On Wed, Sep 23, 2026 at 09:10:13AM +0200, Marc Espie wrote:
> I'll have a closer look tonight hopefully, but the signature information
> is taken from the location, then passed into the installed
> packing-list through decorate (in PackageRepository/Installed.pm)
>
> The location info is done through uncompress, that does parse the gzip
> comment.
>
> Maybe IO::Uncompress::Gunzip changed recently and does not pass the
> full comment around ? that would be my best guess.
Found it.
naddy probably changed the process he uses to sign packages.
the method strips the path, but it's a simple file name now.
The following patch fixes both the recording of the signer from
the gzip header, and not erroring out for installed packages with
no signer annotation.
Index: OpenBSD/PackageRepository.pm
===================================================================
RCS file:
/build/data/openbsd/cvs/src/usr.sbin/pkg_add/OpenBSD/PackageRepository.pm,v
diff -u -p -r1.178 PackageRepository.pm
--- OpenBSD/PackageRepository.pm 1 Jun 2025 00:45:39 -0000 1.178
+++ OpenBSD/PackageRepository.pm 23 Sep 2026 17:39:20 -0000
@@ -406,8 +406,10 @@ sub uncompress($self, $object, @p)
my $h = $fh->getHeaderInfo;
if ($h) {
for my $line (split /\n/, $h->{Comment}) {
- if ($line =~ m/^key=.*\/(.*)\.sec$/) {
- $object->{signer} = $1;
+ if ($line =~ m/^key=(.*)\.sec$/) {
+ my $path = $1;
+ $path =~ s,.*/,,;
+ $object->{signer} = $path;
} elsif ($line =~ m/^date=(.*)$/) {
$object->{signdate} = $1;
}
Index: OpenBSD/PkgInfo.pm
===================================================================
RCS file: /build/data/openbsd/cvs/src/usr.sbin/pkg_add/OpenBSD/PkgInfo.pm,v
diff -u -p -r1.54 PkgInfo.pm
--- OpenBSD/PkgInfo.pm 25 Nov 2023 11:02:23 -0000 1.54
+++ OpenBSD/PkgInfo.pm 23 Sep 2026 17:39:20 -0000
@@ -430,8 +430,9 @@ sub print_info($self, $state, $pkg, $han
if ($plist->is_signed) {
my $sig = $plist->get('digital-signature');
if ($sig->{key} eq 'signify2') {
+ my $signer = $plist->get('signer');
$state->say("reportedly signed by #1",
- $plist->get('signer')->name);
+ $signer->name) if defined $signer;
} else {
$state->say("\@digital-signature #1: no
currently supported signature",
$sig->{key});