[pkg-gnupg-maint] Bug#831500: gnupg: Please declare that GnuPG 2.x breaks debsig-verify

Guillem Jover guillem at debian.org
Sat Jul 16 16:11:08 UTC 2016


Source: gnupg2
Source-Version: 2.1.14-1
Severity: normal

Hi!

The debsig-verify program parses gpg --list-packets output, but its
parser was not very lenient of different but valid input. With GnuPG
2.x which has started to output ‘#’ comments, the parser broke and it
would not be able to verify signed .deb packages, which I've fixed in
version 0.15.

So, even though this is a problem with debsig-verify and its old broken
parser, I cannot declare in any sane way that the old versions do not
work with the newer gnupg versions. But gnupg can declare that it
breaks debsig-verify older than 0.15, which would solve any partial
upgrade problems. So I'd appreciate if you could add to the gnupg 2.x
package something like:

  Breaks: debsig-verify (<< 0.15)

Thanks,
Guillem



More information about the pkg-gnupg-maint mailing list