http://blfs-bugs.linuxfromscratch.org/show_bug.cgi?id=1644





------- Additional Comments From [EMAIL PROTECTED]  2005-10-19 11:26 -------
Thanks McMurchy,

Excerpts from the BLFS Support List subject thread (started by me, Alex, on 10/
17/05):

<< Dan Nicholson's reply:
Same thing happened to me about a month ago.  Sorry I didn't report then.  I 
installed the ones I needed downloaded from cpan.org, and they seem to work 
fine.

Alex to Dan:
I'm not an MD5SUM fanatic but especially in this case where the files are 
written "by hand" (and thus theoretically easily modifiable by any old hacker) 
in seeing all 39 of'em fail I got a little nervous.  ...
I fully concur with the BLFS - and in general the common sense - philosophy 
that 
a file should be downloaded from one place and its signature should be provided 
by an independent source.  A file may seem to work for a while, but who knows 
what happens in the long run. >>

> (1) Not sure how to fix this in the stable book, other than
> (2) download all 39 Perl Modules
> (3) (some of which may not even be available any longer as
they have been updated to newer versions on CPAN) and
> (4) create an md5sums file and upload it to Anduin.

(1) Agree. Too late.  The barn door has long been opened.
(2) Agree. Downloading is not too onerous: approx. 4 SBU's in all.
(3) Agree. On 10/16/05 when I did the 38-file book download I had to do the 
39th 
(Finance-Quote) directly from CPAN.
(4) Full agreement here too, Anduin is the only practical solution.
The only problem - and yes, this one might be time consuming/annoying, etc. - 
is 
the need to verify at least "visually", that the files are not so changed 
(accidentally or maliciously) as to affect BLFS installation of various 
packages 
which require (or option) them.

-- Alex



------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.
You are the QA contact for the bug, or are watching the QA contact.
-- 
http://linuxfromscratch.org/mailman/listinfo/blfs-book
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page

Reply via email to