Bug#1110172: Keys in a user's trustedkeys.gpg keyring are ignored when extracting a source package

Martin-Éric Racine <[email protected]>
Newsgroups gmane.linux.debian.devel.dpkg.bugs
Message-ID <176596607551.35820.13087708243897429316.reportbug__3938.52482536516$1765966198$gmane$org@p8h61.internal>
Package: dpkg-dev
Version: 1.23.0
Followup-For: Bug #1110172
X-Debbugs-Cc: [email protected]

At least 1.23.0 now tells us which keyrings it tried, in order. Thanks for that.

However, no longer checking the user's own keyring really is a regression. This needs to be fixed. IMHO, a good implementation would be to first check the global keyrings (which it already does) then check the user's own keyring as a last resort (which was removed for no good reason).

Martin-Éric

-- System Information:
Debian Release: forky/sid
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'unstable')
Architecture: i386 (x86_64)

Kernel: Linux 6.12.57+deb13-amd64 (SMP w/8 CPU threads; PREEMPT)
Locale: LANG=fi_FI.UTF-8, LC_CTYPE=fi_FI.UTF-8 (charmap=UTF-8), LANGUAGE=fi:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages dpkg-dev depends on:
ii  binutils      2.45.50.20251209-1
ii  bzip2         1.0.8-6
ii  libdpkg-perl  1.23.0
ii  make          4.4.1-3
ii  patch         2.8-2
ii  perl          5.40.1-7
ii  tar           1.35+dfsg-3.1
ii  xz-utils      5.8.1-2

Versions of packages dpkg-dev recommends:
ii  build-essential          12.12
ii  fakeroot                 1.37.1.2-1
ii  gcc [c-compiler]         4:15.2.0-4
ii  gcc-15 [c-compiler]      15.2.0-11
ii  gnupg                    2.4.8-4
ii  gpgv                     2.4.8-4+b1
ii  libalgorithm-merge-perl  0.08-5
ii  sq                       1.3.1-5
ii  sqv                      1.3.0-5

Versions of packages dpkg-dev suggests:
pn  debian-keyring             <none>
ii  debian-tag2upload-keyring  1.1

-- no debconf information
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.