On Tue, Oct 05, 2010 at 05:53:50PM -0400, James Cloos wrote:
> >>>>> "RHJ" == Robin H Johnson <[email protected]> writes:
> 
> RHJ> Some more issues for you:
> RHJ> 1. Increases the size of the Manifest by a minimum of 710 bytes _per_
> RHJ>    file. (4 bytes for 'GPG ', 700-900 for the hash, 1 for the field 
> space, 5-12 bytes for the
> RHJ>    trailer).
> RHJ> 1.1. 55907 Manifest2 entries need this signing, so that's a ~38MiB
> RHJ>      increase in the tree size.
> RHJ> 2. Impossible to validate without Portage itself, or at least another
> RHJ>    tool to convert the signature back into a form readable by GnuPG.
> 
> >From the standpoint of someone using Gentoo to Get Work Done:
> RMD160 and SHA1 just waste space.  SHA2 is sufficient non-encrypted
> hashing.
Please read the tree-signing GLEPs. This is already coming up, the GLEPs
included the migration window for it.

> Put distfile sigs in $DISTDIR or $FILESDIR.  They are just too large
> for a line-per-entry file.
$DISTDIR is an interesting idea. $FILESDIR costs too many inodes.

> Include the signing keyid in the filename to support both allowing
> multiple devs to sign a file and an easy indication of who signed it.
You can extract keyid from any signature trivially.

> Have portage note in the ebuild log what was signed, by what key, and
> whether the sigs were true.
zmedico: can we include this in the repoman commit sig?

> Make failing on a bad sig optional (per overlay?) and make sure that
> even when portage /is/ configured to fail on a bad sig that it only
> fails that one package and anything in the current set which depends
> on that version of the failed package.  Don't stop everything just
> because /one/ package has a problem.
This is already controllable.

> And think about a way to sign Changelog entries.
We wanted commit-signing with the git migration...

-- 
Robin Hugh Johnson
Gentoo Linux: Developer, Trustee & Infrastructure Lead
E-Mail     : [email protected]
GnuPG FP   : 11AC BA4F 4778 E3F6 E4ED  F38E B27B 944E 3488 4E85

Attachment: pgp7WfheVWeR4.pgp
Description: PGP signature

Reply via email to