Re: [PATCH v1] gpg-interface: Signatures by expired keys are fine
- From
- Uwe Kleine-König <ukleinek@kernel.org>
- Date
- Feb 4, 2026, 21:18 UTC
- Message-ID
- <o2xni4463jlbmv226ngrlvepluqm43vg3fsifubanw6unhei77@wwzsa4ciqexw>
- In-Reply-To
- <xmqqjywspgi6.fsf@gitster.g>
Hello,
On Wed, Feb 04, 2026 at 09:26:09AM -0800, Junio C Hamano wrote:
Show 21 quoted lines
> Uwe Kleine-König <ukleinek@kernel.org> writes: > > > If a signature is done with a valid key and that key later expires, the > > signature should still be considered good. > > > > GnuPG exmits in this case something like: > > "emits". > > > diff --git a/gpg-interface.c b/gpg-interface.c > > index 47222bf31b6e..6635c6c8e16f 100644 > > --- a/gpg-interface.c > > +++ b/gpg-interface.c > > @@ -382,7 +382,7 @@ static int verify_gpg_signed_buffer(struct signature_check *sigc, > > > > delete_tempfile(&temp); > > > > - ret |= !strstr(gpg_stdout.buf, "\n[GNUPG:] GOODSIG "); > > + ret |= !strstr(gpg_stdout.buf, "\n[GNUPG:] GOODSIG ") && !strstr(gpg_stdout.buf, "\n[GNUPG:] EXPKEYSIG "); > > Makes sense; I'll wrap this overlong line while queuing, though.
Just to be sure: That means I don't resent with the typo fixed and an additional line break and you care to apply this patch?
Thanks Uwe