All of lore.kernel.org
 help / color / mirror / Atom feed
From: Yann E. MORIN <yann.morin.1998@free.fr>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH 0/3] core: check hashes of license files
Date: Tue, 20 Jun 2017 17:28:13 +0200	[thread overview]
Message-ID: <20170620152813.GA2892@scaer> (raw)
In-Reply-To: <CAAXf6LVAgOoLDEc-HUJJOOm9Oq8k5cG5q2VkK+ZNVJyGhtM4Cw@mail.gmail.com>

Thomas, All,

On 2017-06-19 21:32 +0200, Thomas De Schampheleire spake thusly:
> 2017-06-19 19:47 GMT+02:00 Yann E. MORIN <yann.morin.1998@free.fr>:
> > On 2017-06-19 22:47 +0530, Rahul Bedarkar spake thusly:
> >> On Sun, Jun 18, 2017 at 1:31 PM, Yann E. MORIN <yann.morin.1998@free.fr> wrote:
> >> >
> >> > Hello All!
> >> >
> >> > This small series is a proposal to check the hashes of the license files
> >> > during legal-info, to catch the packages whose license changes but where
> >> > the text of the new license is in the same file.
> >>
> >> Thanks for this series. Checking hashes of the license files during
> >> legal-info stage looks logical but we discussed about doing that after
> >> downloading sources so that change in license file is noticed early
> >> (as a part of build test after version bump).
> >
> > It is not possible to do at download time. It can only be done after
> > the package has been extracted and patched.
> >
> > That is why, when you run legal-info on a non-built (but configured)
> > tree, you'll notice that Buildroot extracts and patches the packages
> > before saving their legal-info.
> >
> > Besides, if one uses the support/scripts/test-pkg script to test the
> > version bump, then legal-info is run by the script.
> >
> > So, I still believe it is better done during legal-info.
> >
> 
> Yann, I think Rahul means that the checking of the hashing should be
> checked as part of the standard 'make pkg' target, whichever subtarget
> it is, be it -build, -install or what not.

OK, I see.

Still, I believe it is better suited to keep that for during the
legal-info step.

Regards,
Yann E. MORIN.

> But, I don't think we should mix such topics: legal info topics should
> stay in the -legal-info target.
> One solution could be to make '-legal-info' part of the standard build
> process, although it will slow down the build and some/many people
> will not like that.
> An alternative is to split '-legal-info' in two parts:
> -legal-info-checks and actual -legal-info. The first part would verify
> some important things, i.e. presence of valid LICENSE, presence of all
> files specified in LICENSE_FILES, hash checking on these files. It
> could be added to the standard 'make pkg' group. The second part would
> do the actual creation of the manifest, copying the sources, etc. and
> remains on-demand only.
> 
> I don't know what you think of that approach, I'm thinking out loud.
> 
> /Thomas

-- 
.-----------------.--------------------.------------------.--------------------.
|  Yann E. MORIN  | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: |
| +33 662 376 056 | Software  Designer | \ / CAMPAIGN     |  ___               |
| +33 223 225 172 `------------.-------:  X  AGAINST      |  \e/  There is no  |
| http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL    |   v   conspiracy.  |
'------------------------------^-------^------------------^--------------------'

  reply	other threads:[~2017-06-20 15:28 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-06-18  8:01 [Buildroot] [PATCH 0/3] core: check hashes of license files Yann E. MORIN
2017-06-18  8:01 ` [Buildroot] [PATCH 1/3] core/pkg-util: pass package directory and name when saving " Yann E. MORIN
2017-06-18  8:01 ` [Buildroot] [PATCH 2/3] core/pkg-utils: check hashes of " Yann E. MORIN
2017-06-23 21:49   ` Luca Ceresoli
2017-06-25 18:09     ` Yann E. MORIN
2017-06-25 21:49       ` Luca Ceresoli
2017-06-18  8:01 ` [Buildroot] [PATCH 3/3] docs/manual: document hashes for " Yann E. MORIN
2017-06-23  2:28   ` Ricardo Martincoski
2017-06-25 21:58     ` Yann E. MORIN
2017-06-23 21:57   ` Luca Ceresoli
2017-06-25 17:51     ` Yann E. MORIN
2017-06-19 17:17 ` [Buildroot] [PATCH 0/3] core: check hashes of " Rahul Bedarkar
2017-06-19 17:47   ` Yann E. MORIN
2017-06-19 19:32     ` Thomas De Schampheleire
2017-06-20 15:28       ` Yann E. MORIN [this message]
2017-06-23 21:50         ` Luca Ceresoli
2017-06-25 21:27           ` Yann E. MORIN
2017-06-20 14:49     ` Rahul Bedarkar

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20170620152813.GA2892@scaer \
    --to=yann.morin.1998@free.fr \
    --cc=buildroot@busybox.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.