apt-get source only checks md5 hashes in Sources files
Bug #1098738 reported by
Marc Deslauriers
This bug affects 3 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
apt (Ubuntu) |
Fix Released
|
High
|
Unassigned |
Bug Description
'apt-get source' only validates the md5 hash in the Sources file. Ideally, it should check the sha hashes also.
Related branches
Changed in apt (Ubuntu): | |
importance: | Undecided → High |
status: | Confirmed → In Progress |
tags: | added: patch |
To post a comment you must log in.
(I should have read all mails before answering some)
Setting to incomplete as I have no idea where you get that idea from. Can you please elaborate?
For history proposes, copy from https:/ /bugs.launchpad .net/launchpad/ +bug/1078697/ comments/ 15: :ForceHash) . What it does do with MD5 only is checking if the file on the disc matches the file we would download and if it does skipping the download as already done, which should be fixed (so that we can drop MD5 at some point) but has no real security implications as someone with write access to your local disk in that directory has better things to do …"
"And of course @mdeslaur, apt-get source does more than just checking MD5. It does what it does for all other downloads as well: Take the "best" checksum it knows and is available for checking if it isn't forced to use another (Acquire: