ports/188815: devel/libserver: BROKEN due to failed checksum

John Marino freebsd.contact at marino.st
Sun Apr 20 12:10:01 UTC 2014


The following reply was made to PR ports/188815; it has been noted by GNATS.

From: John Marino <freebsd.contact at marino.st>
To: James Bailie <jimmy at mammothcheese.ca>, bug-followup at FreeBSD.org
Cc:  
Subject: Re: ports/188815: devel/libserver: BROKEN due to failed checksum
Date: Sun, 20 Apr 2014 14:03:29 +0200

 On 4/20/2014 13:47, James Bailie wrote:
 > Make makesum. Tarball is correct.
 > 
 
 This hash should be provided to the PR first.
 Imagine that the tarball got switched maliciously before a committer got
 a chance to "make makesum" and they accidentally blessed an
 intentionally compromised tarball.
 
 This is why digests exist in the first place -- to be 100% sure that
 downloaded file is what was intended.
 
 John


More information about the freebsd-ports-bugs mailing list