Re: Re: Re: Re: Re: Re: package.xml: md5sum attribute of <file />
| From: | Jon Parise | Date: | Tue, 25 Nov 2003 18:35:33 +0000 |
| Subject: | Re: Re: Re: Re: Re: Re: package.xml: md5sum attribute of <file /> | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-23870@lists.php.net to get a copy of this message | ||
On Tue, Nov 25, 2003 at 07:16:51PM +0100, Roman Neuhauser wrote:
> > Are you just attempting to play devil's advocate, or is there some
> > other motivation for this line of questioning?
>
> I'm genuinely concerned about a) the waste of resources that is the
> current scheme and b) the false sense of security it provides.
>
> > I'm certainly not wed to the current implementation; I'm just trying
> > to explain why it was built the way it exists today.
>
> Erm, you've failed the goal so far. At least I don't remember you
> saying why was the choice made for checksumming individual files.
Ouch. I guess this is a case of "I thought I knew the answer so I
replied to your question", but evidently I don't have enough of the
details. Because no one else has stepped up with an additional
information, I think your best bet is to delve into the mailing list
archives.
> > If you have an alternate implemention, please suggest it. I'm not the
> > ony who designed the current system, but I agree there may be flaws in
> > its design, so if there's a better way to do this, let's consider
> > changing.
>
> No implementation (yet), but the idea is this:
>
> only package-level checksum, fetched from the server in a separate
> request, cached on the disk, perhaps with this interface:
>
> pear checksum [-r [-s]]
>
> checksum
> check the computed md5 sum against one found in
> ${pkgfile%.tgz}.md5 (if present) or one returned by pear server
> checksum -r
> query server even if the md5 file is present
> checksum -rs
> query server even if the md5 file is present, and save the
> result in ${pkgfile%.tgz}.md5, overwriting any existing file
And the authoritive checksum would be computed by pear.php.net as part
of the package submission process?
> Of course, it *does* make sense to store a CRC of individual files
> when they're installed: say if I install Log-1.8.0 and make a tweak
> to Log/file.php, I won't want to lose my changes in a careless /
> colleague-performed update. Or something like that (IIRC you use a
> *BSD so I hope my vague description rings a bell with ports'
> handling of locally modified files).
Yes, I think that makes perfect sense.
--
Jon Parise (jon@php.net) :: The PHP Project (http://www.php.net/)