51
Message-Id: 64bba51d-5ba1-c1cc-44e7-68df468669e7@allanwegan.de
In Reply to: Re: [gentoo-dev] Manifest2 hashes, take n+1-th: 3 hashes for the tie-breaker case by "Michał Górny"
1 >> That is currently the case with portage, but not an inevitable
2 >> consequence of having 3 hash functions in the Manifest. Portage could
3 >> be made to check only one or two of them (even by default), giving
4 >> the tie-breaking ability to those who need it, and speeding up things
5 >> for those who don't.
6 > No, it can't. The specification (GLEP 59) requires it to check all
7 > hashes.
8
9 Of course it can: The code of the specification just has to be changed
10 before changing the code of portage. The question is not whether it is
11 possible to make portage skip hash verification - but whether it is a
12 good idea to make it do that...
13
14 I would not mind as long as the default is to always check all the
15 hashes and the option to disable it is properly named (like
16 "--disable-hash-verification" or something similar) and documented.
17
18
19
20 --
21 Allan Wegan
22 <http://www.allanwegan.de/>
23 Jabber: allanwegan@××××××.net
24 OTR-Fingerprint: E4DCAA40 4859428E B3912896 F2498604 8CAA126F
25 Jabber: allanwegan@××××××××××.de
26 OTR-Fingerprint: A1AAA1B9 C067F988 4A424D33 98343469 29164587
27 ICQ: 209459114
28 OTR-Fingerprint: 71DE5B5E 67D6D758 A93BF1CE 7DA06625 205AC6EC

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] Manifest2 hashes, take n+1-th: one hash to decide them all "Robin H. Johnson" <robbat2@g.o>