Re: package.xml: md5sum attribute of <file />

From: Date: Tue, 25 Nov 2003 19:01:00 +0000
Subject: Re: package.xml: md5sum attribute of <file />
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-23871@lists.php.net to get a copy of this message
# jon@php.net / 2003-11-25 13:35:33 -0500: > Date: Tue, 25 Nov 2003 13:35:33 -0500 > From: Jon Parise <jon@php.net> > To: pear-dev <pear-dev@lists.php.net> > Subject: Re: Re: Re: Re: Re: Re: package.xml: md5sum attribute of <file /> > > On Tue, Nov 25, 2003 at 07:16:51PM +0100, Roman Neuhauser wrote: > > > > Are you just attempting to play devil's advocate, or is there some > > > other motivation for this line of questioning? > > > > I'm genuinely concerned about a) the waste of resources that is the > > current scheme and b) the false sense of security it provides. > > > > > I'm certainly not wed to the current implementation; I'm just trying > > > to explain why it was built the way it exists today. > > > > Erm, you've failed the goal so far. At least I don't remember you > > saying why was the choice made for checksumming individual files. > > Ouch. I guess this is a case of "I thought I knew the answer so I > replied to your question", but evidently I don't have enough of the > details. Because no one else has stepped up with an additional > information, I think your best bet is to delve into the mailing list > archives. and as I wrote in the original mail: the archives don't seem to go far enough in history, which was why I started trolling here in the first place. > > > If you have an alternate implemention, please suggest it. I'm not the > > > ony who designed the current system, but I agree there may be flaws in > > > its design, so if there's a better way to do this, let's consider > > > changing. > > > > No implementation (yet), but the idea is this: > > > > only package-level checksum, fetched from the server in a separate > > request, cached on the disk, perhaps with this interface: > > > > pear checksum [-r [-s]] > > > > checksum > > check the computed md5 sum against one found in > > ${pkgfile%.tgz}.md5 (if present) or one returned by pear server > > checksum -r > > query server even if the md5 file is present > > checksum -rs > > query server even if the md5 file is present, and save the > > result in ${pkgfile%.tgz}.md5, overwriting any existing file > > And the authoritive checksum would be computed by pear.php.net as part > of the package submission process? My take (haven't thought this through too thoroghly) is it should be provided by who/what-ever creates the tarball, be it a human uploading her package through a web based interface or a program that creates tarballs on demand. Having Joe Shmoe upload the md5 sum of his package along with it allows the server to check integrity of the upload. Makes sense? (Again, no protection against attacks, but I don't want to get into this can of worms right now.) -- If you cc me or remove the list(s) completely I'll most likely ignore your message. see http://www.eyrie.org./~eagle/faqs/questions.html

« previous php.pear.dev (#23871) next »