GNU bug report logs

#28659 Content-addressed mirror is not used upon invalid hash

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #11 received at 28659@debbugs.gnu.org (full text, mbox, reply):

Received: (at 28659) by debbugs.gnu.org; 1 Oct 2017 20:43:11 +0000
From debbugs-submit-bounces@debbugs.gnu.org Sun Oct 01 16:43:11 2017
Received: from localhost ([127.0.0.1]:43157 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1dyl4x-0005yl-BR
	for submit@debbugs.gnu.org; Sun, 01 Oct 2017 16:43:11 -0400
Received: from out1-smtp.messagingengine.com ([66.111.4.25]:52655)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <leo@famulari.name>) id 1dyl4v-0005yc-Lc
 for 28659@debbugs.gnu.org; Sun, 01 Oct 2017 16:43:10 -0400
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44])
 by mailout.nyi.internal (Postfix) with ESMTP id D7BAE2064D;
 Sun,  1 Oct 2017 16:43:08 -0400 (EDT)
Received: from frontend2 ([10.202.2.161])
 by compute4.internal (MEProxy); Sun, 01 Oct 2017 16:43:08 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name;
 h=cc:content-type:date:from:in-reply-to:message-id:mime-version
 :references:subject:to:x-me-sender:x-me-sender:x-sasl-enc
 :x-sasl-enc; s=mesmtp; bh=2k+RVcWP0aYb2httTw25HjuBAhrdvLT5W182CD
 yvLes=; b=KNXZhCWG4Bi4tDWcAr6fxdQE5D2Kvx/AmG8c3qXWm5+UluFQOapwCq
 Y9HxzToOo4R5PoLFAD1OFORopE+beX9+a+5Dhf5bILsOosk47Np9NiByJwoj0Uep
 0BOVobwm9r9qMs2oQNCJCJ3nfO1UpTYfUnvIEKButasjjCyIru4UU=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=cc:content-type:date:from:in-reply-to
 :message-id:mime-version:references:subject:to:x-me-sender
 :x-me-sender:x-sasl-enc:x-sasl-enc; s=fm1; bh=2k+RVcWP0aYb2httTw
 25HjuBAhrdvLT5W182CDyvLes=; b=USYoezVLrdZEkfx7DkWNfrS1YQddooiynO
 2l5e5EoErT8gaQB4+UG0A9O6oUF5215FBu5MMwAIhtwEeZTkxL8meLlxACOznQRh
 fLg5X1gMr5ZRWF2oBSqHdFsAVeoqvOt954R4UXjdxwejP3df47nHLfpMqvCcTUFf
 7ZPai++Szihazvlp4xX9yE7ikiJYX3XLfQS5mFeAS9JqfjCZWz5n1RBZcl94/gF9
 F+3ZirB/tQ7L/cJkDsQf7yUrIYFaiBTJ/SFqK+fJ6NikMR4txH6tdeNcuyGHST27
 lO9QHllf9+6broAdrS8wnBUm9U2I4kLeIqB08kjUd70ivqrjNBug==
X-ME-Sender: <xms:XFPRWWlp1bas1Onq0ZV7LzkZYPXMXLF6RMsS1PHNseYFU_Jm7M55rw>
X-Sasl-enc: rtnpa7B2o+RchyHPo/pYQ1m6Lf9VpnyfiQea5QFfeuOw 1506890588
Received: from localhost (unknown [172.58.201.79])
 by mail.messagingengine.com (Postfix) with ESMTPA id 88D172489C;
 Sun,  1 Oct 2017 16:43:08 -0400 (EDT)
Date: Sun, 1 Oct 2017 16:42:37 -0400
From: Leo Famulari <leo@famulari.name>
To: Jan Nieuwenhuizen <janneke@gnu.org>
Subject: Re: bug#28659: v0.13: guix pull fails; libgit2-0.26.0 and 0.25.1
 content hashes fail
Message-ID: <20171001204237.GA11804@jasmine.lan>
References: <877ewf18d4.fsf@gnu.org>
 <87wp4e8yk5.fsf@gnu.org>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature"; boundary="wRRV7LY7NUeQGEoC"
Content-Disposition: inline
In-Reply-To: <87wp4e8yk5.fsf@gnu.org>
User-Agent: Mutt/1.8.3 (2017-05-23)
X-Spam-Score: -0.7 (/)
X-Debbugs-Envelope-To: 28659
Cc: 28659@debbugs.gnu.org
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -0.7 (/)
[Message part 1 (text/plain, inline)]
On Sun, Oct 01, 2017 at 09:20:42PM +0200, Jan Nieuwenhuizen wrote:
> Jan Nieuwenhuizen writes:
> 
> The changing of the libgit-0.26.0 checksum was already reported about 3
> weeks ago (github seems to only show relative dates)
> 
>     https://github.com/libgit2/libgit2/issues/4343
> 
> and the bug is still open.  It seems to be a github thing.  As I
> understand it, currently our options are to update the hash and pray it
> won't happen again or host libgit2 tarballs ourselves.

I contacted GitHub about this issue a few weeks ago and they said that:

1) They do not guarantee bit-reproducibility of the snapshots they
generate automatically for each release tag, and they wish that people
would not rely on them as we do. However, since people *are* relying on
them, they are discussing this issue internally.
2) This is the relevant code change:
https://git.kernel.org/pub/scm/git/git.git/commit/?id=22f0dcd9634a818a0c83f23ea1a48f2d620c0546

In the meantime, we can add this to the list of reasons that
reproducibility is difficult in the long term.

I don't have any solutions in mind besides keeping substitutes available
for as long as possible and, for users, using substitutes. We might also
petition upstream projects to offer a "real" release tarball.
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Mon Sep 8 10:57:44 2025; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.