Control: severity -1 serious

On 03/09/2026 11:00, Steve McIntyre wrote:
On Thu, Sep 03, 2026 at 10:54:43AM +0200, Pascal Hambourg wrote:
This bug is filed against debootstrap but these patches are against
debian-cd. Which package is faulty, debootstrap for not using available
SHA256 checksums or debian-cd for not providing SHA512 checksums ?

Arguably both? I'll take a look at debian-cd shortly...

I would say: Both...

debian-cd currently has a mixture of SHA512 and SHA256, whereas the new version 
of debootstrap picks the strongest and assumes that it will be available for 
both file types.

I propose to have the fix in debian-cd, and keep the current implementation of 
debootstrap.
However the migration of debootstrap to forky should be stalled until the daily 
netinst images are ready for SHA512. So I've raised the severity to RC.

With kind regards,
Roland Clobus

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to