Maxwell G wrote: > Jul 20, 2026 11:50:33 AM Neal Gompa <[email protected]>: > > Sorry, I don't think this makes sense. Why %openpgpverify instead of > > just changing the implementation under %gpgverify? > If we can ensure that changing the implementation doesn't break any existing > packages, I think updating the existing one makes sense, but otherwise > renaming it is probably better.
Not breaking existing packages isn't enough. We don't control what every upstream developer signs releases with. Presumably some share of upstreams will keep using GnuPG. Even if Sequoia is compatible with all existing signatures, we'll start seeing GnuPG-specific signatures sooner or later if the two factions continue going their separate ways. I'd rather not end up with a verifier with "GPG" in its name that can't verify a GPG signature. The best solution would be a signature verifier that understands all kinds of PGP-like signatures, maybe a wrapper that would run either GnuPG or Sequoia depending on what kind of key or signature it's given. Absent that, there will need to be either separate macros or a switch so the packager can specify which tool to verify the signature with. Björn Persson
pgpEugwWEHouF.pgp
Description: OpenPGP digital signatur
-- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
