Re: Re: Re: Re: Re: package.xml: md5sum attribute of <file />

From: Date: Tue, 25 Nov 2003 16:29:12 +0000
Subject: Re: Re: Re: Re: Re: package.xml: md5sum attribute of <file />
References: 1 2 3 4 5 6 7 8 9  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-23863@lists.php.net to get a copy of this message
On Tue, Nov 25, 2003 at 09:18:05AM +0100, Roman Neuhauser wrote: > > > 1. what practical benefit does checksumming individual files > > > provide over whole-package checksums? > > > > It allows the Installer to validate each file as its installed, to > > guard against any archive extraction errors. > > So you say there are real world scenarios where the tgz file is > deemed ok by both gzip(1) and tar(1), but in fact it's corrupt? > > > > 2. why do(es) checksum(s) have to reside inside package.xml? > > > > That's the only place they can reside in the archive. Otherwise, the > > Installer would have to query pear.php.net (or similar) to get the > > checksums (i.e. it makes the archive standalone). > > Is fetching the checksum into a separate file a problem? > (Console_Getopt-1.0.tgz, Console_Getopt-1.0.md5) Are you just attempting to play devil's advocate, or is there some other motivation for this line of questioning? I'm certainly not wed to the current implementation; I'm just trying to explain why it was built the way it exists today. If you have an alternate implemention, please suggest it. I'm not the ony who designed the current system, but I agree there may be flaws in its design, so if there's a better way to do this, let's consider changing. -- Jon Parise (jon@php.net) :: The PHP Project (http://www.php.net/)

« previous php.pear.dev (#23863) next »