Home GnuPG

Recent Activity
ActivePublic

Recent Activity

Today

thesamesam added a comment to T8094: libgcrypt: EC least leak failure.

I can reproduce it using Stuart's script from https://lists.gnupg.org/pipermail/gcrypt-devel/2026-February/006031.html.

Fri, Feb 13, 8:34 AM · Info Needed, libgcrypt, Bug Report
thesamesam added a comment to T8094: libgcrypt: EC least leak failure.
$ uname -a
Linux mop 6.18.10 #1 SMP PREEMPT_DYNAMIC Wed Feb 11 21:14:57 GMT 2026 x86_64 AMD Ryzen 9 3950X 16-Core Processor AuthenticAMD GNU/Linux
Fri, Feb 13, 8:22 AM · Info Needed, libgcrypt, Bug Report
mlaurent committed rMTP5c65c0bf86e5: GIT_SILENT: prepare 6.6.3 (authored by mlaurent).
GIT_SILENT: prepare 6.6.3
Fri, Feb 13, 8:21 AM
mlaurent committed rKLEOPATRA9adc1afa0258: GIT_SILENT: prepare 6.6.3 (authored by mlaurent).
GIT_SILENT: prepare 6.6.3
Fri, Feb 13, 8:20 AM
gniibe added a project to T8094: libgcrypt: EC least leak failure: Info Needed.

Please tell us the information of your environment.
What the versions of gpg and gpg-agent?

Fri, Feb 13, 8:13 AM · Info Needed, libgcrypt, Bug Report
gniibe renamed T8094: libgcrypt: EC least leak failure from libgcrypt: EC least leak failure on 32-bit machine to libgcrypt: EC least leak failure.
Fri, Feb 13, 8:10 AM · Info Needed, libgcrypt, Bug Report
gniibe added a comment to T7875: GnuPG: Deletion of kyber key fails.

Here is an attempt of mine this week:

diff --git a/g10/call-agent.c b/g10/call-agent.c
index 5e13a3e52..8949fad17 100644
--- a/g10/call-agent.c
+++ b/g10/call-agent.c
@@ -3290,13 +3290,14 @@ confirm_status_cb (void *opaque, const char *line)
    message.  If FORCE is true the agent is advised not to ask for
    confirmation. */
 gpg_error_t
-agent_delete_key (ctrl_t ctrl, const char *hexkeygrip, const char *desc,
+agent_delete_key (ctrl_t ctrl, const char *keygrip, const char *desc,
                   int force)
 {
   gpg_error_t err;
   char line[ASSUAN_LINELENGTH];
   struct default_inq_parm_s dfltparm;
   struct confirm_parm_s confirm_parm;
+  const char *keygrip2 = NULL;
Fri, Feb 13, 8:07 AM · Bug Report, PQC, gnupg26
thesamesam added a comment to T8094: libgcrypt: EC least leak failure.

We have seen the same thing on amd64 (x86_64) linux: https://bugs.gentoo.org/969501

Fri, Feb 13, 6:28 AM · Info Needed, libgcrypt, Bug Report

Yesterday

werner committed rGPA196faca458d6: Release 0.11.1 (authored by werner).
Release 0.11.1
Thu, Feb 12, 3:09 PM
werner committed rGPA780fd3940c73: Post release updates (authored by werner).
Post release updates
Thu, Feb 12, 3:09 PM
werner added a parent task for T8101: Upgrade of local (portable) installation failed: T8100: Kleopatra does not start on Windows Server 2016.
Thu, Feb 12, 1:18 PM · Bug Report, gpg4win
werner added a subtask for T8100: Kleopatra does not start on Windows Server 2016: T8101: Upgrade of local (portable) installation failed.
Thu, Feb 12, 1:18 PM · kleopatra, Bug Report, gpg4win, gpd5x, qt
werner added a comment to T8101: Upgrade of local (portable) installation failed.

Please do not use the portable installation - it is dangerous to use it. We will eventually remove this option.

Thu, Feb 12, 1:18 PM · Bug Report, gpg4win
werner committed rDe535913d916d: Add missing marker flag in previous commit (authored by werner).
Add missing marker flag in previous commit
Thu, Feb 12, 12:10 PM
werner added a comment to T8103: gpa: relase new version please.

I also updated the software page. Thanks for the hint.

Thu, Feb 12, 11:51 AM · gpa
werner committed rD606f291fb8fb: web: Update the GPA software page (authored by werner).
web: Update the GPA software page
Thu, Feb 12, 11:51 AM
werner committed rD06e9a11c51c1: swdb: gpa 0.11.1 (authored by werner).
swdb: gpa 0.11.1
Thu, Feb 12, 11:50 AM
svuorela committed rOJ5e2d459b40c7: Init gpgme (authored by svuorela).
Init gpgme
Thu, Feb 12, 11:44 AM
wiz added a comment to T8103: gpa: relase new version please.

That was fast, thank you.
Can you please update https://www.gnupg.org/related_software/gpa/ as well, or is there a better page to use as a homepage link for gpa?

Thu, Feb 12, 11:37 AM · gpa
werner closed T8103: gpa: relase new version please as Resolved.

Done. See T7449

Thu, Feb 12, 11:28 AM · gpa
werner added a comment to T7449: Release GPA 0.11.

Noteworthy changes in version 0.11.1 (2026-02-12)

Thu, Feb 12, 11:26 AM · Release Info, gpa
werner claimed T8103: gpa: relase new version please.
Thu, Feb 12, 11:16 AM · gpa
werner lowered the priority of T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT` from Unbreak Now! to Normal.
Thu, Feb 12, 11:14 AM · gnupg26, CVE, TPM, Bug Report
werner committed rGc0f9ca47f064: tools:gpg-authcode-sign.sh: Keep the log file on success. (authored by werner).
tools:gpg-authcode-sign.sh: Keep the log file on success.
Thu, Feb 12, 11:06 AM
ebo closed T7861: GpgOL: Autosecure + autoencryptUntrusted not working as expected in VSD versions as Invalid.

This ticket is now obsolete, as we will force the setting of autoencryptUntrusted=0 via the registry in Ticket T8090

Thu, Feb 12, 9:57 AM · vsd, gpgol
ebo updated the task description for T8090: Gpgolconfig: Grey out autoencryptUntrusted setting for VSD version.
Thu, Feb 12, 9:52 AM · vsd, vsd34, Installer, gpgol
ebo added a project to T8090: Gpgolconfig: Grey out autoencryptUntrusted setting for VSD version: vsd.
Thu, Feb 12, 9:47 AM · vsd, vsd34, Installer, gpgol
wiz created T8103: gpa: relase new version please.
Thu, Feb 12, 9:08 AM · gpa
gniibe committed rG6eed3959303c: agent: Fix the regression in pkdecrypt with TPM RSA. (authored by gniibe).
agent: Fix the regression in pkdecrypt with TPM RSA.
Thu, Feb 12, 4:05 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEObce4a586813e: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Thu, Feb 12, 2:51 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAf3ba6c3bb00c: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Thu, Feb 12, 2:50 AM
gniibe added a comment to T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT`.

The fix causes a regression. Reported: https://lists.gnupg.org/pipermail/gnupg-devel/2026-February/036218.html

Thu, Feb 12, 2:49 AM · gnupg26, CVE, TPM, Bug Report
gniibe reopened T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT` as "Open".

This is not 2.5-only.

Thu, Feb 12, 2:48 AM · gnupg26, CVE, TPM, Bug Report

Wed, Feb 11

tfry committed rOJ7f68ec183bcf: WIP (authored by tfry).
WIP
Wed, Feb 11, 4:46 PM
werner committed rG2dde9ddf56fe: dirmngr: Let KS_SEARCH print all uid records for a key. (authored by werner).
dirmngr: Let KS_SEARCH print all uid records for a key.
Wed, Feb 11, 4:32 PM
ebo added a comment to T8102: Kleopatra: Wrong message "no certificate found".

Maybe we could show instead the text "No keyserver is configured."? Need not be in the same place. This would also be helpful in the other case, where you go to the search via "Lookup on Server".

Wed, Feb 11, 4:23 PM · gpd5x, kleopatra
ebo triaged T8102: Kleopatra: Wrong message "no certificate found" as Low priority.
Wed, Feb 11, 4:22 PM · gpd5x, kleopatra
ikloecker claimed T6568: Kleopatra: make table column headings accessible.
Wed, Feb 11, 3:00 PM · vsd34, gpd5x, a11y, kleopatra
ikloecker changed the status of T6568: Kleopatra: make table column headings accessible, a subtask of T5824: Kleopatra: Full accessibility support, from Testing to Open.
Wed, Feb 11, 2:58 PM · a11y, kleopatra
ikloecker changed the status of T6568: Kleopatra: make table column headings accessible from Testing to Open.

Make all table column headings accessible (see Update 2025-10-27).

Wed, Feb 11, 2:58 PM · vsd34, gpd5x, a11y, kleopatra
ebo moved T7538: Kleopatra: Do only ask for confirmation twice when deleting a secret key from Done to WIP on the gpd5x board.
Wed, Feb 11, 2:28 PM · gpd5x, kleopatra
ebo edited projects for T7538: Kleopatra: Do only ask for confirmation twice when deleting a secret key, added: gpd5x; removed gpd5x (gpd-5.0.0).
Wed, Feb 11, 2:27 PM · gpd5x, kleopatra
ebo reopened T7538: Kleopatra: Do only ask for confirmation twice when deleting a secret key as "Testing".

Forget my comment above. Or consider it as the "before" part of the task description…

Wed, Feb 11, 2:27 PM · gpd5x, kleopatra
ikloecker changed the status of T8098: Kleopatra: Omit question about own key when importing a secret team key from Open to Testing.
Wed, Feb 11, 2:05 PM · vsd34, gpd5x, kleopatra
ikloecker moved T8098: Kleopatra: Omit question about own key when importing a secret team key from Backlog to WIP on the vsd34 board.

Fixed and backported for VSD 3.4.

Wed, Feb 11, 2:05 PM · vsd34, gpd5x, kleopatra
ikloecker renamed T8100: Kleopatra does not start on Windows Server 2016 from QT: SetThreadDescription not found in Qt6Core.dll to Kleopatra does not start on Windows Server 2016.
Wed, Feb 11, 12:06 PM · kleopatra, Bug Report, gpg4win, gpd5x, qt
ikloecker committed rKLEOPATRAec79933401fa: Don't ask about "only user" when importing a shared secret team key (authored by ikloecker).
Don't ask about "only user" when importing a shared secret team key
Wed, Feb 11, 12:04 PM
pmgdeb added a comment to T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.

Hi, the test is green with rG86baca6e62b3 for both 2038-01-01 and 2105-01-01. Thanks!

Wed, Feb 11, 11:19 AM · Bug Report
ikloecker claimed T8098: Kleopatra: Omit question about own key when importing a secret team key.
Wed, Feb 11, 11:01 AM · vsd34, gpd5x, kleopatra
ikloecker changed the status of T8056: Support config options RSAKeySizes and PGPKeyType for Kf6 from Open to Testing.

The settings should work again. They are described at https://docs.kde.org/trunk_kf6/en/kleopatra/kleopatra/admin.html#admin-certificate-request-wizard-keys , but note that the documentation is severely outdated. Note that those settings are not officially supported by GnuPG (VS-)Desktop (see https://gnupg.com/vsd/kleopatra-settings.html).

Wed, Feb 11, 10:51 AM · gpd5x, kleopatra
tfry committed rOJ7d33d36d907d: Rename manifest.po to avoid potential name clash (authored by tfry).
Rename manifest.po to avoid potential name clash
Wed, Feb 11, 10:43 AM
ikloecker committed rW05631bc0dd97: qtbase: Make it work on Windows Server 2016 (authored by ikloecker).
qtbase: Make it work on Windows Server 2016
Wed, Feb 11, 10:26 AM
ikloecker changed the status of T8100: Kleopatra does not start on Windows Server 2016 from Open to Testing.

Should work now.

Wed, Feb 11, 10:26 AM · kleopatra, Bug Report, gpg4win, gpd5x, qt
ebo triaged T8100: Kleopatra does not start on Windows Server 2016 as Normal priority.
Wed, Feb 11, 9:52 AM · kleopatra, Bug Report, gpg4win, gpd5x, qt
ikloecker claimed T8100: Kleopatra does not start on Windows Server 2016.
Wed, Feb 11, 9:49 AM · kleopatra, Bug Report, gpg4win, gpd5x, qt
ikloecker added a comment to T8100: Kleopatra does not start on Windows Server 2016.

This was fixed in Qt 6.10.0 by adding compatibility code that's "hidden" behind a compiler flag, i.e. we just need to enable this compiler flag. See https://codereview.qt-project.org/c/qt/qtbase/+/629255 for details.

Wed, Feb 11, 9:49 AM · kleopatra, Bug Report, gpg4win, gpd5x, qt
uwi added a comment to T8101: Upgrade of local (portable) installation failed.

For the time being I "upgraded 5.0.1 to 4.4.1 (in the new directory), and then Kleopatra started again.
When upgrading that installation again to 5.0.1, Kleopatra does not start (same error message as before).

Wed, Feb 11, 9:03 AM · Bug Report, gpg4win
uwi added a comment to T8101: Upgrade of local (portable) installation failed.

Also: When I click "Abort" ("Abbrechen"), the dialog disappeared, but the main windows does not show any progress: Specifically it does not abort.
I had to press "Abort" ("Abbrechen") in the main window; then the upgrade aborted.
When retrying (and confirming that I don't want to install as Administrator (actually I cannot), the proposed target directory still is "C:\Program Files\Gpg4win".
When locating the previous installation directory (it seems it was a subdirectory of %USERPROFIL%\Downloads) the upgrade succeeded, but Kleopatra fails to start.
It want a bin\Qt6Core.dll, bit in the bin directory there is only a Qt5Corew.dll dated " 14. ‎Juli ‎2023, ‏‎13:23:40".
When retrying the installation/upgrade it announced to upgrade 5.0.1, but then did seemingly nothing (I guess as the version was estimated to "be current").
It seems some "reinstall/repair" option is missing.

Wed, Feb 11, 8:54 AM · Bug Report, gpg4win
tfry committed rOJ6a405eceb6bf: Localize manifest strings while generating the manifest (authored by tfry).
Localize manifest strings while generating the manifest
Wed, Feb 11, 8:39 AM
uwi created T8101: Upgrade of local (portable) installation failed.
Wed, Feb 11, 8:31 AM · Bug Report, gpg4win
l10n daemon script <scripty@kde.org> committed rLIBKLEO47ca63d019eb: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Wed, Feb 11, 4:18 AM
gniibe added a comment to T8094: libgcrypt: EC least leak failure.

No, OpenBSD's implementation of POSIX semaphore is different to NetBSD.
(It doesn't support PSHARED=1.)

Wed, Feb 11, 2:51 AM · Info Needed, libgcrypt, Bug Report
l10n daemon script <scripty@kde.org> committed rLIBKLEO440b85a6f92e: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Feb 11, 2:49 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA6fa3b37b80a1: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Feb 11, 2:49 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO96873e309146: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Wed, Feb 11, 2:41 AM
gniibe added a comment to T8094: libgcrypt: EC least leak failure.

Possibly, it is related to the NetBSD failure of T8065.
If importing the secret key fails (which invokes gpg-agent), decryption cannot be succeeded.
I will check OpenBSD implementation of POSIX semaphore, if it's similar to NetBSD one.

Wed, Feb 11, 2:41 AM · Info Needed, libgcrypt, Bug Report

Tue, Feb 10

ikloecker added a comment to T8099: Kleopatra: no default OpenPGP server configured.

We forgot to update the tooltip when the default keyserver was removed in gpg 2.5.3. This has already been fixed in the meantime. Sorry for the inconvenience!

Tue, Feb 10, 10:43 PM · Bug Report, gpg4win
ikloecker committed rKLEOPATRAb9fa02ba2216: Use extended helper to get compliant algorithms for CMS (authored by ikloecker).
Use extended helper to get compliant algorithms for CMS
Tue, Feb 10, 5:22 PM
ikloecker committed rLIBKLEO5e47a7ef6ce2: Bump library version (authored by ikloecker).
Bump library version
Tue, Feb 10, 5:17 PM
ikloecker committed rLIBKLEOa6c8962a9e1a: Re-add support for legacy settings PGPKeyType and RSAKeySizes (authored by ikloecker).
Re-add support for legacy settings PGPKeyType and RSAKeySizes
Tue, Feb 10, 5:17 PM
ikloecker committed rLIBKLEO2e1867d75546: Add support for CMS to algorithm helpers (authored by ikloecker).
Add support for CMS to algorithm helpers
Tue, Feb 10, 5:17 PM
ebo created T8100: Kleopatra does not start on Windows Server 2016.
Tue, Feb 10, 4:18 PM · kleopatra, Bug Report, gpg4win, gpd5x, qt
werner committed rG86baca6e62b3: gpgscm: New operator "*long-time-t?" to detect proper time_t systems. (authored by werner).
gpgscm: New operator "*long-time-t?" to detect proper time_t systems.
Tue, Feb 10, 3:40 PM
tfry committed rOJe61d386c0e4d: Do not activate window for RMB click on icon (authored by tfry).
Do not activate window for RMB click on icon
Tue, Feb 10, 3:17 PM
ebo closed T8097: AppImage ships Kleopatra icon in two different variants as Resolved.

Fixed for KF6 versions.

Tue, Feb 10, 3:11 PM · AppImage, Installer, kleopatra
ebo set Version to vsd 3.3.4 on T8097: AppImage ships Kleopatra icon in two different variants.
Tue, Feb 10, 3:11 PM · AppImage, Installer, kleopatra
ikloecker added a comment to T8097: AppImage ships Kleopatra icon in two different variants.

I'm pretty sure that this has already been fixed with the changes made for T8083: Kleopatra: Use blue icon for Gpg4win and GPD. build-appimage.sh now always replaces the Breeze icons shipped with the AppImage with the appropriate head icon.

Tue, Feb 10, 2:41 PM · AppImage, Installer, kleopatra
OliverL created T8099: Kleopatra: no default OpenPGP server configured.
Tue, Feb 10, 1:20 PM · Bug Report, gpg4win
werner triaged T8084: ctype(3) API use as Low priority.
Tue, Feb 10, 11:50 AM · NetBSD, gnupg, Bug Report
werner added a comment to T8097: AppImage ships Kleopatra icon in two different variants.

Won't fix for vsd3x

Tue, Feb 10, 11:50 AM · AppImage, Installer, kleopatra
werner triaged T8097: AppImage ships Kleopatra icon in two different variants as Normal priority.
Tue, Feb 10, 11:49 AM · AppImage, Installer, kleopatra
ebo moved T2227: Sign GpgOL to support group deployments from Backlog to Done on the gpgol board.
Tue, Feb 10, 11:48 AM · gpgol, Feature Request
ebo closed T5807: Extend Authenticode signatures to more (all) Gpg4win binaries and libraries as Resolved.

Meanwhile all executables are signed.

Tue, Feb 10, 11:48 AM · Feature Request, gpg4win
werner committed rW33707dbc0eab: Update libpng to 1.6.55 to due CVE-2026-25646. (authored by werner).
Update libpng to 1.6.55 to due CVE-2026-25646.
Tue, Feb 10, 11:46 AM
werner committed rWc739b47d05eb: msi: Yet another Perl syntax fix. (authored by werner).
msi: Yet another Perl syntax fix.
Tue, Feb 10, 11:33 AM
ebo triaged T8098: Kleopatra: Omit question about own key when importing a secret team key as Normal priority.
Tue, Feb 10, 11:00 AM · vsd34, gpd5x, kleopatra
ikloecker created T8098: Kleopatra: Omit question about own key when importing a secret team key.
Tue, Feb 10, 10:57 AM · vsd34, gpd5x, kleopatra
werner triaged T8094: libgcrypt: EC least leak failure as Low priority.

According to the ML @gniibe tried to replicate the problem without success.

Tue, Feb 10, 10:53 AM · Info Needed, libgcrypt, Bug Report
l10n daemon script <scripty@kde.org> committed rLIBKLEO6adacdb8cabf: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Tue, Feb 10, 2:48 AM
gniibe added a comment to T8066: gpgrt: Static linking support.

Investigating GNU ld, I learned that there is no easy way (~= no way) to suppress the warnings (other than 2>/dev/null). It was implemented by the special section named gnu.warning.SYM where SYM is a symbol. I think that this is not-so-good for glibc to notify its users about possible static link problem, by gnu.warning.SYM.

Tue, Feb 10, 2:42 AM · Linux, Feature Request, gpgrt

Mon, Feb 9

ikloecker added a comment to T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.

I guess the test fails because one cannot create a key with an expiration date before the current date. And the test tries to create a key which expires on 2038-01-01 which will fail if the test is run on 2038-01-01 or later. The easiest fix would be to disable the test cases if the current date is past 2038-01-01.

Mon, Feb 9, 7:36 PM · Bug Report
ikloecker changed the status of T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038 from Open to Testing.

Okay, then I set the ticket to Testing.

Mon, Feb 9, 7:24 PM · S/MIME, Bug Report, vsd34, kleopatra
pmgdeb added a comment to T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.

Unfortunately, this was run on x86_64 and also other 64 bit archs.

Mon, Feb 9, 4:16 PM · Bug Report
werner added a comment to T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.

Is that on a 32 bit machine or 64? The latter would be a problem for 32 bit with 32 bit time-t I'd say: we won't fix it.

Mon, Feb 9, 4:15 PM · Bug Report
tfry committed rOJ575c6ed275ee: Localize tooltip string while generating the manifest (authored by tfry).
Localize tooltip string while generating the manifest
Mon, Feb 9, 3:47 PM
werner added a comment to T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked.

At least for an expired data signature I would suggest to have an info button to further expliah this. Maybe to a FAQ or KB article. The case is too rare that we should not discuss endlessly the pros and cons of expiring signatures. I hope that Kleo does not provide an option to crerate such a signature.

Mon, Feb 9, 3:30 PM · Bug Report, gpd5x, kleopatra
tfry created T8097: AppImage ships Kleopatra icon in two different variants.
Mon, Feb 9, 3:17 PM · AppImage, Installer, kleopatra
pmgdeb created T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.
Mon, Feb 9, 12:21 PM · Bug Report
tfry committed rOJ57c3796b85a8: Also save drafts in new common path (authored by tfry).
Also save drafts in new common path
Mon, Feb 9, 12:02 PM
tfry committed rOJc5bb528f7987: Explicitly share certain paths between client and server (authored by tfry).
Explicitly share certain paths between client and server
Mon, Feb 9, 12:02 PM

Panel Used By

Event Timeline

Mitzie209 renamed this panel from to Recent Activity.Oct 6 2020, 2:19 PM
Mitzie209 edited an edge.