Maxwell G wrote:
> Jul 20, 2026 11:50:33 AM Neal Gompa <[email protected]>:
> > Sorry, I don't think this makes sense. Why %openpgpverify instead of 
> > just changing the implementation under %gpgverify?  
> If we can ensure that changing the implementation doesn't break any existing 
> packages, I think updating the existing one makes sense, but otherwise 
> renaming it is probably better.

Not breaking existing packages isn't enough. We don't control what
every upstream developer signs releases with. Presumably some share of
upstreams will keep using GnuPG. Even if Sequoia is compatible with all
existing signatures, we'll start seeing GnuPG-specific signatures
sooner or later if the two factions continue going their separate ways.
I'd rather not end up with a verifier with "GPG" in its name that can't
verify a GPG signature.

The best solution would be a signature verifier that understands all
kinds of PGP-like signatures, maybe a wrapper that would run either
GnuPG or Sequoia depending on what kind of key or signature it's given.
Absent that, there will need to be either separate macros or a switch
so the packager can specify which tool to verify the signature with.

Björn Persson

Attachment: pgpEugwWEHouF.pgp
Description: OpenPGP digital signatur

-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to