From: Yann E. MORIN <yann.morin.1998@free.fr>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH 11/12] manual: add documentation about packages' hashes
Date: Thu, 6 Mar 2014 18:09:40 +0100 [thread overview]
Message-ID: <20140306170940.GB3625@free.fr> (raw)
In-Reply-To: <CAHXCMMKohY_kE5BEOL9iqs30b9=yS1o_MKpzA9n47kuEGN-=Rw@mail.gmail.com>
Samuel, All,
On 2014-03-06 11:56 +0100, Samuel Martin spake thusly:
> On Wed, Mar 5, 2014 at 10:47 PM, Yann E. MORIN <yann.morin.1998@free.fr> wrote:
[--SNIP--]
> > diff --git a/docs/manual/adding-packages-directory.txt b/docs/manual/adding-packages-directory.txt
> > index e56e59a..4609a7e 100644
> > --- a/docs/manual/adding-packages-directory.txt
> > +++ b/docs/manual/adding-packages-directory.txt
> > @@ -346,3 +346,68 @@ different way, using different infrastructures:
> >
> > Further formatting details: see xref:writing-rules-mk[the writing
> > rules].
> > +
> > +The +.hash+ file
> > +~~~~~~~~~~~~~~~~
> > +[[adding-packages-hash]]
> > +
> > +Optionally, you can add a third file, named +libfoo.hash+, that contains
> > +the hashes of the downloaded files for the +libfoo+ package.
> > +
> > +The hashes stored in that file are used to validate the integrity of the
> > +downloaded files.
> > +
> > +The format for this file is one line for each file for which to check the
> > +hash, each line being space-separated, with these three fields:
> > +
> > +* the type of hash, one of:
> > +** +sha1+, +sha224+, +sha256+, +sha384+, +sha512+
> > +* the hash of the file:
> > +** for +sha1+, 40 hexa-decimal characters
> > +** for +sha224+, 56 hexa-decimal characters
> > +** for +sha256+, 64 hexa-decimal characters
> > +** for +sha384+, 96 hexa-decimal characters
> > +** for +sha512+, 128 hexa-decimal characters
> > +* the name of the file, without any directory component
> > +
> > +Lines starting with a +#+ sign are considered comments, and ignored. Empty
> > +lines are ignored.
> > +
> > +There can be more than one hash for a single file, each of its own line. In
> > +this case, all hashes must match.
>
> Maybe a note explaining why it's better to provide more than 1 hash
> for a file could be added.
As I said to Gustavo on IRC, I'd prefer we only document the format of
the .hash file in the manual, not define any policy. Ie. I don't think
it is sensible to say something like:
For security considerations, adding more than one hash will ower the
risk of collusions if more than one hash type is provided.
However, we can say, and I will add, something like:
If upstream provides more than one type of hash (say, sha1 and
sha512), then it is best to add all those hashes in the .hash file.
This is more policy-neutral.
We have to keep in mind that this feature is a first-level stop-gap for
security-conscious people, but in no way a security measure. Those
security-conscious users are encouraged to check the downloaded files
using a side-band channel (eg. manually checking signatures and so
on...)
Buildroot itself can't check signatures: if the user does not have a
chain-of-trust, from his own key and up to the signer's key, there is no
point in checking the signature in the first place. We can't expect all
users to have such a chain-of-trust, even less that all have a PGP key.
Regards,
Yann E. MORIN.
--
.-----------------.--------------------.------------------.--------------------.
| Yann E. MORIN | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: |
| +33 662 376 056 | Software Designer | \ / CAMPAIGN | ___ |
| +33 223 225 172 `------------.-------: X AGAINST | \e/ There is no |
| http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL | v conspiracy. |
'------------------------------^-------^------------------^--------------------'
next prev parent reply other threads:[~2014-03-06 17:09 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-03-05 21:47 [Buildroot] [PATCH 0/12 v3] some download-related changes Yann E. MORIN
2014-03-05 21:47 ` [Buildroot] [PATCH 01/12] Makefile: rename USER_HOOKS_EXTRA_ENV to EXTRA_ENV Yann E. MORIN
2014-03-05 21:47 ` [Buildroot] [PATCH 02/12] Makefile: add BR2_DL_DIR " Yann E. MORIN
2014-03-05 21:47 ` [Buildroot] [PATCH 03/12] pkg-infra: move the git download helper to a script Yann E. MORIN
2014-03-05 21:47 ` [Buildroot] [PATCH 04/12] pkg-infra: move the svn " Yann E. MORIN
2014-03-05 21:47 ` [Buildroot] [PATCH 05/12] pkg-infra: move the cvs " Yann E. MORIN
2014-03-05 21:47 ` [Buildroot] [PATCH 06/12] pkg-infra: move the hg " Yann E. MORIN
2014-03-05 21:47 ` [Buildroot] [PATCH 07/12] pkg-infra: move the wget " Yann E. MORIN
2014-03-05 21:47 ` [Buildroot] [PATCH 08/12] pkg-infra: don't use DL_DIR as scratchpad for temporary VCS checkouts Yann E. MORIN
2014-03-06 10:25 ` Samuel Martin
2014-03-06 16:54 ` Yann E. MORIN
2014-03-06 17:45 ` Arnout Vandecappelle
2014-03-05 21:47 ` [Buildroot] [PATCH 09/12] pkg-infra: also set PKGDIR for the download step Yann E. MORIN
2014-03-05 21:47 ` [Buildroot] [PATCH 10/12] pkg-infra: add possiblity to check downloaded files against known hashes Yann E. MORIN
2014-03-06 10:45 ` Samuel Martin
2014-03-05 21:47 ` [Buildroot] [PATCH 11/12] manual: add documentation about packages' hashes Yann E. MORIN
2014-03-06 10:56 ` Samuel Martin
2014-03-06 17:09 ` Yann E. MORIN [this message]
2014-03-06 17:14 ` Thomas De Schampheleire
2014-03-06 17:37 ` Yann E. MORIN
2014-03-05 21:47 ` [Buildroot] [PATCH 12/12] package/ca-certificates: add tarball's hashes Yann E. MORIN
-- strict thread matches above, loose matches on Subject: below --
2014-03-10 20:51 [Buildroot] [PATCH 0/12 v4] Some download-related changes (branch yem/check-downloads) Yann E. MORIN
2014-03-10 20:51 ` [Buildroot] [PATCH 11/12] manual: add documentation about packages' hashes Yann E. MORIN
2014-03-11 10:37 ` Thomas De Schampheleire
2014-06-01 17:40 [Buildroot] [PATCH 0/12 v6] Some download-related changes (branch yem/check-downloads) Yann E. MORIN
2014-06-01 17:40 ` [Buildroot] [PATCH 11/12] manual: add documentation about packages' hashes Yann E. MORIN
2014-06-01 20:08 ` Samuel Martin
2014-06-01 20:13 ` Yann E. MORIN
2014-06-08 20:43 [Buildroot] [PATCH 0/12 v7] Some download-related changes (branch yem/check-downloads) Yann E. MORIN
2014-06-08 20:43 ` [Buildroot] [PATCH 11/12] manual: add documentation about packages' hashes Yann E. MORIN
2014-07-02 21:11 [Buildroot] [PATCH 0/12 v10] Some download-related changes (branch yem/check-downloads) Yann E. MORIN
2014-07-02 21:11 ` [Buildroot] [PATCH 11/12] manual: add documentation about packages' hashes Yann E. MORIN
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140306170940.GB3625@free.fr \
--to=yann.morin.1998@free.fr \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox