Gentoo Archives: gentoo-portage-dev

From: Marius Mauch <genone@g.o>
To: gentoo-portage-dev@l.g.o
Subject: Re: [gentoo-portage-dev] Manifest signing
Date: Tue, 22 Nov 2005 20:02:40
Message-Id: 20051122210153.4764da88@sven.genone.homeip.net
In Reply to: Re: [gentoo-portage-dev] Manifest signing by Jason Stubbs
1 On Sat, 19 Nov 2005 20:59:07 +0900
2 Jason Stubbs <jstubbs@g.o> wrote:
3
4 > On Saturday 19 November 2005 20:41, Mike Auty wrote:
5 > > If portage can already handle multiple hash formats,
6 >
7 > Portage can't handle multiple hash formats at the moment. It is only
8 > smart enough to not throw a fit when other hash formats appear.
9
10 Actually all current version (>=2.0.51 IIRC) handle SHA1 digests
11 already (others aren't implemented in portage_checksum.py, but will be
12 silently ignored). We just don't generate SHA1 yet due to compability
13 issues, but those aren't relevant anymore.
14
15 > The user will be able to configure what algorithm(s) are used.
16
17 You mean for creation or verification (or both)?
18 Generation must be done for all available algorithms IMO.
19 Not so sure what to do about verification until the tree is mostly
20 covered with SHA1.
21
22 > > Having to maintain backwards compatibility with old versions of
23 > > portage is a good idea, however just how far back must be supported?
24 >
25 > A year is a good guide.
26
27 I'd say 9 months after the ebuild for that version vanished from
28 the tree as a minimum, but a year is also fine.
29 There are two usergroups creating problems:
30 - the ones that only update packages they're interested in (so no
31 complete system or world update ever)
32 - the ones who only ever update once per year or so (for whatever
33 reason)
34 Maybe we should request an addition to the handbook "You must update
35 sys-apps/portage at least every 6 months"?
36
37 Marius
38
39 --
40 Public Key at http://www.genone.de/info/gpg-key.pub
41
42 In the beginning, there was nothing. And God said, 'Let there be
43 Light.' And there was still nothing, but you could see a bit better.

Attachments

File name MIME type
signature.asc application/pgp-signature