From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Mon, 21 Sep 2026 08:18:30 +0200 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x8XME-004aGi-1O for lore@lore.pengutronix.de; Mon, 21 Sep 2026 08:18:30 +0200 Received: from [127.0.0.1] (helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1x8XMD-0008Dw-91; Mon, 21 Sep 2026 08:18:29 +0200 Received: from mx1.white.stw.pengutronix.de ([2a0a:edc0:0:b01:1d::107]) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1x8XLw-0008Do-5P for ptxdist@pengutronix.de; Mon, 21 Sep 2026 08:18:12 +0200 Received: from mail.thorsis.com (mail.thorsis.com [217.92.40.78]) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPS id DD112200291; Mon, 21 Sep 2026 08:18:10 +0200 (CEST) Authentication-Results: mx1.white.stw.pengutronix.de; dkim=pass header.d=thorsis.com header.s=dkim header.b=gCpfH8Rz; spf=pass (mx1.white.stw.pengutronix.de: domain of ada@thorsis.com designates 217.92.40.78 as permitted sender) smtp.mailfrom=ada@thorsis.com; dmarc=pass (policy=quarantine) header.from=thorsis.com Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id 7314214912CB; Mon, 21 Sep 2026 08:18:19 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thorsis.com; s=dkim; t=1789971499; h=from:subject:date:message-id:to:mime-version:content-type: content-transfer-encoding:in-reply-to:references; bh=RubzWtIxWk7llwlNLPWDM/g0D8vzwSbgYatWeHRXqhw=; b=gCpfH8RzZ+//AwQxzxR+SVdmvd3yESa0khva10Y62B8iMdeapd+ZTrzKot5byBjXEgOBws hWjOzXQYNB1q/07jOnU36j8gOlASEB0ntv/e/GEaZlqSGHVYLa3/HcEWcSVKgIY1Lwq851 izlzHSVRM5qO0NYCKssA2Duj5MO69GODTBcrNe8/kudTIyK77wyiuf4Jyvx0zS2gihnfgr /lz6tphe9pdiHu+ZIq006EeuOEgIfGIW8Oklxv4bZ5G+ybQ7kP/vvNzAEOs8aiyP1Z+6PR UrwBPbK1mUiS0O2JZ3p+uf5ZEz3kvpir5Jf7EAdGviPEJqiE4MPCiTHZTLdkag== Date: Mon, 21 Sep 2026 08:18:04 +0200 To: Alexander Dahl via ptxdist , Alexander Dahl , Sven =?iso-8859-1?Q?P=FCschel?= Message-ID: <20260921-granola-stimulus-1fd65d7980e8@thorsis.com> Mail-Followup-To: Alexander Dahl via ptxdist , Sven =?iso-8859-1?Q?P=FCschel?= References: <20260914150055.317620-1-ada@thorsis.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: User-Agent: Mutt/2.2.13 (2024-03-09) X-Last-TLS-Session-Version: TLSv1.3 X-Rspamd-Server: mx1 X-Stat-Signature: p6qg6hdax7zx91cf7prd4cwpb86zrk5q X-Rspamd-Queue-Id: DD112200291 X-Spamd-Result: default: False [-3.99 / 15.00]; BAYES_HAM(-2.99)[99.97%]; DMARC_POLICY_ALLOW(-0.50)[thorsis.com,quarantine]; R_DKIM_ALLOW(-0.20)[thorsis.com:s=dkim]; R_SPF_ALLOW(-0.20)[+mx]; MIME_GOOD(-0.10)[text/plain]; RCVD_TLS_ALL(0.00)[]; RCVD_VIA_SMTP_AUTH(0.00)[]; ASN(0.00)[asn:3320, ipnet:217.80.0.0/12, country:DE]; RCVD_COUNT_ONE(0.00)[1]; ARC_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; MID_RHS_MATCH_FROM(0.00)[]; NEURAL_HAM(-0.00)[-1.000]; RECEIVED_HELO_LOCALHOST(0.00)[]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_THREE(0.00)[3]; FROM_EQ_ENVFROM(0.00)[]; TO_DN_ALL(0.00)[]; TO_MATCH_ENVRCPT_SOME(0.00)[]; DKIM_TRACE(0.00)[thorsis.com:+] X-Rspamd-Action: no action Subject: Re: [ptxdist] [PATCH] xz: version bump 5.8.1 -> 5.8.4 X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Alexander Dahl via ptxdist Reply-To: ptxdist@pengutronix.de Cc: Alexander Dahl Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false Hello Michael, Am Sat, Sep 19, 2026 at 09:05:28AM +0200 schrieb Michael Olbrich: > On Mon, Sep 14, 2026 at 05:00:55PM +0200, Alexander Dahl via ptxdist wrote: […] > > Notes: > > Not sure what security gain we have from tarballs created by GitHub? > > It helps detecting supply chain attacks. The "make dist" archive is > basically impossible to reproduce, so we need to trust the uploader that it > was not modified. For the git tarball, all changes are visible in the > commit history. While someone still needs to look, it's much easier to spot > something. > And that is not theoretical: The xz backdoor did just that with a modified > build-to-host.m4. > > > This just makes packaging harder. > > I'm not sure what you mean with that. Usually upstream publishes sha256 sums and gpg signatures along a tarball release. I usually check those, and compare with the sums other distributions (e.g. buildroot) have in their packages. If we take the generated tarball from git, those checks are impossible. Greets Alex