1 |
On Mon, Sep 12, 2011 at 10:50:30PM -0700, Zac Medico wrote: |
2 |
> On 09/12/2011 10:30 PM, Zac Medico wrote: |
3 |
> > On 09/12/2011 09:38 PM, Robin H. Johnson wrote: |
4 |
> >> On Tue, Sep 13, 2011 at 03:20:35AM +0000, Zac Medico wrote: |
5 |
> >>> commit: 677240f7b3db66bdcd403c214e5d3fa30e31a24a |
6 |
> >>> Author: Zac Medico <zmedico <AT> gentoo <DOT> org> |
7 |
> >>> AuthorDate: Tue Sep 13 03:20:00 2011 +0000 |
8 |
> >>> Commit: Zac Medico <zmedico <AT> gentoo <DOT> org> |
9 |
> >>> CommitDate: Tue Sep 13 03:20:00 2011 +0000 |
10 |
> >>> URL: http://git.overlays.gentoo.org/gitweb/?p=proj/portage.git;a=commit;h=677240f7 |
11 |
> >>> |
12 |
> >>> repoman: don't sign thin manifests |
13 |
> >>> |
14 |
> >>> Thin manifests imply reliance on the VCS for file integrity, |
15 |
> >>> which implies that manifest signatures are not needed. |
16 |
> >> |
17 |
> >> This is only true after the VCS has signed commits. |
18 |
> >> |
19 |
> >> If the VCS does not have signed commits, then we should have this |
20 |
> >> signature. |
21 |
> > |
22 |
> > So, should we add the ability to set "signed-manifests = false" in |
23 |
> > metadata/layout.conf? I can imagine that people using thin-manifests |
24 |
> > typically don't want signed-manifests, since it tends the introduce |
25 |
> > merge conflicts like those that thin-manifests is supposed to avoid. |
26 |
> |
27 |
> I've implemented "signed-manifests = false" here: |
28 |
> |
29 |
> http://git.overlays.gentoo.org/gitweb/?p=proj/portage.git;a=commit;h=9cb089047e10b300100e7bbdc4274ecf8866b0bb |
30 |
Thanks, that's very useful for working on it, and probably the best |
31 |
solution. |
32 |
|
33 |
-- |
34 |
Robin Hugh Johnson |
35 |
Gentoo Linux: Developer, Trustee & Infrastructure Lead |
36 |
E-Mail : robbat2@g.o |
37 |
GnuPG FP : 11AC BA4F 4778 E3F6 E4ED F38E B27B 944E 3488 4E85 |