Gentoo Archives: gentoo-dev

From: "Frédéric Pierret" <frederic.pierret@××××××××.org>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [PATCH 1/5] verify-sig.eclass: New eclass to verify OpenPGP sigs
Date: Tue, 06 Oct 2020 11:50:05
Message-Id: f9ee74e7-93de-07fa-ad22-0f3ffe835a92@qubes-os.org
In Reply to: Re: [gentoo-dev] [PATCH 1/5] verify-sig.eclass: New eclass to verify OpenPGP sigs by Ulrich Mueller
1 Hi,
2
3 Le 2020-10-06 à 13:17, Ulrich Mueller a écrit :
4 >>>>>> On Tue, 06 Oct 2020, Michał Górny wrote:
5 >
6 >> verify-sig eclass provides a streamlined approach to verifying upstream
7 >> signatures on distfiles. Its primary purpose is to permit developers
8 >> to easily verify signatures while bumping packages. The eclass removes
9 >> the risk of developer forgetting to perform the verification,
10 >> or performing it incorrectly, e.g. due to additional keys in the local
11 >> keyring. It also permits users to verify the developer's work.
12 >
13 > We've already discussed it in #-qa, and I still think that this is
14 > over-engineered. Users can validate the distfile by the Manifest and its
15 > signature, so exposing the feature to users is redundant.
16
17 IMHO, manifest verification and distfile verification are two separate things. Before you validate and sign the Manifest, you need to fetch (new) source and to verify it. This is not redundant at all.
18
19 Best,
20 Frédéric Pierret

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies