* [Buildroot] [PATCH 1/1] mongoose: fix hash
@ 2018-09-06 21:42 Fabrice Fontaine
2018-09-07 3:35 ` Baruch Siach
2018-10-21 16:06 ` Thomas Petazzoni
0 siblings, 2 replies; 5+ messages in thread
From: Fabrice Fontaine @ 2018-09-06 21:42 UTC (permalink / raw)
To: buildroot
When bumping to version 6.7, hash was not updated
Fixes:
- http://autobuild.buildroot.org/results/599920bc0a5821fd3fb0a028574a25a22e12430f
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
---
package/mongoose/mongoose.hash | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/package/mongoose/mongoose.hash b/package/mongoose/mongoose.hash
index d5252eb687..049cd74885 100644
--- a/package/mongoose/mongoose.hash
+++ b/package/mongoose/mongoose.hash
@@ -1,2 +1,2 @@
# Locally computed:
-sha256 ccc971298db70963d3f13766c3246a3c36ae7e388acfab7ba2180149d9c8c64f mongoose-6.7.tar.gz
+sha256 7033c4c9ad0aac2aaa53864ff0bee5468a327a78a3218fb753d55a426a791189 mongoose-6.7.tar.gz
--
2.17.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [Buildroot] [PATCH 1/1] mongoose: fix hash
2018-09-06 21:42 [Buildroot] [PATCH 1/1] mongoose: fix hash Fabrice Fontaine
@ 2018-09-07 3:35 ` Baruch Siach
2018-09-07 7:12 ` Thomas Petazzoni
2018-10-21 16:06 ` Thomas Petazzoni
1 sibling, 1 reply; 5+ messages in thread
From: Baruch Siach @ 2018-09-07 3:35 UTC (permalink / raw)
To: buildroot
Hi Fabrice,
Fabrice Fontaine writes:
> When bumping to version 6.7, hash was not updated
Commit 965c5ca57d3 (mongoose: bump to version 6.7) from April 2017, did
update the hash to its current value. You can find a tarball with this
hash at
http://sources.buildroot.net/mongoose-6.7.tar.gz
But the current github download is indeed different. Not sure what went
wrong here, but this description is not correct.
baruch
> Fixes:
> - http://autobuild.buildroot.org/results/599920bc0a5821fd3fb0a028574a25a22e12430f
>
> Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
> ---
> package/mongoose/mongoose.hash | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/package/mongoose/mongoose.hash b/package/mongoose/mongoose.hash
> index d5252eb687..049cd74885 100644
> --- a/package/mongoose/mongoose.hash
> +++ b/package/mongoose/mongoose.hash
> @@ -1,2 +1,2 @@
> # Locally computed:
> -sha256 ccc971298db70963d3f13766c3246a3c36ae7e388acfab7ba2180149d9c8c64f mongoose-6.7.tar.gz
> +sha256 7033c4c9ad0aac2aaa53864ff0bee5468a327a78a3218fb753d55a426a791189 mongoose-6.7.tar.gz
--
http://baruch.siach.name/blog/ ~. .~ Tk Open Systems
=}------------------------------------------------ooO--U--Ooo------------{=
- baruch at tkos.co.il - tel: +972.52.368.4656, http://www.tkos.co.il -
^ permalink raw reply [flat|nested] 5+ messages in thread
* [Buildroot] [PATCH 1/1] mongoose: fix hash
2018-09-07 3:35 ` Baruch Siach
@ 2018-09-07 7:12 ` Thomas Petazzoni
2018-09-09 10:20 ` Yann E. MORIN
0 siblings, 1 reply; 5+ messages in thread
From: Thomas Petazzoni @ 2018-09-07 7:12 UTC (permalink / raw)
To: buildroot
Hello,
On Fri, 07 Sep 2018 06:35:21 +0300, Baruch Siach wrote:
> Fabrice Fontaine writes:
> > When bumping to version 6.7, hash was not updated
>
> Commit 965c5ca57d3 (mongoose: bump to version 6.7) from April 2017, did
> update the hash to its current value. You can find a tarball with this
> hash at
>
> http://sources.buildroot.net/mongoose-6.7.tar.gz
>
> But the current github download is indeed different. Not sure what went
> wrong here, but this description is not correct.
I saw Yann and Peter talking about github tarballs having changed again:
18:29 < Jacmet> hmm, looks like github tarballs again changed content :/
18:29 < Jacmet> http://autobuild.buildroot.net/results/599/599920bc0a5821fd3fb0a028574a25a22e12430f/build-end.log
18:42 < y_morin> Jacmet: At the same time, the fallback to s.b.o timeout, so maybe it is not a github issue either?
18:43 < Jacmet> y_morin: well, it did get a tarball from github and the hash didn't match
18:43 < y_morin> Jacmet: Arg, indeed. I even had another sha256 than the one in the report.
18:44 < Jacmet> y_morin: and downloading it from github here I also get the same (wrong) hash
Best regards,
Thomas
--
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
^ permalink raw reply [flat|nested] 5+ messages in thread
* [Buildroot] [PATCH 1/1] mongoose: fix hash
2018-09-07 7:12 ` Thomas Petazzoni
@ 2018-09-09 10:20 ` Yann E. MORIN
0 siblings, 0 replies; 5+ messages in thread
From: Yann E. MORIN @ 2018-09-09 10:20 UTC (permalink / raw)
To: buildroot
Fabrice, Thomas, All,
On 2018-09-07 09:12 +0200, Thomas Petazzoni spake thusly:
> On Fri, 07 Sep 2018 06:35:21 +0300, Baruch Siach wrote:
> > But the current github download is indeed different. Not sure what went
> > wrong here, but this description is not correct.
> I saw Yann and Peter talking about github tarballs having changed again:
>
> 18:29 < Jacmet> hmm, looks like github tarballs again changed content :/
> 18:29 < Jacmet> http://autobuild.buildroot.net/results/599/599920bc0a5821fd3fb0a028574a25a22e12430f/build-end.log
> 18:42 < y_morin> Jacmet: At the same time, the fallback to s.b.o timeout, so maybe it is not a github issue either?
> 18:43 < Jacmet> y_morin: well, it did get a tarball from github and the hash didn't match
> 18:43 < y_morin> Jacmet: Arg, indeed. I even had another sha256 than the one in the report.
> 18:44 < Jacmet> y_morin: and downloading it from github here I also get the same (wrong) hash
That does not happen for all archives, though... :-/
And I can see that indeed the generated tarball is different from the
one on s.b.o.: it slightly differ in the way directory entries are
stored... Except for that, the actual content is the same.
Regards,
Yann E. MORIN.
--
.-----------------.--------------------.------------------.--------------------.
| Yann E. MORIN | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: |
| +33 662 376 056 | Software Designer | \ / CAMPAIGN | ___ |
| +33 223 225 172 `------------.-------: X AGAINST | \e/ There is no |
| http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL | v conspiracy. |
'------------------------------^-------^------------------^--------------------'
^ permalink raw reply [flat|nested] 5+ messages in thread
* [Buildroot] [PATCH 1/1] mongoose: fix hash
2018-09-06 21:42 [Buildroot] [PATCH 1/1] mongoose: fix hash Fabrice Fontaine
2018-09-07 3:35 ` Baruch Siach
@ 2018-10-21 16:06 ` Thomas Petazzoni
1 sibling, 0 replies; 5+ messages in thread
From: Thomas Petazzoni @ 2018-10-21 16:06 UTC (permalink / raw)
To: buildroot
Hello,
On Thu, 6 Sep 2018 23:42:20 +0200, Fabrice Fontaine wrote:
> When bumping to version 6.7, hash was not updated
>
> Fixes:
> - http://autobuild.buildroot.org/results/599920bc0a5821fd3fb0a028574a25a22e12430f
>
> Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
> ---
> package/mongoose/mongoose.hash | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
I marked this patch as Rejected, because it would break older Buildroot
releases. Indeed, all Buildroot releases since 2017.05 are using
Mongoose 6.7. They currently fail to download Mongoose from Github due
the hash mismatch, but they fall back to the Buildroot mirror
successfully.
If we update the hash, the Buildroot mirror will discard the current
6.7 tarball, and replace it with a new tarball having the new hash.
While this will make the new Buildroot releases happy it would break
older Buildroot releases, that would no longer be able to download
neither from Github nor from the Buildroot mirror.
So instead, we need to bump to a newer Mongoose version, so that we can
keep the old mongoose-6.7 tarball on the Buildroot mirror to keep old
Buildroot releases happy.
So I've applied the following changes instead:
951f15b16f6167f4205988e5dde4d13e2f560791 package/mongoose: bump to version 6.13
7e62211976e0b9ddfd05a11fb24c61ed8a9a4491 package/mongoose: add hash for license file
dea3ab68400503bebf4152277d63813508f43424 package/mongoose: add security patch fixing CVE-2018-10945
Best regards,
Thomas
--
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2018-10-21 16:06 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-09-06 21:42 [Buildroot] [PATCH 1/1] mongoose: fix hash Fabrice Fontaine
2018-09-07 3:35 ` Baruch Siach
2018-09-07 7:12 ` Thomas Petazzoni
2018-09-09 10:20 ` Yann E. MORIN
2018-10-21 16:06 ` Thomas Petazzoni
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.