On Wed, 2026-08-26 at 16:55:48 +0200, Matthias Urlichs wrote:
> On 26.08.26 14:23, Lionel Élie Mamane wrote:
> > gpg: WARNING: unsafe permissions on homedir 
> > '/srv/vote.debian.org/data/gr_llm'
> > gpg: packet(2) with unknown version 5
> > gpg: no signature found
> > gpg: the signature could not be verified.
> > [GNUPG:] NODATA 3[GNUPG:] NODATA 4
> 
> Bah. Don't we all hate the gnupg-vs-sq protocol version split …

If by that you mean the gnupg-vs-openpgp schism, where OpenPGP (RFC9580)
implies at least Sequoia-PGP, GOpenPGP, OpenPGP.js, rPGP, Bouncy Castle,
PGPainless, hOpenPGP, minipgp6, rnp, etc.

And where gnupg implementing LibrePGP implies support mainly (AFAIR)
from GnuPG and rnp. Then…

> I wonder what would be involved in teaching sq to at least verify
> gnupg's v5 packets. Seems like an ideal task for an AI [SCNR].

…this seems entirely the wrong takeaway. More so when GnuPG already has
now a branch to support OpenPGP proper. And also when it looks to me like
the error above comes from GnuPG itself and not the Sequoia Chameleon.

(dpkg also tries to detect and warn on LibrePGP artifacts to avoid making
the ecosystem situation worse, and will eventually just reject them.)

Regards,
Guillem

Reply via email to