On Tue, 2026-09-29 at 17:37 +0200, Mark Wielaard wrote:
> I believe Ian wrote the checker for the uploads (the signature is also used 
> to check whether the uploader is allowed to release a new version for the 
> project). Ian, could the process be changed to (also) include an 
> detached/armored signature?

I wanted to peek at the server-side ftp-upload-script code and see if, maybe, 
it's already able to handle armored detached signatures or else draft a patch 
myself. After much searching I now believe it's internal-only and the source 
isn't available anywhere 😕

Anyway, I also want to say that conversion from the "binary" detached signature 
format to the "armored" detached signature format can be done losslessly 
without making a new signature. That's because the armored format is basically 
just the binary data but base64-encoded. This means that the script for upload 
acceptance could, going forward, "automagically canonicalize" the detached 
signatures by converting them to the armored format during processing. This 
would allow signatures to be made available in the armored format regardless of 
the particular manner a GNU maintainer prepared the upload, and without forcing 
changes to the "gnupload" script.

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to