From owner-freebsd-questions@FreeBSD.ORG Tue Nov 20 03:04:50 2012 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 08D6D631; Tue, 20 Nov 2012 03:04:50 +0000 (UTC) (envelope-from xaque208@gmail.com) Received: from mail-pa0-f54.google.com (mail-pa0-f54.google.com [209.85.220.54]) by mx1.freebsd.org (Postfix) with ESMTP id A9B4C8FC13; Tue, 20 Nov 2012 03:04:49 +0000 (UTC) Received: by mail-pa0-f54.google.com with SMTP id kp6so4025546pab.13 for ; Mon, 19 Nov 2012 19:04:49 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=date:from:to:cc:subject:message-id:references:mime-version :content-type:content-disposition:in-reply-to:user-agent; bh=ka4POaggfWqht6arGSuXewq3KgCzCUWkGmyCQLKeVA0=; b=tAUrZYw+Avbax1oD3sv3Qdnx6mC64iIPTyv0TT0BnT4b+N6Ta8/VP90lga5QfoRY19 0DBb0q/EEqB6p33J7Wd40+S+KRNp9OuauUqtLxwKMeJvXUQD2jVzh+o8Topw0O8BGmnf iimqy5g1VNvvqnp8UdsSouvGXjDUNkTgUa91YKie43y6tvZBx8u44qDD56Xt17pTVKHw +OiIsc1TNxePz+owWgz/nZLTsf5UDB/9/ruDoGXMDoJUZNi2GqlIJdmT//da0O2n+hry C5daJwBD9P6J4qyR7vMt87iZN+1e0o1y085PSGP810K37b+HqWW8bwu6jWKonps7CVgR fAZg== Received: by 10.68.197.197 with SMTP id iw5mr38584521pbc.22.1353380689192; Mon, 19 Nov 2012 19:04:49 -0800 (PST) Received: from localhost (c-67-171-138-28.hsd1.or.comcast.net. [67.171.138.28]) by mx.google.com with ESMTPS id gu5sm7228613pbc.10.2012.11.19.19.04.46 (version=TLSv1/SSLv3 cipher=OTHER); Mon, 19 Nov 2012 19:04:48 -0800 (PST) Date: Mon, 19 Nov 2012 19:04:45 -0800 From: Zach Leslie To: Adrian Chadd Subject: Re: FreeBSD needs Git to ensure repo integrity [was: 2012 incident] Message-ID: <20121120030445.GA38037@zjl.local> References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.21 (2010-09-15) X-Mailman-Approved-At: Tue, 20 Nov 2012 03:11:26 +0000 Cc: freebsd-security@freebsd.org, freebsd-hackers@freebsd.org, freebsd-hubs@freebsd.org, grarpamp , freebsd-questions@freebsd.org X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Nov 2012 03:04:50 -0000 > There's a git repository. It's public. You can look at what goes into > the FreeBSD git clone to get your assurance that things aren't being > snuck in. People are using it, right now. I've always been confused by this. Which source repo is the true source of truth? To obtain the FreeBSD source, you can use CVS, SVN, or Git? Do all have the same level of support? Are they all up to date? > Honestly, I'd rather see subversion grow this kind of cryptographic > signing of each commit in the short term then migrate everyone over to > git. How much effor would their really be involved, considering your link to the FreeBSD source repo on github. Converting the repos to me seems like it would be the bulk of it, and that work is already done. Help me understand please. Also, local branching and merging is amazing. -- Zach