Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 29 Jun 2016 16:50:55 -0700
From:      Colin Percival <cperciva@freebsd.org>
To:        Bryan Drewery <bdrewery@FreeBSD.org>, Yuri <yuri@rawbw.com>
Cc:        freebsd-pkgbase@FreeBSD.org
Subject:   Re: Are signatures of system images verified?
Message-ID:  <aeab12fa-f0f1-8823-84e4-ab065440a183@freebsd.org>
In-Reply-To: <5d642659-944b-d65d-9fc9-2aeab36acd98@FreeBSD.org>
References:  <2cde3a9e-8b4d-8c5e-408a-053710986e29@rawbw.com> <20160629213252.GI1453@FreeBSD.org> <5f72274d-6932-fbf2-8abd-86a865aec0d1@rawbw.com> <20160629215944.GJ1453@FreeBSD.org> <7ac94438-4d39-2695-7b79-9ce04373e7e1@rawbw.com> <20160629230324.GL1453@FreeBSD.org> <5d642659-944b-d65d-9fc9-2aeab36acd98@FreeBSD.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On 06/29/16 16:38, Bryan Drewery wrote:
> Around that time (January 2016), Colin Percival has been maintaining a
> copy of the MANIFESTS in ports-mgmt/poudriere as well.

For the record, I obtained these files by downloading the release ISOs,
verifying their hashes against the signed release announcements, and
then extracting the MANIFEST files from the ISOs, and I intend to do
this for future releases as well.  I think the consensus was that this
was a better option than adding "commit MANIFEST files to the ports
tree" to the already very lengthy release engineering checklist, but
of course I'd have no objection to handing over this task if re@ wanted
it for some reason. :-)

> Those get
> installed with Poudriere and used during jail -c after fetching if
> available, so that relying on https isn't required.  These were missing
> for ports-mgmt/poudriere-devel until just now.  I've moved them to
> misc/freebsd-release-manifests and made both ports depend on it.

Sounds good.

-- 
Colin Percival
Security Officer Emeritus, FreeBSD | The power to serve
Founder, Tarsnap | www.tarsnap.com | Online backups for the truly paranoid



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?aeab12fa-f0f1-8823-84e4-ab065440a183>