From: Junio C Hamano Date: Wed, 04 Feb 2026 17:26:09 GMT Subject: Re: [PATCH v1] gpg-interface: Signatures by expired keys are fine Message-ID: In-Reply-To: <20260204152306.1767112-2-ukleinek@kernel.org> Uwe Kleine-König writes: > If a signature is done with a valid key and that key later expires, the > signature should still be considered good. > > GnuPG exmits in this case something like: "emits". > diff --git a/gpg-interface.c b/gpg-interface.c > index 47222bf31b6e..6635c6c8e16f 100644 > --- a/gpg-interface.c > +++ b/gpg-interface.c > @@ -382,7 +382,7 @@ static int verify_gpg_signed_buffer(struct signature_check *sigc, > > delete_tempfile(&temp); > > - ret |= !strstr(gpg_stdout.buf, "\n[GNUPG:] GOODSIG "); > + ret |= !strstr(gpg_stdout.buf, "\n[GNUPG:] GOODSIG ") && !strstr(gpg_stdout.buf, "\n[GNUPG:] EXPKEYSIG "); Makes sense; I'll wrap this overlong line while queuing, though. > sigc->output = strbuf_detach(&gpg_stderr, NULL); > sigc->gpg_status = strbuf_detach(&gpg_stdout, NULL); > > @@ -680,7 +680,7 @@ int check_signature(struct signature_check *sigc, > if (status && !sigc->output) > return !!status; > > - status |= sigc->result != 'G'; > + status |= sigc->result != 'G' && sigc->result != 'Y'; > status |= sigc->trust_level < configured_min_trust_level; > > return !!status; > > base-commit: b2826b52eb7caff9f4ed6e85ec45e338bf02ad09