tools.linux.kernel.org archive mirror
 help / color / mirror / Atom feed
* [b4] Sign gzipped tarball instead of .tar
@ 2021-02-17 13:43 foxboron
  2021-02-17 14:08 ` [tools] " Konstantin Ryabitsev
  0 siblings, 1 reply; 3+ messages in thread
From: foxboron @ 2021-02-17 13:43 UTC (permalink / raw)
  To: tools

[-- Attachment #1: Type: text/plain, Size: 868 bytes --]

Yo!

Currently packaging up b4 for Arch Linux and encountered a slight issue with the
release tarballs for the project.

The siganture says it needs to be compared against the tarball of the project,
however the kernel.org and googlesource.com only allows one to download the
gzipped tarball. To recreat the release artifact one would need to clone and
create the archive to have anything to compare against.

This doesn't work that well since we preferably include the sources
declaratively and not work out a tarball from the source checkout during
packaging. This also has the effect of most distros packaging the release
straight from pypi or from git with no release authentication.

Could the gzipped release tarballs be signed instead? Another alternative would
be to sign the release tags of b4.

-- 
Morten Linderud
PGP: 9C02FF419FECBE16

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 849 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2021-02-17 14:59 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-02-17 13:43 [b4] Sign gzipped tarball instead of .tar foxboron
2021-02-17 14:08 ` [tools] " Konstantin Ryabitsev
2021-02-17 14:59   ` Morten Linderud

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).