Gentoo Archives: gentoo-user

From: James <wireless@×××××××××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: package download verification
Date: Fri, 09 May 2014 18:03:48
Message-Id: loom.20140509T164954-318@post.gmane.org
In Reply to: Re: [gentoo-user] Re: package download verification by Alan McKinnon
1 Alan McKinnon <alan.mckinnon <at> gmail.com> writes:
2
3
4 > On 08/05/2014 21:13, James wrote:
5 > > So, what a torrent_style tool that uses a distributed hashes/keys
6 > > to check code integrity; is possible?
7 > In one word: git
8 > > Surely the code histogram idea is possible?
9 > Again, git.
10
11
12 Wow, this is freaky. I've never read up on git's diff-stat.
13 There are numerous advanced mathematical methodologies that
14 can be applied to histograms, some of which run blazingly
15 fast on GPU and customer gate arrays. I wonder where I can
16 read up on "diffstat" and see what mathematics they are applied
17 or are contemplating to use? Google reveals nothing yet
18 and I'm too lazy (right now) to read the code.
19
20 "Copyright © 1996-2013,2014 by Thomas E. Dickey
21 diffstat reads the output of diff and displays a histogram of the
22 insertions, deletions, and modifications per-file. It is useful for
23 reviewing large, complex patch files. "
24
25
26 this is really cool, I shoot one from the hip and it is a well
27 established tool? scary, but, math is math.....
28
29 Do you know (of) this guy? is he easy to approach or territorial?
30 I never heard of this guy.....
31
32 > An aspect of the git design spec is to try deal with the kind of things
33 > you are pondering here. It seems a valid approach - if many people out
34 > there clone and make copies of the code then work on it, and if a bad
35 > hat injects some weirdness, there are enough eyes to hopefully catch it.
36 > Now that I think of it, it's an elegant solution:
37 > Avoid the problems of a single master store but not having one.
38
39
40 Beyond elegant. Some very cool mathematics can be applied to (histogram)
41 verious images and image manipultation as a sort of "out of band" security
42 scan..... There are also some very cool bit manipulations deep in
43 H.264 that are similarly applicable. In fact "motion detection"
44 is a first cousin to these transfroms (z, laplace, fft) which are often
45 embedded in hardware for system checks). DOD......
46
47 Well, I'm off to go play basketball and the the Tampabay Devil rays
48 (hopefully) pound those cleveland indians.........
49
50 I'm jazzed. I usually lucky when hips shots do not richochet around and
51 hit me in the rear!.............
52
53 Since I'm not driving, I going to have a BIG FAT MARGARITA, and give you
54 a salute at the BB game.... You've made my week!
55
56
57
58
59 thx!
60 James