[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: md5sums files

> > On Wed, Mar  3, 2010 at 10:05:11 -0600, Peter Samuelson wrote:
> >> fundamentally, shipping a md5sums file is really just a tradeoff in
> >> download size vs. installation speed, not unlike gzip vs. bzip2.  One

> Julien Cristau <jcristau@debian.org> writes:
> > Only if you assume that disks never fail and thus files never get
> > corrupted when the package gets unpacked.

[Goswin von Brederlow]
> Or the memory, the cpu, the pci bus, the ide bus, ... have a bit
> toggler. There are many ways file can be corrupted between being
> downloaded (where apt checks them) and them being unpacked and
> checksumed locally.

Be that as it may, I don't think the md5sums file was ever intended to
be an integrity check of the .deb itself.  Fortunately, the .deb also
includes checksums of control.tar.gz and data.tar.gz, thanks to use of
the gzip container format.
Peter Samuelson | org-tld!p12n!peter | http://p12n.org/

Reply to: