Re: Files missing in RPM database

2024-05-01 Thread Christoph Karl via devel
Hi! Am 01.05.24 um 19:58 schrieb Jens-Ulrik Petersen: On Thu, May 2, 2024 at 1:21 AM Christoph Karl via devel < devel@lists.fedoraproject.org> wrote: I tried to find out which files on my upgraded fc40 installation are not installed via dnf/rpm. The list is surprisingly long. Perha

Files missing in RPM database

2024-05-01 Thread Christoph Karl via devel
Hi! I tried to find out which files on my upgraded fc40 installation are not installed via dnf/rpm. The list is surprisingly long. Main reasons are symlinks and directories not defined in the spec file. A quick check shows that this is also the case with a fresh installation. I see three reason

Re: Switching XZ for ZSTD?

2024-04-04 Thread Christoph Karl via devel
Hi! +1 The sequence must be: measure -> think -> act. Not: act (in panic) -> think (oh, that ist not the correct way, or even worse: oh, this is the way the attacker wants us to go.) measure (we have a weakness) Best regards Christoph Am 04.04.24 um 20:11 schrieb Leon Fauster via devel: One

Re: Three steps we could take to make supply chain attacks a bit harder

2024-03-31 Thread Christoph Karl via devel
+1 Am 01.04.24 um 06:31 schrieb Scott Schmit: One approach: 1. do the build 2. do the install 3. generate the RPMs 4. quarantine the RPMs so they're safe from modification - I believe this could be done via SELinux policy - there are probably other mechanisms 5. run the tests - for