From mboxrd@z Thu Jan  1 00:00:00 1970
Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org)
	by finch.gentoo.org with esmtp (Exim 4.60)
	(envelope-from <gentoo-dev+bounces-41587-garchives=archives.gentoo.org@lists.gentoo.org>)
	id 1OSwfO-0007de-59
	for garchives@archives.gentoo.org; Sun, 27 Jun 2010 18:33:19 +0000
Received: from pigeon.gentoo.org (localhost [127.0.0.1])
	by pigeon.gentoo.org (Postfix) with SMTP id 503A5E0D53;
	Sun, 27 Jun 2010 18:33:15 +0000 (UTC)
Received: from mail-pw0-f53.google.com (mail-pw0-f53.google.com [209.85.160.53])
	by pigeon.gentoo.org (Postfix) with ESMTP id 93193E0D4B
	for <gentoo-dev@lists.gentoo.org>; Sun, 27 Jun 2010 18:33:05 +0000 (UTC)
Received: by pwj9 with SMTP id 9so95961pwj.40
        for <gentoo-dev@lists.gentoo.org>; Sun, 27 Jun 2010 11:33:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=gamma;
        h=domainkey-signature:received:received:received:date:from:to:subject
         :message-id:references:mime-version:content-type:content-disposition
         :in-reply-to:user-agent;
        bh=zyNWQhUmx67pU9JrMgn7n6CZfWOVF9vAvSdYl+cKVyI=;
        b=wUAkeYe7NyXohayXIe285X1VJ1svBMwxi0yfhmncNpAHtia5V5v8R5wVi1i4NVOsQX
         i+8lCaL9Pm7J7rooTsNpDTdAY/qkssBRmJ6EOdqQb8WHArjccYNeEVYZTi9iJ78EA3Yx
         3mdvQAr3iiYPSTr1q4hWogFP1H2YBB+URqp7k=
DomainKey-Signature: a=rsa-sha1; c=nofws;
        d=gmail.com; s=gamma;
        h=date:from:to:subject:message-id:references:mime-version
         :content-type:content-disposition:in-reply-to:user-agent;
        b=gbQCcmbkR8Pc0kgzGFD26+04CBXaUkRldkdXIQZkDia0H+8FgoJZksrEPahspb/uMV
         d1LzbZdmYyqgzFxIWh/PV6saC/botLs7jAxC+DI5aJRI3+02I5hyZaq3SrCFQlSShHIQ
         wcCcRGPVl1kh+tdsmIdkX+8MNW3scJxTJQxD4=
Received: by 10.142.249.2 with SMTP id w2mr4285954wfh.25.1277663584813;
        Sun, 27 Jun 2010 11:33:04 -0700 (PDT)
Received: from smtp.gmail.com (c-67-171-128-62.hsd1.wa.comcast.net [67.171.128.62])
        by mx.google.com with ESMTPS id 21sm2255692wfi.5.2010.06.27.11.33.02
        (version=TLSv1/SSLv3 cipher=RC4-MD5);
        Sun, 27 Jun 2010 11:33:03 -0700 (PDT)
Received: by smtp.gmail.com (sSMTP sendmail emulation); Sun, 27 Jun 2010 11:33:06 -0700
Date: Sun, 27 Jun 2010 11:33:06 -0700
From: Brian Harring <ferringb@gmail.com>
To: gentoo-dev@lists.gentoo.org
Subject: Re: [gentoo-dev] FYI:  Rules for distro-friendly packages
Message-ID: <20100627183306.GA9990@hrair>
References: <4C2518FB.9090800@gentoo.org>
 <20100626185104.GB4789@nibiru.local>
 <4C265345.6060102@gentoo.org>
 <20100626194639.GE4789@nibiru.local>
 <20100626205921.4e2a0b9e@snowcone>
 <20100626200909.GG4789@nibiru.local>
 <20100626211816.7b4a13dc@snowcone>
 <20100627103443.GA23460@nibiru.local>
 <20100627114558.3e2d652d@snowcone>
 <20100627110858.GF23460@nibiru.local>
Precedence: bulk
List-Post: <mailto:gentoo-dev@lists.gentoo.org>
List-Help: <mailto:gentoo-dev+help@lists.gentoo.org>
List-Unsubscribe: <mailto:gentoo-dev+unsubscribe@lists.gentoo.org>
List-Subscribe: <mailto:gentoo-dev+subscribe@lists.gentoo.org>
List-Id: Gentoo Linux mail <gentoo-dev.gentoo.org>
X-BeenThere: gentoo-dev@lists.gentoo.org
Reply-to: gentoo-dev@lists.gentoo.org
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="PNTmBPCT7hxwcZjr"
Content-Disposition: inline
In-Reply-To: <20100627110858.GF23460@nibiru.local>
User-Agent: Mutt/1.5.20 (2009-06-14)
X-Archives-Salt: c4a8921f-1baa-4f07-91a9-6476fc3fcfa4
X-Archives-Hash: 4e91f3ff0854426f34ef69821fd25122


--PNTmBPCT7hxwcZjr
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sun, Jun 27, 2010 at 01:08:58PM +0200, Enrico Weigelt wrote:
> * Ciaran McCreesh <ciaran.mccreesh@googlemail.com> schrieb:
>=20
> > > Well, at least for tar, I've experienced no problem here yet.
> > > But: true, it might change between tar versions.
> >=20
> > The main offender is the compression program, not tar.
>=20
> hmm, I'm exclusively using bzip2 and never had these problems
> yet. maybe it depends on the compressor type.

http://www.gentoo.org/proj/en/glep/glep-0025.html#the-problem-in-detail

Note also that bzip2 had another change in output after that=20
release- my memory is failing me a bit, but it was roughly a=20
a reduction of their hash size to fix a CVE- either way, same thing,=20
differing output.

It happens, and further, is a well known potential for compressors.

~harring

--PNTmBPCT7hxwcZjr
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.15 (GNU/Linux)

iEYEARECAAYFAkwnmWIACgkQsiLx3HvNzgfVPACghdAOmikaopRoJOMf9NprKv2U
R78Ani+pbFk32ZnljJ/hZpcWuCO/c1fu
=d6Oe
-----END PGP SIGNATURE-----

--PNTmBPCT7hxwcZjr--