Quicklisp (https://www.quicklisp.org/beta/) is a great tool for downloading Common Lisp libraries. However, it works with HTTP only. HTTP is inherently insecure to man in the middle attacks. This little patch is meant to address this problem.
Quicklisp uses its own Lisp code to download the required packages (commonly as gzipped files), from the designated URLs. These repos all provide HTTPS endpoints as well. But since Quicklisp code is meant to work with all Lisps and most platforms, it can only
download with HTTP urls currently. This patch uses system wget to mitigate the problem.
Once you have a working Quicklisp installed on your system,
- Make sure you have
wgetinstalled. Alternatively you can use anything you like (e.g.curl). - Download the
http.lispfile and replace Quicklisp's own http.lisp with it. Make sure you take a backup before replacing. - Open the new http.lisp and search for
Note to programmer. - Here, you can change the path to your WGET or CURL or any other program that supports downloading https urls.
- That's all there is.
When installing systems with Quicklisp next time, you should see messages like this:
WARNING: Using system WGET instead of native Lisp code
INFO: URL http://beta.quicklisp.org/archive/drakma/2019-11-30/drakma-v2.0.7.tgz
WARNING: Switching to HTTPS
INFO: New URL https://beta.quicklisp.org/archive/drakma/2019-11-30/drakma-v2.0.7.tgz