1 |
On 17 July 2015 at 22:34, Andrew Savchenko <bircoph@g.o> wrote: |
2 |
> 2. Add an optional feature to emerge (or even to PMS?) allowing user |
3 |
> to provide a usable GPG key for signing packages CONTENTS files |
4 |
> after its generation. In order for such key to be usable during |
5 |
> emerge run, gpg-agent should be used; alternatively it may be |
6 |
> allowed to sign already installed packages on a trusted system. |
7 |
> 3. Of course backward compatibility with old CONTENTS format should |
8 |
> be kept. |
9 |
|
10 |
|
11 |
To keep things simple, I'd suggest storing the signature externally to |
12 |
the CONTENTS file. |
13 |
|
14 |
This would be more convenient for any tools that are trying to scrape |
15 |
the CONTENTS files with regex/grep not needing to first unwrap them. ( |
16 |
Not to mention trivial to determine which packages have signatures |
17 |
without needing to actually read the files ) |
18 |
|
19 |
Though, seeing we're going down this road, you could sign the whole vdb dir. |
20 |
|
21 |
-- |
22 |
Kent |
23 |
|
24 |
KENTNL - https://metacpan.org/author/KENTNL |