Re: Re: package.xml: md5sum attribute of <file />
| From: | Jon Parise | Date: | Mon, 24 Nov 2003 18:05:30 +0000 |
| Subject: | Re: Re: package.xml: md5sum attribute of <file /> | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-23831@lists.php.net to get a copy of this message | ||
On Mon, Nov 24, 2003 at 06:20:16PM +0100, Roman Neuhauser wrote:
> # jon@php.net / 2003-11-24 11:20:03 -0500:
> > On Mon, Nov 24, 2003 at 11:24:04AM +0100, Roman Neuhauser wrote:
> >
> > > I looked at the archive, seems it doesn't go back enough in time, hence
> > > this question: what purpose does <file md5sum="..." /> fill that
> > > wouldn't be satisfied by checksumming the whole tarball?
> >
> > Wouldn't be be exceptionally hard to checksum the entire tarball and
> > store the result in the package.xml file when the package.xml file is
> > stored within the tarball.
>
> It doesn't have to be included in package.xml.
It gives the PEAR Installer a mechanism by which to validate the
individual files that it's about to place on the user's disk.
> There are two concerns:
I wasn't suggesting that we don't want to store a checksum for the
entire package, as well. I think we even talked about digitally
signing packages at one point.
--
Jon Parise (jon@php.net) :: The PHP Project (http://www.php.net/)