Re: Re: Re: Re: package.xml: md5sum attribute of <file />
| From: | Roman Neuhauser | Date: | Tue, 25 Nov 2003 08:18:05 +0000 |
| Subject: | Re: Re: Re: Re: package.xml: md5sum attribute of <file /> | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-23854@lists.php.net to get a copy of this message | ||
# jon@php.net / 2003-11-25 02:04:42 -0500:
> On Tue, Nov 25, 2003 at 07:47:31AM +0100, Roman Neuhauser wrote:
>
> > > The emphasis is on "individual". The manifest is the package.xml
> > > file, which is stored in and distributed with the package archive.
> > > Therefore, the package.xml file can have no knowledge of the overall
> > > integrity of the package archive, but it can verify that the
> > > individual files are valid based on their MD5 checksums.
> >
> > So again:
> >
> > 1. what practical benefit does checksumming individual files
> > provide over whole-package checksums?
>
> It allows the Installer to validate each file as its installed, to
> guard against any archive extraction errors.
So you say there are real world scenarios where the tgz file is
deemed ok by both gzip(1) and tar(1), but in fact it's corrupt?
> > 2. why do(es) checksum(s) have to reside inside package.xml?
>
> That's the only place they can reside in the archive. Otherwise, the
> Installer would have to query pear.php.net (or similar) to get the
> checksums (i.e. it makes the archive standalone).
Is fetching the checksum into a separate file a problem?
(Console_Getopt-1.0.tgz, Console_Getopt-1.0.md5)
--
If you cc me or remove the list(s) completely I'll most likely ignore
your message. see http://www.eyrie.org./~eagle/faqs/questions.html