From mboxrd@z Thu Jan 1 00:00:00 1970 From: ng0 Subject: Re: Packaging packages with GPG signed source archives Date: Fri, 02 Sep 2016 12:46:41 +0000 Message-ID: <87inueo4em.fsf@we.make.ritual.n0.is> References: <87oa49crz1.fsf@gmail.com> <20160831172204.GB28096@jasmine> <87wpiwlmea.fsf@gnu.org> <878tvcmwqk.fsf@we.make.ritual.n0.is> <878tvcuinm.fsf@gnu.org> <87poomr4r8.fsf@we.make.ritual.n0.is> <87twdyo5w1.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:52884) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bfnrv-0000qo-BQ for help-guix@gnu.org; Fri, 02 Sep 2016 08:46:52 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bfnrq-0007M3-TT for help-guix@gnu.org; Fri, 02 Sep 2016 08:46:51 -0400 In-Reply-To: <87twdyo5w1.fsf@gnu.org> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: help-guix-bounces+gcggh-help-guix=m.gmane.org@gnu.org Sender: "Help-Guix" To: Ludovic =?utf-8?Q?Court=C3=A8s?= Cc: help-guix Ludovic Courtès writes: > ng0 skribis: > >> Ludovic Courtès writes: >> >>> Hi, >>> >>> ng0 skribis: >>> >>>> On the subject of git repos, I do not understand enough of the >>>> git-download.scm at the moment to add this myself, but why don't we have >>>> git-fsck in it as default? >>> >>> Dunno; what would it add? >>> >>> Ludo’. >> >> I don't understand enough of it, I only know someone else added it to >> some project I contribute to. > > Guix ‘origin’ forms store the expected SHA256 of the checkout. So > everytime we do a Git checkout, guix-daemon explicitly makes sure the > the checkout contents match the given SHA256. IOW, we already have > integrity checks built in Guix. For this reason, I think ‘git fsck’ > wouldn’t provide any additional guarantee. > > Hope this makes sense! > > Ludo’. I agree …and wonder if I run into equal problems once I have done the guix publish/pull/package via gnunet-fs as Nix is discussing for the distributed system they are discussing to move to, where their problem is that they need to convert all the hashes for when they'll move all the sources into that network. I'll see when I get there. -- ng0 For non-prism friendly talk find me on http://www.psyced.org