Re: reduce/simplify the maintenance of sec-keys packages

Sam James <[email protected]> Tue, 16 Jun 2026 20:25:55 +0100
Newsgroups gmane.linux.gentoo.devel
Organization Gentoo
Message-ID <[email protected]>
Hank Leininger <[email protected]> writes:

> On 2026-06-16, Agostino Sarubbo wrote:
>> I have not analyzed whether this is technically possible, but I am
>> wondering whether it would make sense to create a dedicated Git
>> repository on GitWeb, store all keys there, and have a single ebuild
>> that installs all of them.
>
> I p-m a few packages, have added sec-keys for some and would like to do
> so for more over time.
>
> Adding a key and adding/updating a package ebuild to add verify-sig
> support referencing that key is doable in multiple commits in a single
> PR, so it's atomic from the perspective of ::gentoo users.
>
> Sometimes a project changes key and we need old-key in-tree for PV 1.2.3
> and new-key for PV 1.2.4.

Right, there's also some complications there with how the current setup
would allow us to SLOT the key package if we needed to, while the new
setup would possibly make that harder (or at least unclear how a key
would be renamed and what the mapping would be).

>
> Both of those sound like they might be made harder, not easier, by your
> proposal?
>
> Thanks,
signature.asc (application/pgp-signature, 418 B)
-----BEGIN PGP SIGNATURE-----

iQEBBAEWCgCpFiEEJaa7iN2bdkxrVUHCc4QJ9SDfkZAFAmoxo0QbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25z
Lm9wZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQyNUE2QkI4OEREOUI3NjRDNkI1NTQx
QzI3Mzg0MDlGNTIwREY5MTkwDxxzYW1AZ2VudG9vLm9yZwAKCRBzhAn1IN+RkKVY
AP4+wGpJd7rAC0uB/kNQkuqCYFnbd0lfZT5z0B01hkORFQD/TToDrHF6t0WCfxF4
niB16skVj7z4L7xIXhLG+Anwvgg=
=sB4k
-----END PGP SIGNATURE-----