[Rpm-maint] [rpm-software-management/rpm] Document rpmkeys output and the overall verify policy in some detail (PR #4170)
Panu Matilainen
notifications at github.com
Wed Apr 8 11:05:22 UTC 2026
@pmatilai commented on this pull request.
> ...
```
+ The output is on the level of individual verifiables.
+
+ Range describes the area which the verifiable covers. Possible
+ values are:
+ - *Header*: The main header of the package
+ - *Payload*: The payload of the package
+ - *Legacy*: The main header and the payload of the package
+
+ Description includes general information about this verifiable,
+ such the algorithm name and OpenPGP version of a signature.
There's the "Note that the verbose mode output is intended for diagnostic purposes only, and details may vary between releases" disclaimer, but I doubt anybody actually reads them. And the caveat that the final result is not actually printed at all in this mode.
OTOH having written it down, it seems kinda crazy there hasn't been any documentation as to what all that stuff *means*.
--
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/pull/4170#discussion_r3050900367
You are receiving this because you are subscribed to this thread.
Message ID: <rpm-software-management/rpm/pull/4170/review/4074639556 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20260408/83706e83/attachment.htm>
More information about the Rpm-maint
mailing list