1 |
Nick Rout schreef: |
2 |
> |
3 |
> I agree it is necessary when doing something in your overlay. It |
4 |
> seems most people who post to bugs.gentoo.org do not post a digest |
5 |
> file. Perhaps they should. |
6 |
|
7 |
Sometimes people do, but iirc this is discouraged by the dev team. Don't |
8 |
know why, but I know if I use an overlay ebuild, the tarball is |
9 |
downloaded when the digest is made (thus the md5 is taken directly from |
10 |
the tarball after downloading). I don't really think I'd want to rely on |
11 |
some unknown person's digest from a download that may not be the same as |
12 |
mine for whatever reason. At least this way I can confirm the tarball is |
13 |
from the legitimate source (by watching the wget output), and if |
14 |
necessary, compare the digest md5 with the md5 on the tarball's homepage |
15 |
(usually available). |
16 |
|
17 |
Having a digest from an 'untrusted source' (it's unofficial, after all) |
18 |
would encourage me to trust sources I shouldn't just trust by default, |
19 |
and I don't want to get into a bad habit like that. |
20 |
|
21 |
Holly |
22 |
-- |
23 |
gentoo-user@g.o mailing list |