tag2upload supports pristine-tar
Ian Jackson <[email protected]>
| Newsgroups | gmane.linux.debian.devel.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
We are pleased to announce that tag2upload now supports pristine-tar.
Previously, even if you (the maintainer) used pristine-tar, the
tag2upload service would always generate any .orig tarballs not found
in the Debian archive with "git archive". git-debpush would warn you,
to avoid any surprises.
Now, origs will be regenerated using pristine-tar, if applicable.
Use of pristine-tar will be automatically detected; there is no need
to pass any additional options to git-debpush. [0]
You will need git-debpush 16.x, which is available in testing and
trixie-backports.
This support is still new, but it has been used successfully for many
uploads already. But problems are possible, especially with weird
tarballs. As ever, if you encounter problems, please file a bug.
To get going with tag2upload, start with the wiki docs or manpage:
https://wiki.debian.org/tag2upload
https://manpages.debian.org/trixie/git-debpush/git-debpush.1.en.html
Background and advice, about pristine-tar and gbp import-orig:
We do not recommend use of pristine-tar. Indeed, pristine-tar's
author intended the name as a joke, and doesn't recommend it either!
[1]
We also advise against gbp import-orig. gbp import-orig prefers
upstream tarball contents over real upstream source code from git.
This was even a factor which helped facilitate the xz backdoor! [2]
Instead, we recommend disregarding upstream tarballs and directly
using upstream git (via gbp import-ref, or plain git merge).
However, we want every maintainer to be able to use tag2upload,
without making other changes to your packaging practices.
We recognise that use of gbp import-orig and pristine-tar is very
common in Debian, and lack of pristine-tar support has been a blocker
for many people.
So, we have put in the work to integrate pristine-tar. It is now a
fully supported mode of operation for tag2upload.
I'd like to thank the early adopters who tried this out with the
new version of git-debpush (including from experimental) and whose
reports helped iron out a few bugs.
Ian.
(for the tag2upload Delegates)
[0] Non-users of pristine-tar do not need to worry: if you don't have
a pristine-tar branch with relevant data, git-debpush will function
precisely as before. And, tag2upload has safeguards against anomalous
pristine-tar data - better than traditional upload tools. For
example, even when pristine-tar in use, tag2upload will still ensure
that the uploaded source package corresponds precisely to your
packaging git branch.
[1] https://joeyh.name/blog/entry/upstream_git_repositories/
[2] https://en.wikipedia.org/wiki/XZ_Utils_backdoor#Mechanism
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27#design
-----BEGIN PGP SIGNATURE-----
iQJUBAEBCgA+FiEEQWOBFNEyiDslog3dR1FXV9gAJFYFAmp58FkgHGlqYWNrc29u
QGNoaWFyay5ncmVlbmVuZC5vcmcudWsACgkQR1FXV9gAJFbyrA/+IljKRiKmpHnJ
hXtInVnGTBVJHXm0FKtcRzc8dutjVfPtf9uHqocWKFVJ5jtEm6OrN7DgVieXnvAb
fd2ziBlnjhWzPlBJtbmLCUNd5RK2EBti2hccXvZFUMRK8UOWC+xbhEACalLVX0yR
xfMcHEKdHYNwzTUZJDTEp/Ftv/pCAtq4/EpT8bGpL7LWV/4+sCfCoC8SsX4yOZ3i
nco9Y60eBG3uqwg6mxgsr/03Ipe1pubY9UbkGiCFJpF4RCS7vRLpHGPtH81YN0Ku
pU5fHT/m+AKmIhyRwHj9K94yfXlfOaw2otpgHX9HGQPB0fj93pTyb4JjYh5aAjYZ
BQBvQJtOArHtz/r/fWFC0CjNvEx/oJ08fJK2+JsK7rUylGJf+z9i7iJE4fToLvwY
ZikS2T8cl4jRBdFzahR4Kk8AaztEKgndL3QTdsAt1R/Io1iEtEEnwdkzvotG9Frg
OF0aSM3FVVtcnlx3AFoWgDjFglepIjjsrXZt8IYxNMLLQUGHMzuJW4f5huhA2cZO
1HsXEB5bvG4KvlQBCezl+Dsv8xkOwD9CeZGEsOpjEW7TRPqBLBzT78BBjE9iIydJ
gOSZ1XDggR/878QKe6eVjlrl+0BHPMsiE/Br7ps7OKu9B5wMc/8EGAhgcgUvJmrK
VH0qvg/2JMXCHkgcMQ2UqDSRw6+m4M4=
=Uw6T
-----END PGP SIGNATURE-----