Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: Andrew Savchenko <bircoph@g.o>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [RFC] Make manifest signatures mandatory for repoman commit
Date: Wed, 15 Apr 2015 09:06:48
Message-Id: 20150415110622.55ab869c@pomiot.lan
In Reply to: [gentoo-dev] [RFC] Make manifest signatures mandatory for repoman commit by Andrew Savchenko
1 Dnia 2015-04-15, o godz. 11:59:12
2 Andrew Savchenko <bircoph@g.o> napisał(a):
3
4 > Hi,
5 >
6 > why manifest signatures are still optional for repoman?
7 >
8 > Repoman signatures are currently optional and this creates nasty
9 > consequences: if signing errors occurs, repoman still proceeds :/
10 >
11 > I just had a phone call during repoman commit and was not able to
12 > type my password. Due to gpg-agent timeout repoman completed commit
13 > without a signature :( Should signatures be mandatory, repoman will
14 > bail out on such conditions and devs can recommit again safely.
15
16 This is problem with the CVS two-commit procedure. The only solution is
17 to stop using CVS keywords which people don't want to do because THEY
18 ARE SO VERY USEFUL.
19
20 Or make repoman do first commit without Manifest, so instead of
21 unsigned Manifest you'd have Manifest failure.
22
23 --
24 Best regards,
25 Michał Górny

Replies