Re: Re: package.xml: md5sum attribute of <file />

From: Date: Mon, 24 Nov 2003 18:05:30 +0000
Subject: Re: Re: package.xml: md5sum attribute of <file />
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-23831@lists.php.net to get a copy of this message
On Mon, Nov 24, 2003 at 06:20:16PM +0100, Roman Neuhauser wrote: > # jon@php.net / 2003-11-24 11:20:03 -0500: > > On Mon, Nov 24, 2003 at 11:24:04AM +0100, Roman Neuhauser wrote: > > > > > I looked at the archive, seems it doesn't go back enough in time, hence > > > this question: what purpose does <file md5sum="..." /> fill that > > > wouldn't be satisfied by checksumming the whole tarball? > > > > Wouldn't be be exceptionally hard to checksum the entire tarball and > > store the result in the package.xml file when the package.xml file is > > stored within the tarball. > > It doesn't have to be included in package.xml. It gives the PEAR Installer a mechanism by which to validate the individual files that it's about to place on the user's disk. > There are two concerns: I wasn't suggesting that we don't want to store a checksum for the entire package, as well. I think we even talked about digitally signing packages at one point. -- Jon Parise (jon@php.net) :: The PHP Project (http://www.php.net/)

« previous php.pear.dev (#23831) next »