* fetch checksum when possible * use sha256sum -c to validate checksum * use tar features to extract artifacts * validate installed pkg in-place Signed-off-by: Cyril Jouve <jv.cyril@gmail.com> Signed-off-by: Cyril Jouve <jv.cyril@gmail.com>