On 6. 10. 2026 16:38, Ivan Zhakov wrote:
On Tue, 6 Oct 2026 at 13:42, Branko Čibej <[email protected]> wrote:
On 6. 10. 2026 10:57, Ivan Zhakov wrote:
On Mon, 5 Oct 2026 at 19:42, Branko Čibej <[email protected]> wrote:
On 24. 9. 2026 13:21, Evgeny Kotkov via dev wrote:
The 1.15.0 release artifacts are now available for testing/signing.
Please get the tarballs from
https://dist.apache.org/repos/dist/dev/subversion
and add your signatures there.
Note: 1.15.0 tarballs should be functionally identical to 1.15.0-rc4
(they
are built from the same revision r1937767), with the only difference
being
in the version number.
Thanks!
I have an issue with the signatures for the .zip file:
gpg: assuming signed data in 'dev/subversion-1.15.0.zip'
... skipped sig from Evgeny
gpg: Signature made Fri Sep 25 12:54:09 2026 CEST
gpg: using RSA key
D6678482E2ED5750E28B69292FB22D0D4ADC662A
gpg: key 2FB22D0D4ADC662A: new key but contains no user ID - skipped
gpg: Can't check signature: No public key
I have the key in my keyring, but a public key without a user
ID isn't valid. Could whoever owns this key add an ID and
upload the updated key, please? Ivan, I think that's your new
key, given what I see in the logs?
It's my key.
It's the same key that I used to sign Subversion 1.15.0-rc4.
It's available on people.apache.org <http://people.apache.org>:
https://people.apache.org/keys/committer/ivan
And PGP keyservers:
https://keyserver.ubuntu.com/pks/lookup?search=D667+8482+E2ED+5750+E28B++6929+2FB2+2D0D+4ADC+662A&fingerprint=on&op=index
<https://keyserver.ubuntu.com/pks/lookup?search=D667+8482+E2ED+5750+E28B++6929+2FB2+2D0D+4ADC+662A&fingerprint=on&op=index>
https://keys.openpgp.org/vks/v1/by-fingerprint/D6678482E2ED5750E28B69292FB22D0D4ADC662A
I also see it in the subversion-1.15.0.KEYS file.
[[[
ASF ID: ivan
LDAP PGP key: D667 8482 E2ED 5750 E28B 6929 2FB2 2D0D 4ADC 662A
pub rsa4096/2FB22D0D4ADC662A 2026-07-14 [SC]
Key fingerprint = D667 8482 E2ED 5750 E28B 6929 2FB2 2D0D
4ADC 662A
uid [ unknown] Ivan Zhakov (CODE SIGNING KEY)
<[email protected]>
sub rsa4096/C62470648595D168 2026-07-14 [E]
Key fingerprint = 9F3F 4DF5 6E1A EF95 73AB F318 C624 7064
8595 D168
....
]]]
May be I am missing something?
Or maybe I am. I didn't see this key in my rc4 tests, because I
did the signature check before you signed. Could it be gpg somehow
got an incomplete copy of it? That would be a huge bug, but I
guess it's possible. Let me check ...
... so it turns out that your key did not propagate correctly to
keys.openpgp.org <http://keys.openpgp.org> which I use by default,
this is what I get:
$ gpg --keyserver hkps://keys.openpgp.org <http://keys.openpgp.org>
--recv-keys 2FB22D0D4ADC662A
gpg: key 2FB22D0D4ADC662A: new key but contains no user ID - skipped
gpg: Total number processed: 1
gpg: w/o user IDs: 1
Well, it's strange because the key is on keys.openpgp.org
<http://keys.openpgp.org>:
https://keys.openpgp.org/vks/v1/by-fingerprint/D6678482E2ED5750E28B69292FB22D0D4ADC662A
Yes, the key file is there, but it's incomplete. I downloaded it and
checked the contents and there's no UID.
$ gpg -v D6678482E2ED5750E28B69292FB22D0D4ADC662A.asc
gpg: enabled compatibility flags:
gpg: WARNING: no command supplied. Trying to guess what you mean ...
gpg: armor header: Comment: D667 8482 E2ED 5750 E28B 6929 2FB2 2D0D 4ADC 662A
pub rsa4096 2026-07-14 [SCEA]
D6678482E2ED5750E28B69292FB22D0D4ADC662A
sub rsa4096 2026-07-14 [E]
sig 2FB22D0D4ADC662A 2026-07-14 [keybind]
Only the pub, sub and sig fields are there, the uid field is missing.
That field is present in the key that's available on keyserver.ubuntu.com.
-- Brane