[qt/qt/qtapplicationmanager]: Summary of bulk changes made

KDE Git Services - Bulk Change <[email protected]>
Newsgroups gmane.comp.kde.cvs
Message-ID <[email protected]>
Git repository change summary for qt/qt/qtapplicationmanager
Pushed by mirror-service into branch '6.12'.
Changed from 02235924d273f5ed57e3d81cef4ea6fc00e85cca to 60102008496b23dbd38210cdd0063c22b49a4ec5
Acknowledgement was received that this change introduces only existing code that has been pushed to another public open source repository.

This change contains the following new commits:

Git commit a6d80c1ad057562ccccb18b864ce128b64262ed8 by Qt Cherry-pick Bot (on behalf of Robert Griebl) on 13/08/2026 at 14:51..
Security review: require store signatures for System UI installs

Split the task origin System into SystemDeveloper and SystemUI and
derive it in one place from the D-Bus bus type and the development
mode. The signature verification in InstallationTask is now purely
origin based instead of consulting the development mode:

 * SystemUI installs always need both a store and a developer
   signature. Before, enabling development mode also relaxed the
   store signature requirement for System UI initiated installs.
 * ApplicationDeveloper installs (via appman-controller) reject
   store-signed packages and require a developer signature created
   by the currently set developer certificate, with the package
   staying within the certificate's bounds.
 * SystemDeveloper installs (via appman-controller) can sideload
   store-signed packages; a developer signature is always required.

The duplicated developer-certificate bounds checks are now in the
checkDeveloperCertificate() helper, which also reports a missing
certificate explicitly instead of failing the package-id match
against an empty certificate. The signer-binding check moved out of
the verification try block, so its errors are no longer re-wrapped
as verification failures.

The tests install dev-signed packages via the controller origin now
and a new test verifies the store signature requirement for System
UI installs.

Change-Id: I4c18ae36e72b7fa073b0ef62058aea855a332f6e
Fixes: QTBUG-149118
Reviewed-by: Thomas Senyk <[email protected]>
(cherry picked from commit 54375674bede168249620ffee2f2c5c715686c58)
Reviewed-by: Qt Cherry-pick Bot <[email protected]>
https://invent.kde.org/qt/qt/qtapplicationmanager/-/commit/a6d80c1ad057562ccccb18b864ce128b64262ed8

Git commit f81a5bfe94cdca20d0abdf5f2e79db0530c2b0a2 by Qt Cherry-pick Bot (on behalf of Robert Griebl) on 13/08/2026 at 14:51..
Doc: improve the taskFinished/taskFailed signals docs

Change-Id: I135f163906e21fd46d2fa9cb858b80a94e283202
Reviewed-by: Thomas Senyk <[email protected]>
(cherry picked from commit 2734d238fbf706a05afc267470488f4d55ee7d9a)
Reviewed-by: Qt Cherry-pick Bot <[email protected]>
https://invent.kde.org/qt/qt/qtapplicationmanager/-/commit/f81a5bfe94cdca20d0abdf5f2e79db0530c2b0a2

Git commit 60102008496b23dbd38210cdd0063c22b49a4ec5 by Qt Submodule Update Bot on 13/08/2026 at 15:51..
Update dependencies on '6.12' in qt/qtapplicationmanager

Change-Id: Iecf58035074e7f68e012ba1a7293c840b277f4d0
Reviewed-by: Qt Submodule Update Bot <[email protected]>
https://invent.kde.org/qt/qt/qtapplicationmanager/-/commit/60102008496b23dbd38210cdd0063c22b49a4ec5
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.