Vick Khera vivek at khera.org
Thu Oct 14 10:57:16 PDT 2010
On Thu, Oct 14, 2010 at 11:30 AM, Christopher Browne
<cbbrowne at ca.afilias.info> wrote:
> Ah, so BSD ports actually captures the checksum, and uses it.  That's
> good to know.  I'm glad that it is being used, and I suppose we ought to
> document the dependency.
>

FreeBSD ports system does this: download the raw tarball source files,
compare checksums, run configure with appropriate flags for FreeBSD,
compile, and finally install.  All scripted.

The checksums are baked into the recipe by the person making the port.
 In this case, me.

It was this exact mechanism that caught a trojaned OpenSSH source
tarball on one of its official mirrors a few years ago.


More information about the Slony1-general mailing list