Re: Re: Re: package.xml: md5sum attribute of <file />
| From: | Roman Neuhauser | Date: | Tue, 25 Nov 2003 06:47:31 +0000 |
| Subject: | Re: Re: Re: package.xml: md5sum attribute of <file /> | ||
| References: | 1 2 3 4 5 6 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-23850@lists.php.net to get a copy of this message | ||
# jon@php.net / 2003-11-24 13:35:14 -0500:
> On Mon, Nov 24, 2003 at 07:11:07PM +0100, Roman Neuhauser wrote:
>
> > > It gives the PEAR Installer a mechanism by which to validate the
> > > individual files that it's about to place on the user's disk.
> >
> > what exactly does "validate" mean in the above sentence? or is
> > emphasis on the word "individual"?
>
> The emphasis is on "individual". The manifest is the package.xml
> file, which is stored in and distributed with the package archive.
> Therefore, the package.xml file can have no knowledge of the overall
> integrity of the package archive, but it can verify that the
> individual files are valid based on their MD5 checksums.
So again:
1. what practical benefit does checksumming individual files
provide over whole-package checksums?
2. why do(es) checksum(s) have to reside inside package.xml?
--
If you cc me or remove the list(s) completely I'll most likely ignore
your message. see http://www.eyrie.org./~eagle/faqs/questions.html