Browse Source
62dc983f1a Check sha256 hashes for downloads before GPG signature validation (Kristaps Kaupe)
Pull request description:
See #1338. User got partially downloaded libsodium tarball for some reason and user got confused with GPG signature validation error and though there was some problem with that. Let's check sha256 hashes before and abort there on error.
Before:
```
gpg: BAD signature from "Frank Denis (Jedi/Sector One) <0daydigest@pureftpd.org>" [unknown]
Terminated
```
After:
```
libsodium-1.0.18.tar.gz: FAILED
sha256sum: WARNING: 1 computed checksum did NOT match
Libsodium was not built. Exiting.
```
Top commit has no ACKs.
Tree-SHA512: b86d76fbc675092d9774a9210475b9e7ec9f81a6a89bc239bc37d99e737edf8e3d14ed5bf4640a0c5cbf0aabf788012e7dcef781aef0be0106260cd6086959de
master
1 changed files with 3 additions and 3 deletions
Loading…
Reference in new issue