Re: [graphviz-interest] graphviz-2.39.20150520.1950.tar.gz has been stealth-updated

John Ellson <[email protected]> Mon, 01 Jun 2015 20:46:37 -0400
Newsgroups gmane.comp.video.graphviz
Message-ID <[email protected]>
Ryan,

OK, now I'm confused.

The md5sum on the web site matches the tar file:

$ wget -q -O - 
http://graphviz.org/pub/graphviz/development/SOURCES/graphviz-2.39.20150520.1950.tar.gz 
| md5sum
6b57d70edba18861f7ac2d92808e8ffe -
$ wget -q -O - 
http://graphviz.org/pub/graphviz/development/SOURCES/graphviz-2.39.20150520.1950.tar.gz.md5
6b57d70edba18861f7ac2d92808e8ffe  graphviz-2.39.20150520.1950.tar.gz


So I don't quite understand how you are detecting a problem?

The timestamp is now that of the last commit into github,  so the 
timestamps of any generated files inside the tar will always be 
later.      (Normally these will be <24hours later,  but right now they 
may be later than that because I've been messing with the build scripts.)

I don't understand the https://trac.macports.org/ticket/47902 report.  
Are they using some different checksum?

John


On 05/30/2015 11:42 PM, John Ellson wrote:
> Ryan,
>
> Probably bugs in my new scripts.
>
> I'm moving to a system where the timestamp on the sources, and all the 
> products built from those sources
> is based on the time of the last commit to github.    Previously it 
> was the time of the clone used for the build, and so there
> would be a new timestamp every day regardless of whether a commit had 
> been made or not.
>
> There is still  a clone and build every day, to verify that the 
> builders and the build dependencies are still good,   but the results
> are not (or not supposed to be) updated on the website if the 
> timestamp has not changed.
>
> I hope to get this all fixed shortly....
>
> John
>
> On 05/30/2015 09:59 PM, Ryan Schmidt wrote:
>> Hello,
>>
>> The file graphviz-2.39.20150520.1950.tar.gz on your server has been 
>> changed since it was uploaded -- not the contents of the files inside 
>> the archive, but their timestamps. The file was presumably first 
>> uploaded on 20150520. When I downloaded the file early on 20150523, 
>> some files in the archive were timestamped on 20150522. Downloading 
>> the file today, it contains files timestamped on 20150524. The 
>> changed timestamps cause the checksums of the tarball to change, 
>> which causes problems for anyone trying to use checksums to verify 
>> the file's integrity, as MacPorts does, as was reported here:
>>
>> https://trac.macports.org/ticket/47902
>>
>> I also note that this 20150520 tarball is the most recent available, 
>> though today is 20150530. You used to upload a tarball automatically 
>> every day. I assume you have changed your process so that you upload 
>> a tarball only when there have been changes in the repository, and 
>> that for a few days you had a bug in your procedure where you were 
>> rebuilding and uploading the tarball with new timestamps even though 
>> there had been no changes. Is that about right? You mentioned in this 
>> Graphviz bug report that you were going to change the frequency of 
>> the tarballs:
>>
>> http://www.graphviz.org/mantisbt/view.php?id=2545
>>
>> Has the process now been stabilized so that we can once again rely on 
>> the checksums of your files not changing after they are initially 
>> uploaded?
>>
>> Thanks,
>> -Ryan
>>
>>
>> _______________________________________________
>> [email protected]
>> http://lists.research.att.com/mailman/listinfo/graphviz-interest
>

_______________________________________________
[email protected]
http://lists.research.att.com/mailman/listinfo/graphviz-interest