From mboxrd@z Thu Jan 1 00:00:00 1970 From: Andreas Enge Subject: Re: Torrenting GuixSD! Date: Wed, 25 Feb 2015 18:51:56 +0100 Message-ID: <20150225175156.GA6653@debian.math.u-bordeaux1.fr> References: <54DE3317.7090002@riseup.net> <87vbj5e83e.fsf@fsf.org> <20150213205028.3f7cb9ba@PocketWee> <87wq382w45.fsf@gnu.org> <20150223205440.GA25828@debian> <87vbiqw0o4.fsf@gnu.org> <20150225141215.GA5109@debian.math.u-bordeaux1.fr> <87oaoidn19.fsf@netris.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:50080) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1YQg8f-0000TT-56 for guix-devel@gnu.org; Wed, 25 Feb 2015 12:52:50 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1YQg8b-0004yh-1Y for guix-devel@gnu.org; Wed, 25 Feb 2015 12:52:49 -0500 Content-Disposition: inline In-Reply-To: <87oaoidn19.fsf@netris.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org To: Mark H Weaver Cc: guix-devel@gnu.org, Polchi On Wed, Feb 25, 2015 at 10:32:50AM -0500, Mark H Weaver wrote: > If we were to extend this argument to non-torrent downloads, then all > of our downloads (source tarballs and images) should be tar files > containing a signature bundled with the thing being signed. mit-krb5 > follows this policy with their source tarballs. No, extending this argument to non-torrent downloads means that we should advertise the signature next to the actual file. This holds on the gnu ftp servers, where alphabetical ordering ensures they are next to each other. And it usually holds on web sites. In both cases, there is almost no extra effort for downloading the signature. Alternatively in our case, since the torrent file also needs to be downloaded from somewhere, it would make sense to put the signature file next to the torrent file on the download site. Andreas