Add package verification to updatemgr#1497
Open
dpsmith wants to merge 4 commits intoOpenXT:masterfrom
Open
Conversation
Use the hash length to determine which algorithm to use. Signed-off-by: Jason Andryuk <jandryuk@gmail.com>
Use getopts to allow -d and -p to be specified in any order. Signed-off-by: Jason Andryuk <jandryuk@gmail.com>
It's better this way to check the signature before looking at the contents.
Use the new option to check the package hashes.
crogers1
reviewed
Aug 7, 2025
Contributor
crogers1
left a comment
There was a problem hiding this comment.
Looks fine to me other than the one comment.
| verifyUpdateMetadataSignature = void $ | ||
| handleError failed . safeShellExecuteAndLogOutput . cmd =<< allowDevRepoCert | ||
| where | ||
| - cmd False = "verify-repo-metadata " ++ updateDirCurrent |
Contributor
There was a problem hiding this comment.
Any reason this part of the change didn't go directly into manager.git?
shahs-ais
approved these changes
Aug 8, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR adds the ability for updatemgr to verify contents of packages file. For now the changes to updatemgr haskell code is left as a patch. If this is the desired default behavior, the patch can be applied to the haskell code repo, otherwise the patch could be hidden behind a OE feature variable.