Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 27 Apr 2013 19:39:34 +0200
From:      John Marino <dragonflybsd@marino.st>
To:        freebsd-ports@freebsd.org
Subject:   Re: databases/mongodb 2.4.3 File size mismatch
Message-ID:  <517C0D56.8010505@marino.st>
In-Reply-To: <447gjolyxc.fsf@lowell-desk.lan>
References:  <517B8410.5010705@gmail.com> <447gjolyxc.fsf@lowell-desk.lan>

next in thread | previous in thread | raw e-mail | index | archive | help
On 4/27/2013 18:29, Lowell Gilbert wrote:
> klaasdemter@gmail.com writes:
>
>> something is wrong with mongodb port, make reports a mismatched file size.
>> =>  Attempting to fetch
>> http://downloads.mongodb.org/src/mongodb-src-r2.4.3.tar.gz
>> fetch: http://downloads.mongodb.org/src/mongodb-src-r2.4.3.tar.gz:
>> size mismatch: expected 14108201, actual 14108398
>
> Looks like the distfile got re-rolled under the same name.
> In which case it would be safe to just update the distinfo
> and go ahead with the build.
> I'm CC'ing the maintainer to update the port and
> double-check my (very quick) analysis of the security issues.

The pkgsrc guys make it a point to contact the party responsible for the 
re-roll and polite ask to never, ever do that again because all the 
repositories (ports, pkgsrc, apt, arch, rest of linux, etc) are 
depending on a hash and rerolling breaks all of them.

Sometimes upstream just doesn't realize the consequences and they'll not 
do it again once informed.  Something they just don't care and it keeps 
happening.

I am a bit surprised that a database developer that should understand 
issues with data integrity pulls a stunt like that though.

John



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?517C0D56.8010505>