On 2026/09/23 19:41, Marc Espie wrote:
> On Wed, Sep 23, 2026 at 09:10:13AM +0200, Marc Espie wrote:
> > I'll have a closer look tonight hopefully, but the signature information
> > is taken from the location, then passed into the installed
> > packing-list through decorate (in PackageRepository/Installed.pm)
> > 
> > The location info is done through uncompress, that does parse the gzip
> > comment.
> > 
> > Maybe IO::Uncompress::Gunzip changed recently and does not pass the
> > full comment around ? that would be my best guess.
> 
> Found it.
> 
> naddy probably changed the process he uses to sign packages.
> 
> the method strips the path, but it's a simple file name now.

---------------------
PatchSet 206 
Date: 2025/05/20 02:03:56
Author: tedu
Branch: HEAD
Tag: (none) 
Log:
only include basename of seckey in gzip header.
requested by deraadt to not leak paths.

Members: 
        signify.c:1.136->1.137 
        signify.h:1.2->1.3 
        zsig.c:1.19->1.20 

> The following patch fixes both the recording of the signer from
> the gzip header, and not erroring out for installed packages with
> no signer annotation.

committed.

Reply via email to