[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: svn commit: r13872 - trunk

From: Max Bowsher <maxb_at_ukf.net>
Date: 2005-04-03 22:10:09 CEST

Justin Erenkrantz wrote:
> --On Sunday, April 3, 2005 11:50 AM +0100 Max Bowsher <maxb@ukf.net>
> wrote:
>> Is signing supposed to assert "I have tested this"?
>> If so, shouldn't signing be a manual process?
> Well, it's an optional flag. Typically, the RM tests the release
> locally before posting it anywhere. Yet, I find signing the tarball
> at that initial stage is a good way to ensure that the tarball
> doesn't change once testing starts. The MD5 and sha1 sums aren't
> saved to a file, so there's no record of them except for being in the
> output of dist.sh.

If you would like to make them saved to a file, I think that's a reasonable
change to dist.sh.

> With the .asc file present, the RM can easily
> check the validity of the just created tarball. -- justin

Um, what? How is a tarball going to change without the concious activity of
the RM?

I still think that is inappropriate for our official distribution script to
be facilitating signing before test, whilst we have a policy of signatures
meaning "I have tested this".


To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org
Received on Sun Apr 3 22:12:24 2005

This is an archived mail posted to the Subversion Dev mailing list.