[vlc-devel] Complete, Corresponding Source (CCS) for a VLC binary release

Lasse Kantola Lasse.Kantola at iki.fi
Sat Feb 17 07:46:33 CET 2018


On Mon, 12 Feb 2018 00:39:21 +0100
"Jean-Baptiste Kempf" <jb at videolan.org> wrote:

> It seems all were correctly mirrored on our servers, then.

Yes, the mirrored packages were all correct.

> > - Packages without SHA512SUMS
> >   - mfx: BAD, because uses Git clone, but version is not specified.
> >   - postproc: looks BAD, but OK in practice.
> >     - BAD, because uses Git snapshot without version information.
> >     - OK, because no version changes in Git after 2012, and the Git 
> > snapshot is bit-exact to 
> > http://ftp.videolan.org/pub/contrib/postproc-git.tar.gz
> >   - tremor: BAD, because uses SVN export without version
> > information.
> >   - x264: BAD, because uses Git snapshot without version
> > information
> > ftp://ftp.videolan.org/pub/videolan/x264/snapshots/last_stable_x264.tar.bz2
> So, only those 4 libraries are an actual issue, right?

Yes, the version information for x264, postproc, mfx, and tremor is not
exact, there is no SHA512SUM or pinned Git version. However, tremor and
mfx were not part of the VLC 2.2.2 binary release, so there is no issue.
Also, the postproc version can be deduced easily and matches the
mirrored postproc-git.tar.gz.

So in the end, the only real remaining issue for the VLC 2.2.2 release
is the x264 version that is not exactly known.


More information about the vlc-devel mailing list