Re: weaning distributions off tarballs: extended verification of git tags
- From
Duy Nguyen <pclouds@gmail.com>
- Date
- Mar 2, 2015, 23:20 UTC
- Message-ID
- <CACsJy8C3=f=esBrHE8OudSa0nUbCrLaYJtLC2in3p+tcc-d9bw@mail.gmail.com>
- In-Reply-To
- <20150302181230.GA31798@kitenet.net>
On Tue, Mar 3, 2015 at 1:12 AM, Joey Hess <id@joeyh.name> wrote:
Show 10 quoted lines
> I support this proposal, as someone who no longer releases tarballs > of my software, when I can possibly avoid it. I have worried about > signed tags / commits only being a SHA1 break away from useless. > > As to the implementation, checksumming the collection of raw objects is > certainly superior to tar. Colin had suggested sorting the objects by > checksum, but I don't think that is necessary. Just stream the commit > object, then its tree object, followed by the content of each object > listed in the tree, recursing into subtrees as necessary. That will be a > stable stream for a given commit, or tree.
It could be simplified a bit by using ls-tree -r (so you basically have a single big tree). Then hash commit, ls-tree -r output and all blobs pointed by ls-tree in listed order.
-- Duy