Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: Alon Bar-Lev <alonbl@g.o>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] News item review: SquashDelta syncing support
Date: Sat, 16 May 2015 22:06:24
Message-Id: 20150517000601.1a7d13d8@pomiot.lan
In Reply to: Re: [gentoo-dev] News item review: SquashDelta syncing support by Alon Bar-Lev
1 Dnia 2015-05-16, o godz. 23:48:01
2 Alon Bar-Lev <alonbl@g.o> napisał(a):
3
4 > On 15 May 2015 at 17:51, Michał Górny <mgorny@g.o> wrote:
5 > > Please note that the current syncing code does not verify the OpenPGP
6 > > signature to confirm the authenticity of fetched snapshots and deltas.
7 > > This feature will be added as soon as gentoo-keys support in Portage is
8 > > available.
9 >
10 > These are great news!
11 > We can retire the webrsync.
12 > Why not sign it similar to the portage snapshot are signed for now?
13 > The webrsync signature validation is quite simple.
14
15 All signing is in place already for a long time. Just the verification
16 code is missing, and it wasn't added because I was told to wait for
17 gentoo-keys.
18
19 > Just a reminder: please note the rollback prevention mechanism in
20 > webrsync, it is not enough to check signature, but also prevent older
21 > snapshot to be used.
22
23 Truth be told, the squashdelta syncing wasn't really made with rollback
24 prevention in mind. I can't think immediately of any solution that
25 would prevent accidental rollback while preserving the intended
26 flexibility.
27
28 --
29 Best regards,
30 Michał Górny