5 ms·
Does anyone know how the `make verify-source` works?
by milliams 3y ago
Does anyone know how the `make verify-source` works?
- sltkr 3y agoIt's explained here: https://sqlite.org/getthecode.html#verifying_that_the_code_is_unmodified https://sqlite.org/getthecode.html#verifying_that_the_code_i...
- Denvercoder9 3y agoYou can find the source here: https://www.sqlite.org/cgi/src/file?name=tool/src-verify.c&ci=trunk https://www.sqlite.org/cgi/src/file?name=tool/src-verify.c&c... It seems to use a manifest with hashes for every file generated by their VCS.
- tedunangst 3y ago[god damn is it annoying to navigate through fossil to actually find a file] It appears to be basically sha3sum against an included manifest file. https://sqlite.org/src/file?name=tool/src-verify.c https://sqlite.org/src/file?name=tool/src-verify.c I am kinda perplexed at the threat model resolved by including a manifest in the same tree as the adulterated sources, checked by a running a tool compiled from those same adulterated sources.
- deleted 3y ago[deleted]
- istjohn 3y agoCosmic rays or other random sources of data corruption?
- inferiorhuman 3y ago[god damn is it annoying to navigate through fossil to actually find a file] Hey it still sucks less than the deuce Github's UI people dropped. They somehow managed to break using non-default branches. Imagine a world where git branches are an untested feature.
- justinclift 3y ago> They somehow managed to break using non-default branches. Interesting. What's the thing with non-default branches that's broken?
- inferiorhuman 3y agoThe first two have have finally been fixed more or less but: The compact navigation bar hides the branch (this part has been fixed). Scroll down and you can no longer jump to a different branch without scrolling back to the top of the page… which takes a while because the code view widget (UGH) punts navigation key presses off into a black hole. The new symbol navigator only links to the default branch even if you're on a different branch. The compare branches button is gone. You have to open a pull request to compare branches (or manually craft the path). Hyperlinks within markdown that reference the repo only go to the default branch. Searching within a repo only searches default branch even if you're searching from a different branch. Granted the search results have never been good, but still. More or less pick a non-default branch and experiment a little. Chances are you'll be forced back to the default branch in short order. Even when the ref name is a parameter in the URL. And that's about the nicest thing I can say about the new Github UI. Pretty much everything else is just worse universally (blurry text, laggy find within page, nothing rendered if javascript is disabled, etc, etc, etc).
- justinclift 3y agoOuch. Yeah, those sound like a pain. I don't like the recent UI overhaul much either, as it makes navigating around a bunch harder in most situations. :/
- inferiorhuman 3y agoYeah, it's especially unfortunate with all the vendor lock-in that Github's managed. Jumping ship to something with a usable interface means not contributing to a huge number of open source projects.