Hello community, here is the log from the commit of package wireshark for openSUSE:Factory checked in at 2013-03-18 07:19:17 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/wireshark (Old) and /work/SRC/openSUSE:Factory/.wireshark.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Package is "wireshark", Maintainer is "CYLiu@suse.com" Changes: -------- --- /work/SRC/openSUSE:Factory/wireshark/wireshark.changes 2013-03-08 09:56:56.000000000 +0100 +++ /work/SRC/openSUSE:Factory/.wireshark.new/wireshark.changes 2013-03-18 07:19:19.000000000 +0100 @@ -1,0 +2,5 @@ +Sat Mar 9 11:24:29 UTC 2013 - andreas.stieger@gmx.de + +- add verfication of source signatures + +------------------------------------------------------------------- New: ---- SIGNATURES-1.8.6.txt wireshark.keyring ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ wireshark.spec ++++++ --- /var/tmp/diff_new_pack.S2IxJO/_old 2013-03-18 07:19:21.000000000 +0100 +++ /var/tmp/diff_new_pack.S2IxJO/_new 2013-03-18 07:19:21.000000000 +0100 @@ -25,9 +25,12 @@ Summary: A Network Traffic Analyser License: GPL-2.0+ and GPL-3.0+ Group: Productivity/Networking/Diagnostic -Url: http://www.wireshark.org/ -Source: http://www.wireshark.org/download/src/%{name}-%{version}.tar.bz2 +Url: https://www.wireshark.org/ +Source: https://www.wireshark.org/download/src/%{name}-%{version}.tar.bz2 Source1: include.filelist +Source2: https://www.wireshark.org/download/SIGNATURES-%{version}.txt +# https://www.wireshark.org/download/gerald_at_wireshark_dot_org.gpg +Source3: wireshark.keyring # PATCH-FIX-OPENSUSE wireshark-1.6.3-disable-warning-dialog.patch bnc#349782 prusnak@suse.cz -- don't show warning when running as root Patch1: %{name}-1.2.0-disable-warning-dialog.patch # PATCH-FEATURE-OPENSUSE wireshark-1.2.0-geoip.patch prusnak@suse.cz -- search in /var/lib/GeoIP if user hasn't set any GeoIP folders @@ -78,6 +81,9 @@ BuildRequires: update-desktop-files Recommends: GeoIP %endif +%if 0%{?suse_version} >= 1230 +BuildRequires: gpg-offline +%endif %description Wireshark is a free network protocol analyzer for Unix and Windows. It @@ -105,6 +111,12 @@ view the reconstructed stream of a TCP session. %prep +%{?gpg_verify: %gpg_verify %{S:2}} +# The publisher doesn't sign the source tarball, but a signatures file containing multiple hashes. +# Verify hashes in that file against source tarball. +echo "`grep %{name}-%{version}.tar.bz2 %{S:2} | grep MD5 | head -n1 | cut -d= -f2` %{S:0}" | md5sum -c +echo "`grep %{name}-%{version}.tar.bz2 %{S:2} | grep SHA1 | head -n1 | cut -d= -f2` %{S:0}" | sha1sum -c + %setup -q %patch2 %patch4 ++++++ SIGNATURES-1.8.6.txt ++++++ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 wireshark-1.8.6.tar.bz2: 24250787 bytes MD5(wireshark-1.8.6.tar.bz2)=317361e701936c72f7f18f857059b944 SHA1(wireshark-1.8.6.tar.bz2)=0f51ed901b5e07cceb1373f3368f739be8f1e827 RIPEMD160(wireshark-1.8.6.tar.bz2)=21688bef39816cc81d596205eefc5a067e5d6c25 Wireshark-win64-1.8.6.exe: 26847472 bytes MD5(Wireshark-win64-1.8.6.exe)=ddd3d98096538e357e2dd0d6cd04ed6b SHA1(Wireshark-win64-1.8.6.exe)=0d042dce029072dfcb8f52f49aa0c84bfb6d8a69 RIPEMD160(Wireshark-win64-1.8.6.exe)=2656bf18e3131da2b64feeb4d91c687768fe6f1f Wireshark-win32-1.8.6.exe: 21173600 bytes MD5(Wireshark-win32-1.8.6.exe)=3a0de374fc4979001727bfa5fc19d3c5 SHA1(Wireshark-win32-1.8.6.exe)=bed78fb3c51cfec9914bf46f6257da2541407d5c RIPEMD160(Wireshark-win32-1.8.6.exe)=e6cb0e40236093f5bf45909d1c306b64b0b99264 Wireshark-1.8.6.u3p: 28607931 bytes MD5(Wireshark-1.8.6.u3p)=fa19996f6c69f68d011565b2c49c27b3 SHA1(Wireshark-1.8.6.u3p)=e29efab380c4da61b25678c764403719b0088875 RIPEMD160(Wireshark-1.8.6.u3p)=01cb4634b95e8b08387711fab79f674d1dcae4b4 WiresharkPortable-1.8.6.paf.exe: 22184584 bytes MD5(WiresharkPortable-1.8.6.paf.exe)=a09a4ab23ffff08685d0ef42a0dc0f09 SHA1(WiresharkPortable-1.8.6.paf.exe)=f6f39ee3b202488ce3c48521692599a458c024e0 RIPEMD160(WiresharkPortable-1.8.6.paf.exe)=68a2dcf651c661499717a0f6c2abacabca48d94e Wireshark 1.8.6 Intel 32.dmg: 22122012 bytes MD5(Wireshark 1.8.6 Intel 32.dmg)=41b1249c0e0bdf0d851a816d20e01c12 SHA1(Wireshark 1.8.6 Intel 32.dmg)=d8eaf89fd2fdf13f47aaa9a25c1587a760534635 RIPEMD160(Wireshark 1.8.6 Intel 32.dmg)=ccadbdadddfd19991a6c7af9d2643a343fb3db75 Wireshark 1.8.6 PPC 32.dmg: 22934708 bytes MD5(Wireshark 1.8.6 PPC 32.dmg)=e9556eeacd50ddb4e70c9e5f98c442fa SHA1(Wireshark 1.8.6 PPC 32.dmg)=a8c8b2f6fb659b20ef2ae7785a2b5646f33c7ff5 RIPEMD160(Wireshark 1.8.6 PPC 32.dmg)=7b6a0e6161c1fb1d31caf7a6b5007cd38fce62f6 Wireshark 1.8.6 Intel 64.dmg: 21799059 bytes MD5(Wireshark 1.8.6 Intel 64.dmg)=265318dd55f4fd3dca228d9afc9348fe SHA1(Wireshark 1.8.6 Intel 64.dmg)=475ae0f50e65399a9a16c8266e505e8d9b27d308 RIPEMD160(Wireshark 1.8.6 Intel 64.dmg)=281386411018db57322e04c6c24927e9a7a774e7 patch-wireshark-1.8.5-to-1.8.6.diff.bz2: 385614 bytes MD5(patch-wireshark-1.8.5-to-1.8.6.diff.bz2)=1a61fcdfaf6d17d40cbe961951c1133e SHA1(patch-wireshark-1.8.5-to-1.8.6.diff.bz2)=18d53194b13de978d950394734ab7302f6d0394a RIPEMD160(patch-wireshark-1.8.5-to-1.8.6.diff.bz2)=b542539170925e88b52940ca41b65be1d0167a7c -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (Darwin) iEYEARECAAYFAlE3xcUACgkQpw8IXSHylJrbBQCfZNtcBR0tbayTH4LSikKn/tVY 3/kAoK21Cq19K4bhkOcEnHHEyelZWFOm =arCK -----END PGP SIGNATURE----- -- To unsubscribe, e-mail: opensuse-commit+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-commit+help@opensuse.org