Bug#636314: apt: Packages.bz2 checksum mismatch not detected

2011-08-13 Thread Julian Andres Klode
On Fri, Aug 05, 2011 at 07:23:15AM -0400, Hamish Moffatt wrote: On Fri, Aug 05, 2011 at 12:32:17PM +0200, Michael Vogt wrote: On Tue, Aug 02, 2011 at 04:14:18AM -0400, Hamish Moffatt wrote: Package: apt Version: 0.8.10.3+squeeze1 Severity: important Thanks for your bugreport.

Bug#636314: apt: Packages.bz2 checksum mismatch not detected

2011-08-05 Thread Michael Vogt
On Tue, Aug 02, 2011 at 04:14:18AM -0400, Hamish Moffatt wrote: Package: apt Version: 0.8.10.3+squeeze1 Severity: important Thanks for your bugreport. I have a test repository containing a Packages.bz2 file with different checksums than what is listed in the signed Release file. However,

Bug#636314: apt: Packages.bz2 checksum mismatch not detected

2011-08-05 Thread Hamish Moffatt
On Fri, Aug 05, 2011 at 12:32:17PM +0200, Michael Vogt wrote: On Tue, Aug 02, 2011 at 04:14:18AM -0400, Hamish Moffatt wrote: Package: apt Version: 0.8.10.3+squeeze1 Severity: important Thanks for your bugreport. I have a test repository containing a Packages.bz2 file with different

Bug#636314: apt: Packages.bz2 checksum mismatch not detected

2011-08-05 Thread Michael Vogt
On Fri, Aug 05, 2011 at 07:23:15AM -0400, Hamish Moffatt wrote: On Fri, Aug 05, 2011 at 12:32:17PM +0200, Michael Vogt wrote: On Tue, Aug 02, 2011 at 04:14:18AM -0400, Hamish Moffatt wrote: Package: apt Version: 0.8.10.3+squeeze1 Severity: important [..] I can verify this for

Bug#636314: apt: Packages.bz2 checksum mismatch not detected

2011-08-05 Thread Hamish Moffatt
On Fri, Aug 05, 2011 at 02:04:27PM +0200, Michael Vogt wrote: On Fri, Aug 05, 2011 at 07:23:15AM -0400, Hamish Moffatt wrote: The test-bz2-hash-error.tar that is attached to the bug does not have a Release.gpg file. With this unsigned archive there is indeed no hashsum check. So it is, my

Bug#636314: apt: Packages.bz2 checksum mismatch not detected

2011-08-02 Thread Hamish Moffatt
Package: apt Version: 0.8.10.3+squeeze1 Severity: important I have a test repository containing a Packages.bz2 file with different checksums than what is listed in the signed Release file. However, 'apt-get update' does not report any error and shows the resulting packages in the output of