EPICS Controls Argonne National Laboratory

Experimental Physics and
Industrial Control System

1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024  Index 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024 
<== Date ==> <== Thread ==>

Subject: Re: Changed source archive of StreamDevice release 2.8.22
From: "Zimoch Dirk \(PSI\) via Tech-talk" <tech-talk at aps.anl.gov>
To: NICOLE Remi <remi.nicole at cea.fr>
Cc: "tech-talk at aps.anl.gov" <tech-talk at aps.anl.gov>
Date: Thu, 24 Nov 2022 16:46:31 +0000
Hi Nicole,

Of course I never download the tarball from git, so I did not notice.
The content of the .VERSION file is generated on the git server at each download (by .gitattributes).
I can imagine it changes when 2.8.22 is no longer the current master HEAD when I uploaded a newer version. It contains
REFS: $Format:%D$
The %D is replaced by the git server.

Dirk

Am 24.11.2022 um 16:38 schrieb NICOLE Remi <remi.nicole at cea.fr>:

Hello, all!

I was testing a build of an IOC including StreamDevice with our Nix
build system, and that build system reported that the StreamDevice-
2.8.22.zip archive had a hash mismatch, i.e. the content changed
between when I first packaged it, and when I downloaded it recently.

I compared a previous version and a recent version, and I found that
the `.VERSION` file had a small change:

@@ -1,3 +1,3 @@
COMMIT: 94721c2b0e2ae118778d5783bd35cc642f573f60
-REFS:   HEAD -> master, tag: 2.8.22
+REFS:   tag: 2.8.22
DATE:   2021-11-11 11:49:32 +0100

Obviously, I think there's no functional change between the two, and it
seems the issue arose from the fact that the 2.8.22 tag was also the
master branch before.

But it seems weird to me that GitHub "reuploaded" the tarball, despite
GitHub saying the release was made in 2021-11-11.

It also feels weird that a source tarball of a fixed tagged version is
not itself "fixed". This, to me, feels like a security issue.

Any insights on this? Did anyone encounter this?

Thanks, and have a great day!
--
Rémi NICOLE <remi.nicole at cea.fr>
CEA/DRF/IRFU/DIS/LDISC

Replies:
Re: Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk
References:
Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk

Navigate by Date:
Prev: Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk
Next: Re: Illegal field value PV: oms:m1 motor_init_record_com(): card does not exist! motorOMS st.cmd error Mark Rivers via Tech-talk
Index: 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024 
Navigate by Thread:
Prev: Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk
Next: Re: Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk
Index: 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024 
ANJ, 25 Nov 2022 Valid HTML 4.01! · Home · News · About · Base · Modules · Extensions · Distributions · Download ·
· Search · EPICS V4 · IRMIS · Talk · Bugs · Documents · Links · Licensing ·