Re: Re: Re: Re: Re: package.xml: md5sum attribute of <file />
| From: | Jon Parise | Date: | Tue, 25 Nov 2003 16:29:12 +0000 |
| Subject: | Re: Re: Re: Re: Re: package.xml: md5sum attribute of <file /> | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-23863@lists.php.net to get a copy of this message | ||
On Tue, Nov 25, 2003 at 09:18:05AM +0100, Roman Neuhauser wrote:
> > > 1. what practical benefit does checksumming individual files
> > > provide over whole-package checksums?
> >
> > It allows the Installer to validate each file as its installed, to
> > guard against any archive extraction errors.
>
> So you say there are real world scenarios where the tgz file is
> deemed ok by both gzip(1) and tar(1), but in fact it's corrupt?
>
> > > 2. why do(es) checksum(s) have to reside inside package.xml?
> >
> > That's the only place they can reside in the archive. Otherwise, the
> > Installer would have to query pear.php.net (or similar) to get the
> > checksums (i.e. it makes the archive standalone).
>
> Is fetching the checksum into a separate file a problem?
> (Console_Getopt-1.0.tgz, Console_Getopt-1.0.md5)
Are you just attempting to play devil's advocate, or is there some
other motivation for this line of questioning? I'm certainly not wed
to the current implementation; I'm just trying to explain why it was
built the way it exists today.
If you have an alternate implemention, please suggest it. I'm not the
ony who designed the current system, but I agree there may be flaws in
its design, so if there's a better way to do this, let's consider
changing.
--
Jon Parise (jon@php.net) :: The PHP Project (http://www.php.net/)