On Tue, 2026-09-29 at 17:37 +0200, Mark Wielaard wrote: > I believe Ian wrote the checker for the uploads (the signature is also used > to check whether the uploader is allowed to release a new version for the > project). Ian, could the process be changed to (also) include an > detached/armored signature?
I wanted to peek at the server-side ftp-upload-script code and see if, maybe, it's already able to handle armored detached signatures or else draft a patch myself. After much searching I now believe it's internal-only and the source isn't available anywhere 😕 Anyway, I also want to say that conversion from the "binary" detached signature format to the "armored" detached signature format can be done losslessly without making a new signature. That's because the armored format is basically just the binary data but base64-encoded. This means that the script for upload acceptance could, going forward, "automagically canonicalize" the detached signatures by converting them to the armored format during processing. This would allow signatures to be made available in the armored format regardless of the particular manner a GNU maintainer prepared the upload, and without forcing changes to the "gnupload" script.
signature.asc
Description: This is a digitally signed message part
