Re: package.xml: md5sum attribute of <file />

From: Date: Mon, 24 Nov 2003 17:20:16 +0000
Subject: Re: package.xml: md5sum attribute of <file />
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-23830@lists.php.net to get a copy of this message
# jon@php.net / 2003-11-24 11:20:03 -0500: > On Mon, Nov 24, 2003 at 11:24:04AM +0100, Roman Neuhauser wrote: > > > I looked at the archive, seems it doesn't go back enough in time, hence > > this question: what purpose does <file md5sum="..." /> fill that > > wouldn't be satisfied by checksumming the whole tarball? > > Wouldn't be be exceptionally hard to checksum the entire tarball and > store the result in the package.xml file when the package.xml file is > stored within the tarball. It doesn't have to be included in package.xml. There are two concerns: 1. Validating that the tarball didn't get accidentally corrupted during transfer / while sitting on one's disk after download. Most of (if not all) such cases is caught by gzip. 2. Defense against attacks. Current scheme provides none by definition. We could maybe come up with a workable scheme if the checksum was detached from the package itself. For both purposes (tarball gets corrupted but gzip doesn't notice, and malice), 1 checksum is just as good as 1000. -- If you cc me or remove the list(s) completely I'll most likely ignore your message. see http://www.eyrie.org./~eagle/faqs/questions.html

« previous php.pear.dev (#23830) next »