Re: Deprecating .gz format on kernel.org

Eric Sandall (eric@sandall.us)
Thu, 20 Mar 2003 10:31:28 -0800 (PST)


Jamie Lokier said:
> Eric Sandall wrote:
>> Jamie Lokier said:
>> <snip>
>> > Which is ok of course, but then the signatures don't match any more.
>> <snip>
>> > -- Jamie
>>
>> Why not get the signature from the .tar file, that way the compression
>> method doesn't matter? This is how Source Mage does it's checking, we
>> create and md5sum (and soon GPG) signature based on the uncompressed
>> .tar file. This way, you can use any compression you want, even
>> changing around the compression to your favourite one, and the
>> signatures will always match. :)
>
> (a) I use .gz for the patches not the tar files. But your point still
> applies.
>
> (b) On something as large as a .tar, decompressing a bz2 file to check
> the signature is really quite slow, compared with checking the
> signature of the compressed file.
>
> -- Jamie

True...for large files it'd be nice to know if you have the correct
tarball _before_ spending all that CPU time decompressing it. It's a
trade off, mostly, CPU time for more generic useage. I know this isn't
the Right Way(TM), but since fast computers are becoming fairly cheap, I
say the signature on the .tar file is a good way to go. However, Linux
also runs sufficiently well on slow machines, and this would just make
them slower. Shall we just follow the path of least resistence and keep
it as is?

-Sandalle

-- 
PGP Key 0x5C8D199A5A317214
http://search.keyserver.net:11371/pks/lookup?op=get&search=0x5A317214

Eric Sandall | Source Mage GNU/Linux Developer eric@sandall.us | http://www.sourcemage.org/ http://eric.sandall.us/ | SysAdmin @ Inst. Shock Physics @ WSU http://counter.li.org/ #196285 | http://www.shock.wsu.edu/

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/