On Wednesday, 31 December 2025 at 04:35, Eli Schwartz <[email protected]> wrote:
> Hi,
>
>
> If the Exherbo Linux distribution lacks enough manpower</snip> >
You were NOT a Gentoo developer back when Gentoo initialy started
using manifests, as some of us were, so you can NOT possibly know.
Yet, you had to take the time on a precious new year's day to pay
me your respects by formulating two completely non-technical answers.
Haters gonna hate?..
I have respect to this list and I wouldn't reply if this was the
only thing I had to say but the feedback otherwise has been great.
I've learned from David Runge on Mastodon[1] that Arch Linux people
are working on this project called voa[2] that can unify package
artifact signing across distributions. I've also learned this project
is kindly funded by STF. Voa supports GPG atm but they are open to
adding support for minisign, signify and friends. I intend to work together
with them to add signify support as a start. I deeply hope we can use this
solution for Exherbo Linux too.
Meanwhile, I did a bit of work and released 0.1.1. Now I am fairly sure
it does the same thing as OpenBSD signify does. Is that the right thing?
That's of course open for debate. I have also added AFL++ fuzzing
which I intend to leave running for a week or three[3]. Next goal is
to port to WASM, below is the changelog[4] for 0.1.1[5]:
- Write unit tests, property based tests, and AFL++ fuzz tests to ensure
code correctness.
- Compile keyrings(7) support by default on Linux and Android, and remove
the keyring feature.
- Port OpenBSD regression tests and fix issues related to CLI option
parsing spotted by them.
- Use a 1KB buffer rather than 4KB for password input which is consistent
with OpenBSD.
Enjoy.
> --
> Eli Schwartz
Please Eli, take this moment to make a new start. It does not have to be like
this.
I hate what happened in the history as much as you do. Let's refuse to feed this
hate further. Do not drink your own poison and hope me to die. Happy new year.
[1]: https://chaos.social/@dvzrv/115819220124450391
[2]: https://voa.archlinux.page/
[3]: inb4 we crack ed25519 :P
[4]: https://git.sr.ht/~alip/signify/tree/main/item/ChangeLog.md
[5]: https://crates.io/crates/signify-rs/0.1.1
Best regards,
Ali Polatel
publickey - [email protected] - 0xC22DA9DE.asc
Description: application/pgp-keys
signature.asc
Description: OpenPGP digital signature
