On Sun, Jun 27, 2010 at 01:08:58PM +0200, Enrico Weigelt wrote:
> * Ciaran McCreesh <ciaran.mccre...@googlemail.com> schrieb:
> 
> > > Well, at least for tar, I've experienced no problem here yet.
> > > But: true, it might change between tar versions.
> > 
> > The main offender is the compression program, not tar.
> 
> hmm, I'm exclusively using bzip2 and never had these problems
> yet. maybe it depends on the compressor type.

http://www.gentoo.org/proj/en/glep/glep-0025.html#the-problem-in-detail

Note also that bzip2 had another change in output after that 
release- my memory is failing me a bit, but it was roughly a 
a reduction of their hash size to fix a CVE- either way, same thing, 
differing output.

It happens, and further, is a well known potential for compressors.

~harring

Attachment: pgp3rTeFHDsRa.pgp
Description: PGP signature

Reply via email to