Gentoo Archives: gentoo-dev

From: Zac Medico <zmedico@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [enhancement proposal] Per-file Manifest GPG signatures
Date: Wed, 06 Oct 2010 00:49:58
Message-Id: 4CABC79B.3030605@gentoo.org
In Reply to: Re: [gentoo-dev] [enhancement proposal] Per-file Manifest GPG signatures by "Robin H. Johnson"
1 On 10/05/2010 05:26 PM, Robin H. Johnson wrote:
2 > On Tue, Oct 05, 2010 at 05:53:50PM -0400, James Cloos wrote:
3 >> Have portage note in the ebuild log what was signed, by what key, and
4 >> whether the sigs were true.
5 > zmedico: can we include this in the repoman commit sig?
6
7 Sure. Currently, repoman only signs the Manifest files in the ebuild
8 directories. For single package commits, that's just one file. However,
9 it's possible to do category-level or even full-repo level commits,
10 though they're relatively rare. For these cases we'd be listing all the
11 Manifest files that changed.
12
13 Are we counting the files listed in the signed Manifest as signed too?
14 In that case, you want it to list any files that changed during that
15 commit? Forgive me if this is a stupid question, because I haven't been
16 following the whole discussion.
17 --
18 Thanks,
19 Zac

Replies

Subject Author
Re: [gentoo-dev] [enhancement proposal] Per-file Manifest GPG signatures "Robin H. Johnson" <robbat2@g.o>