[Rpm-maint] [rpm-software-management/rpm] Document rpmkeys output and the overall verify policy in some detail (PR #4170)

Panu Matilainen notifications at github.com
Thu Apr 9 11:08:37 UTC 2026


@pmatilai commented on this pull request.



>      ...
 ```
 
+	The output is on the level of individual verifiables.
+
+	Range describes the area which the verifiable covers. Possible
+	values are:
+	- *Header*: The main header of the package
+	- *Payload*: The payload of the package
+	- *Legacy*: The main header and the payload of the package
+
+	Description includes general information about this verifiable,
+	such the algorithm name and OpenPGP version of a signature.
+
+	*ALT* indicates the verifiable is an optional alternative to another
+	verifiable.
+
+	Class is one of *digest* or *signature*.

Moved the disclaimer about the verbose format being unstable and for diagnostics only to the start of the `--checksig --verbose` section and bolded the `Note` part. It wont prevent people from parsing the output, but at least we can point them here: "we told you so".

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/pull/4170#discussion_r3057332918
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/pull/4170/review/4081754357 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20260409/fc41a0ff/attachment.htm>


More information about the Rpm-maint mailing list