Re: Re: Re: Re: Re: Re: package.xml: md5sum attribute of <file />

From: Date: Tue, 25 Nov 2003 18:35:33 +0000
Subject: Re: Re: Re: Re: Re: Re: package.xml: md5sum attribute of <file />
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-23870@lists.php.net to get a copy of this message
On Tue, Nov 25, 2003 at 07:16:51PM +0100, Roman Neuhauser wrote: > > Are you just attempting to play devil's advocate, or is there some > > other motivation for this line of questioning? > > I'm genuinely concerned about a) the waste of resources that is the > current scheme and b) the false sense of security it provides. > > > I'm certainly not wed to the current implementation; I'm just trying > > to explain why it was built the way it exists today. > > Erm, you've failed the goal so far. At least I don't remember you > saying why was the choice made for checksumming individual files. Ouch. I guess this is a case of "I thought I knew the answer so I replied to your question", but evidently I don't have enough of the details. Because no one else has stepped up with an additional information, I think your best bet is to delve into the mailing list archives. > > If you have an alternate implemention, please suggest it. I'm not the > > ony who designed the current system, but I agree there may be flaws in > > its design, so if there's a better way to do this, let's consider > > changing. > > No implementation (yet), but the idea is this: > > only package-level checksum, fetched from the server in a separate > request, cached on the disk, perhaps with this interface: > > pear checksum [-r [-s]] > > checksum > check the computed md5 sum against one found in > ${pkgfile%.tgz}.md5 (if present) or one returned by pear server > checksum -r > query server even if the md5 file is present > checksum -rs > query server even if the md5 file is present, and save the > result in ${pkgfile%.tgz}.md5, overwriting any existing file And the authoritive checksum would be computed by pear.php.net as part of the package submission process? > Of course, it *does* make sense to store a CRC of individual files > when they're installed: say if I install Log-1.8.0 and make a tweak > to Log/file.php, I won't want to lose my changes in a careless / > colleague-performed update. Or something like that (IIRC you use a > *BSD so I hope my vague description rings a bell with ports' > handling of locally modified files). Yes, I think that makes perfect sense. -- Jon Parise (jon@php.net) :: The PHP Project (http://www.php.net/)

« previous php.pear.dev (#23870) next »