[MERGE] [0.90] Disable patch verification (broken for CRLF files)

James Westby jw+debian at jameswestby.net
Mon Aug 13 17:43:27 BST 2007


On (13/08/07 08:54), Aaron Bentley wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Hi all,
> 
> We recently discovered that patch verification is broken for CRLF files
> (and probably CR files, too).  The fix appeared simple, but I've run
> into problems testing it, so I think the safest things it to disable it
> for now.  I'll get a fix in before 0.91.
> 
> I think it is important to get some kind of fix into 0.90, because it
> will be an extremely visible bug for projects using non-LF source files
> and bundles/merge-directives.
> 

I don't doubt the importance of this problem, but isn't the proposed fix
for 0.90 just opening up the hole that the check is designed to
prevent?

My understanding is that this check is there to ensure that the
revisions that will be installed have the effect that the preview patch
says they will when they are taken together. If this is not the case
then please correct me.

Thanks,

James

-- 
  James Westby   --    GPG Key ID: B577FE13    --     http://jameswestby.net/
  seccure key - (3+)k7|M*edCX/.A:n*N!>|&7U.L#9E)Tu)T0>AM - secp256r1/nistp256



More information about the bazaar mailing list