[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: packages without .md5sums file?



Previously Massimo Dal Zotto wrote:
> Is this allowed by policy?

Yes.

> And if not should we change the policy and require that every package have
> the .md5sums file?

No. .md5sums are the wrong approach for this. The right approach is
a combination of signing packages themselves, and dpkg generating (multiple)
checksums on the fly when installing a packages. The signing part is
implemented already, the second is not currently.

I'ld much rather wait until that is implemented (which also won't require
any policy changes) then decide on an imperfect temporary solution. (And
yes, we are working on implementing that).

Wichert.

-- 
  _________________________________________________________________
 /       Nothing is fool-proof to a sufficiently talented fool     \
| wichert@wiggy.net                   http://www.liacs.nl/~wichert/ |
| 1024D/2FA3BC2D 576E 100B 518D 2F16 36B0  2805 3CB8 9250 2FA3 BC2D |



Reply to: