* Fix build on openbsd.
Thanks, James Cook for the patch.
* Include libkqueue.h file needed to build the assistant on BSDs.
+ * Tahoe: Avoid verifying hash after download, since tahoe does sufficient
+ verification itself.
-- Joey Hess <id@joeyh.name> Thu, 28 Jan 2021 12:34:32 -0400
downloadKey :: Key -> AssociatedFile -> FilePath -> MeterUpdate -> Annex Verification
downloadKey key _file dest p = do
get . map (torrentUrlNum . fst . getDownloader) =<< getBitTorrentUrls key
+ -- While bittorrent verifies the hash in the torrent file,
+ -- the torrent file itself is downloaded without verification,
+ -- so the overall download is not verified.
return UnVerified
where
get [] = giveup "could not download torrent"
retrieve :: RemoteStateHandle -> TahoeHandle -> Key -> AssociatedFile -> FilePath -> MeterUpdate -> Annex Verification
retrieve rs hdl k _f d _p = do
go =<< getCapability rs k
- return UnVerified
+ -- Tahoe verifies the content it retrieves using cryptographically
+ -- secure methods.
+ return Verified
where
go Nothing = giveup "tahoe capability is not known"
go (Just cap) = unlessM (liftIO $ requestTahoe hdl "get" [Param cap, File d]) $
-- ok, so if verification is disabled, don't verify it
| Verified
-- ^ Content was verified during transfer, so don't verify it
- -- again.
+ -- again. The verification does not need to use a
+ -- cryptographically secure hash, but the hash does need to
+ -- have preimage resistance.
| MustVerify
-- ^ Content likely to have been altered during transfer,
-- verify even if verification is normally disabled