git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v1] gpg-interface: Signatures by expired keys are fine

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 4, 2026, 17:26 UTC
Message-ID
<xmqqjywspgi6.fsf@gitster.g>
In-Reply-To
<20260204152306.1767112-2-ukleinek@kernel.org>
Uwe Kleine-König <ukleinek@kernel.org> writes:
> If a signature is done with a valid key and that key later expires, the
> signature should still be considered good.
>
> GnuPG exmits in this case something like:
"emits".
Show 10 quoted lines
> diff --git a/gpg-interface.c b/gpg-interface.c
> index 47222bf31b6e..6635c6c8e16f 100644
> --- a/gpg-interface.c
> +++ b/gpg-interface.c
> @@ -382,7 +382,7 @@ static int verify_gpg_signed_buffer(struct signature_check *sigc,
>  
>  	delete_tempfile(&temp);
>  
> -	ret |= !strstr(gpg_stdout.buf, "\n[GNUPG:] GOODSIG ");
> +	ret |= !strstr(gpg_stdout.buf, "\n[GNUPG:] GOODSIG ") && !strstr(gpg_stdout.buf, "\n[GNUPG:] EXPKEYSIG ");
Makes sense; I'll wrap this overlong line while queuing, though.
Show 14 quoted lines
>  	sigc->output = strbuf_detach(&gpg_stderr, NULL);
>  	sigc->gpg_status = strbuf_detach(&gpg_stdout, NULL);
>  
> @@ -680,7 +680,7 @@ int check_signature(struct signature_check *sigc,
>  	if (status && !sigc->output)
>  		return !!status;
>  
> -	status |= sigc->result != 'G';
> +	status |= sigc->result != 'G' && sigc->result != 'Y';
>  	status |= sigc->trust_level < configured_min_trust_level;
>  
>  	return !!status;
>
> base-commit: b2826b52eb7caff9f4ed6e85ec45e338bf02ad09
Previous: Neal H. WalfieldNext: Uwe Kleine-König
Message 3 of 6 in “gpg-interface: Signatures by expired keys are fine”
  1. gpg-interface: Signatures by expired keys are fineUwe Kleine-König, Feb 4, 2026
  2. Neal H. WalfieldFeb 4, 2026
  3. Junio C HamanoFeb 4, 2026
  4. Uwe Kleine-KönigFeb 4, 2026
  5. Junio C HamanoFeb 4, 2026
  6. Uwe Kleine-KönigFeb 5, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.