From: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH 1/1] linuxptp: bump to the latest version
Date: Sun, 10 Sep 2017 20:40:51 +0200 [thread overview]
Message-ID: <20170910204051.3db9ec8f@windsurf.lan> (raw)
In-Reply-To: <20170910181806.GA21464@scaer>
Hello,
On Sun, 10 Sep 2017 20:18:06 +0200, Yann E. MORIN wrote:
> Globally, the hash is here for three reasons:
>
> 1- be sure that what we download is what we expect, to avoid
> man-in-the-middle attacks, especially on security-sensitive
> packages: ca-certificates, openssh, dropbear, etc...
>
> 2- be sure that what we download is what we expect, to avoid silent
> corruption of the downloaded blob, or to avoid fscked-up by
> intermediate CDNs (already seen!)
>
> 3- detect when upstream completely messes up, and redoes a release,
> like regnerating a release tarball, or re-tagging another commit,
> after the previous one went public.
I think there is also another reason for the hashes to exist: if you
fetch from a BR2_PRIMARY_SITE or from the BR2_BACKUP_SITE, you're
really fetching tarballs, and not doing git clones. So in this case,
having a hash makes a lot of sense.
Best regards,
Thomas
--
Thomas Petazzoni, CTO, Free Electrons
Embedded Linux and Kernel engineering
http://free-electrons.com
next prev parent reply other threads:[~2017-09-10 18:40 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-09-09 17:17 [Buildroot] [PATCH 1/1] linuxptp: bump to the latest version Petr Kulhavy
2017-09-09 20:08 ` Thomas Petazzoni
2017-09-09 20:53 ` Petr Kulhavy
2017-09-10 6:04 ` Thomas Petazzoni
2017-09-10 9:24 ` Yann E. MORIN
2017-09-10 10:31 ` Petr Kulhavy
2017-09-10 18:18 ` Yann E. MORIN
2017-09-10 18:40 ` Thomas Petazzoni [this message]
2017-09-10 23:30 ` Petr Kulhavy
2017-09-11 20:04 ` Yann E. MORIN
2017-09-10 9:57 ` Petr Kulhavy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170910204051.3db9ec8f@windsurf.lan \
--to=thomas.petazzoni@free-electrons.com \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox