From: Denys Dmytriyenko <denis@denix.org>
To: openembedded-devel@lists.openembedded.org
Subject: Re: checksums situation
Date: Wed, 25 Feb 2009 18:04:12 -0500 [thread overview]
Message-ID: <20090225230412.GA25783@denix.org> (raw)
In-Reply-To: <1235552980.5399.10.camel@dax.rpnet.com>
On Wed, Feb 25, 2009 at 09:09:40AM +0000, Richard Purdie wrote:
> On Tue, 2009-02-24 at 22:29 +0000, Phil Blundell wrote:
> > I think Tom Rini's point, which is a good one, was that the existing
> > checksums.ini workflow doesn't actually do anything to protect against
> > those threats, since there isn't any validation of the checksum against
> > an authoritative source. Right now, the checksum that you get in
> > checksums.ini is just what was computed by the first person to build the
> > corresponding .bb file: if the file had been compromised before that, we
> > would never know.
> >
> > Even in the case where the upstream tarball changes unexpectedly, I
> > wouldn't be at all surprised if some or other developer just decided
> > that the checksums.ini entry was wrong and quietly checked in a
> > "correction" for it. So I tend to agree with Tom, the checksums in
> > their current form do not really buy much.
>
> I think checksums.ini even in its current form is useful. If the
> checksum matches it tells us that your build configuration at least
> matches the configuration the original recipe submitter had. It also
> spots corrupted downloads and cases where upstream changes and we have
> seen those cases. People shouldn't be silently checking in those changes
> and if they do, would most likely get spotted by people with the old
> version in DL_DIR.
>
> So to say it does buy much isn't really fair although I agree if you
> want verification of the sources at every level, its not good enough. If
> we want to do better, all it takes is someone to do the work. We could
> have a "verified-checksums.ini" file with some policy attached to it
> which is used instead of or supplements checksums.ini...
>
> For overlays, I'd suggest just scanning the overlay directories (BBPATH)
> for more checksum.ini files like we do with conf/class files...
Richard,
I'm not in the position to explain how Bitbake works to the Bitbake's core
developer and maintainer. :) So, below is just my understanding of how it
works.
So, for overlays it currently works the same way for checksums.ini as it does
for conf/class files - it uses only one instance of a file with the same name,
depending on the priority either from overlay or from upstream org.oe.dev. In
other words - if my overlay has a higher priority, it would use my
checksums.ini INSTEAD of the upstream one in org.oe.dev. Same with conf/class
files - if I have a copy of base.bbclass in my overlay, it REPLACES the one
from upstream org.oe.dev...
Are you suggesting to simply combine checksums.ini files from overlay and
org.oe.dev? That may work as long as duplicates are handled properly - I guess
they can be overwritten based on the priorities - i.e. the entry with higher
priority would replace the duplicate one. But it is not the way it works now.
And this will definitely not work for conf/class files...
Or maybe I'm just completely missing your point.
--
Denys
next prev parent reply other threads:[~2009-02-25 23:08 UTC|newest]
Thread overview: 51+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-02-13 16:28 checksums situation Marcin Juszkiewicz
2009-02-13 17:08 ` Otavio Salvador
2009-02-13 17:39 ` Ihar Hrachyshka
2009-02-13 18:37 ` Otavio Salvador
2009-02-13 19:35 ` Leon Woestenberg
2010-02-12 18:45 ` mike
2009-02-13 19:41 ` John Willis
2009-02-15 10:04 ` Phil Blundell
2009-02-15 18:32 ` Otavio Salvador
2009-02-13 17:09 ` Tom Rini
2009-02-13 17:28 ` Andrea Adami
2009-02-13 17:34 ` Andrea Adami
2009-02-13 18:02 ` Koen Kooi
2009-02-14 14:51 ` Yuri Bushmelev
2009-02-24 6:46 ` Tom Rini
2009-02-24 6:51 ` Tom Rini
2009-02-24 8:49 ` Marcin Juszkiewicz
2009-02-24 15:02 ` Tom Rini
2009-02-24 16:13 ` Michael 'Mickey' Lauer
2009-02-24 16:25 ` Angus Ainslie
2009-02-24 16:37 ` Tom Rini
2009-02-24 16:28 ` Philip Balister
2009-02-24 16:36 ` Tom Rini
2009-02-24 22:10 ` GNUtoo
2009-02-24 22:17 ` Tom Rini
2009-02-24 22:29 ` Phil Blundell
2009-02-24 22:42 ` GNUtoo
2009-02-25 9:09 ` Richard Purdie
2009-02-25 23:04 ` Denys Dmytriyenko [this message]
2009-02-26 13:28 ` Richard Purdie
2009-02-27 0:20 ` Otavio Salvador
2009-02-24 18:01 ` Otavio Salvador
2009-02-24 18:36 ` Ihar Hrachyshka
2009-02-24 18:50 ` Tom Rini
2009-02-24 22:20 ` GNUtoo
2009-02-25 2:01 ` Otavio Salvador
2009-02-25 2:25 ` Tom Rini
2009-02-25 9:01 ` Richard Purdie
2009-02-25 21:27 ` Vitus Jensen
2009-02-25 21:35 ` Tom Rini
2009-02-25 22:04 ` Vitus Jensen
2009-02-26 8:10 ` Koen Kooi
2009-02-26 12:50 ` Bernhard Guillon
2009-02-28 9:57 ` Alessandro GARDICH
2009-02-28 10:45 ` Koen Kooi
2009-02-28 10:51 ` Alessandro GARDICH
2009-02-28 13:12 ` Philip Balister
2009-02-24 20:29 ` Bernhard Guillon
2009-02-24 22:45 ` GNUtoo
2009-02-25 9:16 ` Koen Kooi
-- strict thread matches above, loose matches on Subject: below --
2009-02-24 20:00 Frans Meulenbroeks
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090225230412.GA25783@denix.org \
--to=denis@denix.org \
--cc=openembedded-devel@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.