Ticket #1242 (closed enhancement: fixed)

Opened 7 years ago

Last modified 7 years ago

[patch] GPG signature support for dotar

Reported by: mehh Owned by:
Priority: Sometime Milestone:
Component: clients/cave Version: 0.74.1
Keywords: Cc:
Blocked By: Blocking:
Distribution: N/A

Description

Here's a straightforward GPG signature support patch for the dotar fetchers. I use it to get a "Gentoo Portage Snapshot Signing Key" < http://www.gentoo.org/proj/en/releng/> authenticated version of the portage tree over dodgy networks.

The signature is downloaded first to make this less racy.

Attachments

gentoo-auth.conf Download (312 bytes) - added by mehh 7 years ago.
syncer-dotar-gpgsig.patch Download (1.4 KB) - added by mehh 7 years ago.
0001-Support-git-signature-sync-option-in-dotar-fetchers.patch Download (1.8 KB) - added by mehh 7 years ago.
please ignore this one
0001-Support-gpg-signature-sync-option-in-dotar-fetchers.patch Download (1.8 KB) - added by mehh 7 years ago.

Change History

Changed 7 years ago by mehh

Changed 7 years ago by mehh

comment:1 Changed 7 years ago by dleverton

Strictly speaking this shouldn't assume that the same value of ${FETCHER} is OK for both the tarball and the signature. On the other hand, having it separate implies having a --signature-fetch-option flag or something, which is possibly overdoing it a bit, and it's pretty unlikely to be different in practice....

As for the race between downloading the tarball and downloading the signature, that's a bit unfortunate, but again I'm not sure if there's a reasonable alternative. emerge-webrsync handles this by explicitly figuring out the date of the latest snapshot and downloading it by the dated name, rather than using "latest", which we could potentially do in a more specialised fetcher but not the generic tar one.

If no-one has any further comments on the above, could you reattach in "git format-patch" format please? It's not vital but allows the authorship to be recorded properly.

Changed 7 years ago by mehh

please ignore this one

comment:2 Changed 7 years ago by dleverton

  • Status changed from new to closed
  • Resolution set to fixed

Someone REALLY needs to fix trac to send emails when people attach files. Now committed, sorry for the delay.

Note: See TracTickets for help on using tickets.