From: Yann E. MORIN <yann.morin.1998@free.fr>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH 4/4] pkg-download: check hasahes for locally cached files
Date: Wed, 3 Dec 2014 19:51:57 +0100 [thread overview]
Message-ID: <20141203185157.GG4152@free.fr> (raw)
In-Reply-To: <20141202093148.1a1f7db7@free-electrons.com>
Thomas, All,
On 2014-12-02 09:31 +0100, Thomas Petazzoni spake thusly:
> On Tue, 2 Dec 2014 00:24:09 +0100, Yann E. MORIN wrote:
> > In some cases, upstream just update their releases in-place, without
> > renaming them. When that package is updated in Buildroot, a new hash to
> > match the new upstream release is included in the corresponding .hash
> > file.
> >
> > As a consequence, users who previously downloaded that package's tarball
> > with an older version of Buildroot, will get stuck with an old archive
> > for that package, and after updating their Buildroot copy, will be greeted
> > with a failed download, due to the local file not matching the new
> > hashes.
> >
> > So, to avoid this situation, check the hashes prior to doing the
> > download. If the hashes match, consider the locally cached file genuine,
> > and do not download it. However, if the locally cached file does not
> > match the known hashes we have for it, it is promptly removed, and a
> > download is re-attempted.
>
> So in essence, from now on, at each build, we are re-checking the
> hashes, while previously they were checked only when the file was
> downloaded. Not that great for build time, but well, again maybe the
> time to check the hashes is negligible compared to the build time. And
> we can assume that a big tarball, which takes a certain time to hash,
> will also contain a lot of source code to build, so the time to
> calculate the hash is proportional to the build time of the package. So
> if you're ready to spend several minutes to build Qt, you're probably
> ready to wait a few more seconds to calculate the hash of the Qt
> tarball each time.
I just hashed a 231MiB tarball (qt-everywhere-opensource-src-4.8.6.tar.gz)
and it takes (wall-clock time, core-i5 @2.5GHz):
- cache-cold sha1 : 1.914s
- cache-hot sha1 : 0.762s
- cache-hot sha256: 1.270s
(cache-cold sha256 is not easily done, I'd have to either umount /home
or reboot...)
Needless to say this is negligible when compared to the build time of Qt
(I do not have the numbers available for now, but I doubt it would be
less than 30 seconds on my machine).
I will add those numbers in the commit log next time I respin.
Regards,
Yann E. MORIN.
--
.-----------------.--------------------.------------------.--------------------.
| Yann E. MORIN | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: |
| +33 662 376 056 | Software Designer | \ / CAMPAIGN | ___ |
| +33 223 225 172 `------------.-------: X AGAINST | \e/ There is no |
| http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL | v conspiracy. |
'------------------------------^-------^------------------^--------------------'
next prev parent reply other threads:[~2014-12-03 18:51 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-12-01 23:24 [Buildroot] [PATCH 0/4] pkg-download: check hashes before the download (branch yem/download-hash) Yann E. MORIN
2014-12-01 23:24 ` [Buildroot] [PATCH 1/4] pkg-download: check for already downloaded file in the download wrapper Yann E. MORIN
2014-12-02 8:26 ` Thomas Petazzoni
2014-12-03 18:43 ` Yann E. MORIN
2014-12-01 23:24 ` [Buildroot] [PATCH 2/4] pkg-download: fix arguments to hash checking script Yann E. MORIN
2014-12-01 23:24 ` [Buildroot] [PATCH 3/4] pkg-download: verify the hashes from the download wrapper Yann E. MORIN
2014-12-02 8:29 ` Thomas Petazzoni
2014-12-03 18:45 ` Yann E. MORIN
2014-12-01 23:24 ` [Buildroot] [PATCH 4/4] pkg-download: check hasahes for locally cached files Yann E. MORIN
2014-12-02 8:31 ` Thomas Petazzoni
2014-12-02 9:27 ` Peter Korsgaard
2014-12-02 9:30 ` Thomas Petazzoni
2014-12-03 18:51 ` Yann E. MORIN [this message]
2014-12-06 12:44 ` Yann E. MORIN
2014-12-06 12:53 ` Thomas Petazzoni
2014-12-07 10:47 ` Yann E. MORIN
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20141203185157.GG4152@free.fr \
--to=yann.morin.1998@free.fr \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox