[Fedora-packaging] bad file in look-aside repository

Rex Dieter rdieter at math.unl.edu
Wed Mar 11 17:44:29 UTC 2009


John Dennis wrote:
> I need to correct a problem and I'm not sure the best way to handle it. 
...
> It seems as though "make new-sources" allows one to replace a file. Is 
> this true? If so I'm a bit surprised because it could permit malicious 
> behaviour and lead to non-repeatable builds.

My understanding is that sources are stored per cvs module (ie, a source 
uploaded in cvs module foo/ is not accessible from module bar/).

> Is there a mechanism to remove a file uploaded by mistake?

make new-sources ... again.  the md5sum will (should!) be different, and 
life should be good again.

-- Rex




More information about the Fedora-packaging mailing list