On Tue, Jul 21, 2026 at 11:01 AM Zbigniew Jędrzejewski-Szmek <
[email protected]> wrote:

> On Mon, Jul 20, 2026 at 02:42:38PM -0500, Maxwell G wrote:
> > Jul 20, 2026 11:50:33 AM Neal Gompa <[email protected]>:
> >
> > > Sorry, I don't think this makes sense. Why %openpgpverify instead of
> > > just changing the implementation under %gpgverify?
> > If we can ensure that changing the implementation doesn't break any
> existing
> > packages, I think updating the existing one makes sense, but otherwise
> > renaming it is probably better.
>
> I'm with Neal on this… Please make the existing macro use the new tool.
>

As already mentioned by Fabio, the gpgverify naming is confusing as its
tied to the
GnuPG name (instead of the OpenPGP standard) and we deliberately wanted to
avoid
this confusion.


> This will avoid a lot of work for both the Change Owners and the individual
> packagers, and also a lot of noise in the packages. And additionally,
> for packages which use the same branch for older releases, divergence
> between the branches.
>

It should not be a problem to create the macro for F44 and F43 to avoid
divergence.
If it will be a macro of different name than the current one -- that case
would be more
complicated.

It seems that the great majority of packages are using the standard form
> of "%{gpgverify} --keyring=… --signature=… --data=…", so hopefully we
> can make the new impl. a seamless replacement.


Yes. I already started putting together some tests to identify where the
sqv behaves
differently than the gpgv. From the gpgverify testsuite, its for example
missing support
for keybox keyrings and sequoia's handling of multiple armored signatures
in one
file (out of specs):

https://gitlab.com/sequoia-pgp/sequoia-sqv/-/work_items/27

The above discussed verification at the time of signature still need to be
tested and
I hope I will get to that in coming days.

Jakub
-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to