[Rpm-maint] [rpm-software-management/rpm] Document rpmkeys output and the overall verify policy in some detail (PR #4170)

Panu Matilainen notifications at github.com
Thu Apr 2 06:27:30 UTC 2026


@pmatilai commented on this pull request.



>      ...
 ```
 
+	The output is on the level of individual verifiables.
+
+	Range describes the area which the verifiable covers. Possible
+	values are:
+	- *Header*: The main header of the package
+	- *Payload*: The payload of the package
+	- *Legacy*: The main header and the payload of the package
+
+	Description includes general information about this verifiable,
+	such the algorithm name and OpenPGP version of a signature.

I pondered about the enumeration order too. Thing is, the OpenPGP version exists only in signatures, so the actual majority of the output does start with an algorithm name of the hash algo. And even with signatures it's after the "OpenPGP" text, and only there if it's actually present, but not in NOTFOUND lines. Which is not to say I disagree.

I'm kinda torn on this whole thing: I'd rather not go into the details of what the string contains *at all* but then might well be easier to just to explain the actual format :smile: 

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/pull/4170?email_source=notifications&email_token=ADLPZU2VRTOAJIYTPVNFD5L4TYB5FA5CNFSNUABKM5UWIORPF5TWS5BNNB2WEL2QOVWGYUTFOF2WK43UKJSXM2LFO4XTIMBUHA3DENRVGYYKM4TFMFZW63VKON2WE43DOJUWEZLEUVSXMZLOOS6XA4S7OJSXM2LFO5PW433UNFTGSY3BORUW63TTL5RWY2LDNM#discussion_r3026156242
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/pull/4170/review/4048626560 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20260401/6a923161/attachment-0001.htm>


More information about the Rpm-maint mailing list