On 10/04/2011 11:02 AM, Greg KH wrote:
> On Tue, Oct 04, 2011 at 01:46:34PM -0400, Steven Rostedt wrote:
>> +my $pgp = `gpg --simple-sk-checksum -a --detach-sign $pass --output - <
>> $tmpfile`;
>
> Try not to use gpg when calling from scripts, use gpgv instead, it
> handles things much better, and sets the return value correctly so you
> can check it (which I don't think you do here.)
>
gpgv is only usable to verify contents (equivalent to gpg --verify).
For other things you need to use gpg's --status-fd feature, *or*
(perhaps better) run gpgv on the output to verify that you actually got
a good signature.
-hpa
_______________________________________________
Quilt-dev mailing list
[email protected]
https://lists.nongnu.org/mailman/listinfo/quilt-dev