[MDEV-7212] Yum repo - altered packages with identical version numbers Created: 2014-11-26  Updated: 2015-06-19  Resolved: 2015-06-19

Status: Closed
Project: MariaDB Server
Component/s: Galera
Affects Version/s: 10.0.15-galera
Fix Version/s: 5.5.41-galera

Type: Bug Priority: Major
Reporter: Kenny Rasschaert Assignee: Daniel Bartholomew
Resolution: Fixed Votes: 0
Labels: galera


 Description   

We keep a downstream mirror of the package repository (specifically, the Galera variant of MariaDB 10.0 for CentOS 6 x86_64 and i686).

When updating last night, we downloaded the new 10.0.15 packages. What was troubling to us is that the galera-25.3.5-1.rhel6.x86_64.rpm package was modified. By this I mean that we previously had an identically named package with an md5 checksum of 9b9ac4f9e9f4f9fc0b0ec5435a6d2054 that since last night has the md5 checksum 3b85a02d1be91a4ac0708fc5cb71699c.

This raised some eyebrows. I hope you agree this goes against the reasonable expectation that when the package is altered, the version number (or at the very least the package release number) is increased.

After a quick investigation, it appears that the package contents are unaltered, but rpm tells us the previous package was signed at `Thu 16 Oct 2014 01:48:54 AM CEST`, where the new package was signed at `Mon 24 Nov 2014 04:06:28 PM CET`. Build time for both packages is identical at `Wed 25 Jun 2014 04:35:31 AM CEST`.

Our guess is that the CD process responsible for creating the repositories indiscriminately re-signs unaltered packages each time a repository build job is performed.



 Comments   
Comment by Elena Stepanova [ 2014-11-26 ]

nirbhay_c,

Could you please check whether it was a one-time thing, and if so, what was the reason for that, or is it a part of the process which in this case should be amended?

Comment by Nirbhay Choubey (Inactive) [ 2014-12-08 ]

dbart Do you know why the checksum for galera package changed?

Comment by Daniel Bartholomew [ 2014-12-08 ]

I agree, that should not happen. I'll investigate.

Comment by Daniel Bartholomew [ 2015-06-19 ]

we've altered how repositories are generated so that signatures for files that are constant between MariaDB versions stay the same, closing issue

Generated at Thu Feb 08 07:17:51 UTC 2024 using Jira 8.20.16#820016-sha1:9d11dbea5f4be3d4cc21f03a88dd11d8c8687422.