Page MenuHome GnuPG
Feed Advanced Search

Nov 30 2016

gniibe added a comment to T1686: GPG Smartcard daemons not detecting card change Windows 8.1.

Fixed in 2.1.11 and 2.0.30.

Nov 30 2016, 2:44 AM · gnupg, Windows 32, gnupg (gpg20), Windows, Bug Report
gniibe removed a project from T2698: Building static GnuPG fails with 2.1.15 (works with 2.1.14): Restricted Project.
Nov 30 2016, 2:42 AM · Bug Report, gnupg
gniibe closed T2698: Building static GnuPG fails with 2.1.15 (works with 2.1.14) as Resolved.
Nov 30 2016, 2:42 AM · Bug Report, gnupg
gniibe added a comment to T2698: Building static GnuPG fails with 2.1.15 (works with 2.1.14).

Fixed in 2.1.16.

Nov 30 2016, 2:42 AM · Bug Report, gnupg
gniibe closed T2651: scdaemon should free the reader after card removal as Resolved.
Nov 30 2016, 2:41 AM · Bug Report, gnupg, scd
gniibe added a comment to T2651: scdaemon should free the reader after card removal.

Fixed in 2.1.16. Will be in 2.0.31 as the fix is in the git repo already.

Nov 30 2016, 2:41 AM · Bug Report, gnupg, scd
gniibe removed a project from T2651: scdaemon should free the reader after card removal: Restricted Project.
Nov 30 2016, 2:41 AM · Bug Report, gnupg, scd
gniibe removed a project from T1779: AIX & GCC 4.7.4: 27 of 30 tests failed Please report to http://bugs.gnupg.org: Restricted Project.
Nov 30 2016, 2:38 AM · gnupg, Bug Report
gniibe added a comment to T1779: AIX & GCC 4.7.4: 27 of 30 tests failed Please report to http://bugs.gnupg.org.

Fixed with nPth 1.3.

Nov 30 2016, 2:38 AM · gnupg, Bug Report
gniibe closed T1779: AIX & GCC 4.7.4: 27 of 30 tests failed Please report to http://bugs.gnupg.org as Resolved.
Nov 30 2016, 2:38 AM · gnupg, Bug Report
gniibe removed a project from T2403: make check failed for t-stringhelp (AIX 7.1): Restricted Project.
Nov 30 2016, 2:36 AM · Bug Report, gnupg
gniibe added a comment to T2403: make check failed for t-stringhelp (AIX 7.1).

Fixed with nPth 1.3.

Nov 30 2016, 2:36 AM · Bug Report, gnupg
gniibe closed T2403: make check failed for t-stringhelp (AIX 7.1) as Resolved.
Nov 30 2016, 2:36 AM · Bug Report, gnupg
gniibe added a project to T2852: scdaemon + forwarded ssh agent: 100% reproducible crash: Restricted Project.
Nov 30 2016, 2:22 AM · Unreleased, gnupg (gpg20), Bug Report, gnupg
gniibe added a comment to T2852: scdaemon + forwarded ssh agent: 100% reproducible crash.

Fixed in STABLE-BRANCH-2-0 branch of git repo, as of the commit:
5c599e4f6edd288f4759c9fc2bcf9fe87dee1836

Nov 30 2016, 2:22 AM · Unreleased, gnupg (gpg20), Bug Report, gnupg

Nov 29 2016

werner added a comment to T2849: dirmngr fails to terminate on SIGTERM if an existing connection is open.

While looking at the problem I found a corner case related to a shutdown and
fixed that.

I also tried to close the listening socket after the first shutdown event. I
reverted that because the effect is that a client trying to connect immediately
gets a failure and then starts a new dirmngr - which is not the idea of a shutdown.

Nov 29 2016, 8:40 PM · Too Old, gnupg, Bug Report, dirmngr
werner added a project to T2849: dirmngr fails to terminate on SIGTERM if an existing connection is open: gnupg.
Nov 29 2016, 7:59 PM · Too Old, gnupg, Bug Report, dirmngr
werner added a comment to T2230: gpgsm decryption with smartcard fails with "Invalid session key".

Yeah, lets do that. Commit 8489b12 to go into 2.1.17. Thanks.

Nov 29 2016, 7:51 PM · Restricted Project, gnupg, scd, Bug Report, S/MIME
werner added a project to T2230: gpgsm decryption with smartcard fails with "Invalid session key": Restricted Project.
Nov 29 2016, 7:51 PM · Restricted Project, gnupg, scd, Bug Report, S/MIME
werner added a project to T2677: enable-special-filenames does not work with --output: Unreleased.
Nov 29 2016, 5:03 PM · Bug Report, gnupg
werner added a comment to T2677: enable-special-filenames does not work with --output.

commit a5910e00ace882b8a17169faf4607163ab454af9 should fix that. Will go into
2.1.17.

Nov 29 2016, 5:03 PM · Bug Report, gnupg
werner removed a project from T2677: enable-special-filenames does not work with --output: In Progress.
Nov 29 2016, 5:03 PM · Bug Report, gnupg
werner closed T2677: enable-special-filenames does not work with --output as Resolved.
Nov 29 2016, 5:03 PM · Bug Report, gnupg
lorenz added a comment to T2230: gpgsm decryption with smartcard fails with "Invalid session key".

What about putting in the suggested patch as an intermediate step towards a full
solution?

Nov 29 2016, 4:58 PM · Restricted Project, gnupg, scd, Bug Report, S/MIME
lorenz added a comment to T1854: Problems with same encryption and signing key on smartcard.

Anything I can do to help?

Nov 29 2016, 4:57 PM · gnupg, Feature Request, scd
justus added a comment to T2846: Regression: build needs -lintl for macOS.

Addressed in 9fb5e9c14557f7567cbc7c50b9881b7d7bfa2f12.

Is that sufficient?

Nov 29 2016, 4:05 PM · Bug Report, gnupg
justus added a project to T2846: Regression: build needs -lintl for macOS: Restricted Project.
Nov 29 2016, 4:05 PM · Bug Report, gnupg
aheinecke added a comment to T2812: TOFU very slow on Windows.

On Windows especially the initial keylist is very slow, subsequent keylists are
okish (less then 10 seconds) I don't think it's as big a problem anymore.
Listing a specific key is ~100ms. And that is with a large keyring (~18mb) on a
VM with a fairly slow harddisk.

For me this would be good enough to use tofu on windows. So it can be resolved
if you do not think the performance (especially of the initial listing) can be
improved or should have been better.

PS C:\Users\aheinecke> Measure-Command -Expression { gpg --no-auto-check-trustdb
--with-colons --trust-model tofu --list-keys --with-colons > $null }
gpg: NOTE: THIS IS A DEVELOPMENT VERSION!
gpg: It is only intended for test purposes and should NOT be
gpg: used in a production environment or with production keys!
gpg: please do a --check-trustdb
gpg: public key 60041E4EC03449C4 is 39 seconds newer than the signature
gpg: public key 60041E4EC03449C4 is 39 seconds newer than the signature

Days : 0
Hours : 0
Minutes : 1
Seconds : 14
Milliseconds : 785
Ticks : 747854659
TotalDays : 0.000865572521990741
TotalHours : 0.0207737405277778
TotalMinutes : 1.24642443166667
TotalSeconds : 74.7854659
TotalMilliseconds : 74785.4659

PS C:\Users\aheinecke> Measure-Command -Expression { gpg --no-auto-check-trustdb
--with-colons --trust-model tofu --list-keys --with-colons > $null }
gpg: NOTE: THIS IS A DEVELOPMENT VERSION!
gpg: It is only intended for test purposes and should NOT be
gpg: used in a production environment or with production keys!
gpg: please do a --check-trustdb
gpg: public key 60041E4EC03449C4 is 39 seconds newer than the signature

Days : 0
Hours : 0
Minutes : 0
Seconds : 7
Milliseconds : 812
Ticks : 78128420
TotalDays : 9.0426412037037E-05
TotalHours : 0.00217023388888889
TotalMinutes : 0.130214033333333
TotalSeconds : 7.812842
TotalMilliseconds : 7812.842

PS C:\Users\aheinecke> Measure-Command -Expression { gpg --no-auto-check-trustdb
--with-colons --trust-model pgp --list-keys --with-colons > $null }
gpg: NOTE: THIS IS A DEVELOPMENT VERSION!
gpg: It is only intended for test purposes and should NOT be
gpg: used in a production environment or with production keys!
gpg: public key 60041E4EC03449C4 is 39 seconds newer than the signature

Days : 0
Hours : 0
Minutes : 0
Seconds : 1
Milliseconds : 369
Ticks : 13697177
TotalDays : 1.58532141203704E-05
TotalHours : 0.000380477138888889
TotalMinutes : 0.0228286283333333
TotalSeconds : 1.3697177
TotalMilliseconds : 1369.7177

PS C:\Users\aheinecke> gpg --version
gpg (GnuPG) 2.1.17-beta30
libgcrypt 1.7.3

NOTE: THIS IS A DEVELOPMENT VERSION! It is only intended for test purposes and should NOT be used in a production environment or with production keys! Copyright (C) 2016 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later https://gnu.org/licenses/gpl.html This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law.

Home: C:/Users/aheinecke/AppData/Roaming/gnupg
Supported algorithms:
Pubkey: RSA, ELG, DSA, ECDH, ECDSA, EDDSA
Cipher: IDEA, 3DES, CAST5, BLOWFISH, AES, AES192, AES256, TWOFISH,

CAMELLIA128, CAMELLIA192, CAMELLIA256

Hash: SHA1, RIPEMD160, SHA256, SHA384, SHA512, SHA224
Compression: Uncompressed, ZIP, ZLIB, BZIP2

Nov 29 2016, 3:44 PM · Stalled, Bug Report, gnupg, Windows 32, TOFU, Windows
werner closed T2699: Assuan Context for inquiry callback not set if gpg-agent is just started as Resolved.
Nov 29 2016, 3:09 PM · Bug Report, gnupg
werner removed a project from T2699: Assuan Context for inquiry callback not set if gpg-agent is just started: Restricted Project.
Nov 29 2016, 3:09 PM · Bug Report, gnupg
werner closed T2702: ECDSA doesn't reject invalid digests when signing as Resolved.
Nov 29 2016, 3:09 PM · Bug Report, gnupg
werner added a comment to T2702: ECDSA doesn't reject invalid digests when signing.

Released with 2.1.16.

Nov 29 2016, 3:09 PM · Bug Report, gnupg
werner removed a project from T2702: ECDSA doesn't reject invalid digests when signing: Restricted Project.
Nov 29 2016, 3:09 PM · Bug Report, gnupg
werner closed T2756: gpg-agent auto-detection of socket removal doesn't trigger actual shutdown as Resolved.
Nov 29 2016, 3:07 PM · Bug Report, gnupg
werner added a comment to T2756: gpg-agent auto-detection of socket removal doesn't trigger actual shutdown.

all done.

Nov 29 2016, 3:07 PM · Bug Report, gnupg
werner removed a project from T2756: gpg-agent auto-detection of socket removal doesn't trigger actual shutdown: Restricted Project.
Nov 29 2016, 3:07 PM · Bug Report, gnupg
werner assigned T2846: Regression: build needs -lintl for macOS to justus.
Nov 29 2016, 3:02 PM · Bug Report, gnupg
werner updated subscribers of T2846: Regression: build needs -lintl for macOS.
Nov 29 2016, 3:02 PM · Bug Report, gnupg
werner added a comment to T2846: Regression: build needs -lintl for macOS.

Patrick also mentioned this on the ML. I am not sure whether this has been
fixed. Can you please check tools/Makefile.am and close this bug if -lintl has
not yet been added.

Nov 29 2016, 3:02 PM · Bug Report, gnupg
werner closed T2389: segfault after importing key, corrupting trustdb as Resolved.
Nov 29 2016, 2:59 PM · gnupg, MacOS, Bug Report
werner removed a project from T2389: segfault after importing key, corrupting trustdb: Restricted Project.
Nov 29 2016, 2:59 PM · gnupg, MacOS, Bug Report
werner added a comment to T2389: segfault after importing key, corrupting trustdb.

FWIW, we are running build tests now on macOS Sierra w/o problems.

Nov 29 2016, 2:59 PM · gnupg, MacOS, Bug Report
werner added a comment to T1448: gpgconf lists options which break gpg1 when gpg2 is also installed.

Sorry, I have not used those conf files suffixed for a long time.

Nov 29 2016, 2:28 PM · Not A Bug, Bug Report, gnupg
werner claimed T2857: gpg-agent crashes regularly, out of core in secure memory allocations.
Nov 29 2016, 2:26 PM · gnupg (gpg22), Bug Report, gnupg, gpgagent
werner added a comment to T2857: gpg-agent crashes regularly, out of core in secure memory allocations.

gpg-agent sets 32k aside for so called secure memory. It seems Libgcrypt runs
out of memory during computations with private key parameters.

Please put "debug memstat" into gpg-agent.conf which should print two lines of
info at process termination. If possible do the same with the old version and
compare.

Another thing you can do is to start gpg-agent ("gpgconf --launch gpg-agent"),
then look for its PID and attach gdb:

  $ gpg gpg-agent PID
  gdb> break log_fatal
  gdb> c

after you hit the breakpoint enter "bt".

Nov 29 2016, 2:26 PM · gnupg (gpg22), Bug Report, gnupg, gpgagent
justus renamed T2857: gpg-agent crashes regularly, out of core in secure memory allocations from gpg-agent crashes regularly to gpg-agent crashes regularly, out of core in secure memory allocations.
Nov 29 2016, 1:35 PM · gnupg (gpg22), Bug Report, gnupg, gpgagent
Pazuzu set Version to 2.1.16 on T2857: gpg-agent crashes regularly, out of core in secure memory allocations.
Nov 29 2016, 12:04 PM · gnupg (gpg22), Bug Report, gnupg, gpgagent
Pazuzu added projects to T2857: gpg-agent crashes regularly, out of core in secure memory allocations: gpgagent, gnupg, Bug Report.
Nov 29 2016, 12:04 PM · gnupg (gpg22), Bug Report, gnupg, gpgagent
werner set External Link to 846175@bugs.debian.org on T2856: Can't ssh-add a key w/o a passphrase.
Nov 29 2016, 10:40 AM · Debian, Bug Report, gnupg, ssh
werner set Version to 2.1.16 on T2856: Can't ssh-add a key w/o a passphrase.
Nov 29 2016, 10:40 AM · Debian, Bug Report, gnupg, ssh
werner added projects to T2856: Can't ssh-add a key w/o a passphrase: ssh, gnupg, Bug Report, Debian.
Nov 29 2016, 10:40 AM · Debian, Bug Report, gnupg, ssh
gniibe added a comment to T2852: scdaemon + forwarded ssh agent: 100% reproducible crash.

Thank you for your report.
In 2.1.x, I fixed scdaemon so that card removal works fine.
I'll backport to 2.0.

Nov 29 2016, 2:23 AM · Unreleased, gnupg (gpg20), Bug Report, gnupg
gniibe claimed T2852: scdaemon + forwarded ssh agent: 100% reproducible crash.
Nov 29 2016, 2:23 AM · Unreleased, gnupg (gpg20), Bug Report, gnupg

Nov 28 2016

justus added a comment to T2847: ssh.scm fails to import ecdsa key on macOS.

Also:

$ ssh -V
OpenSSH_7.2p2, LibreSSL 2.4.1

Nov 28 2016, 3:05 PM · MacOS, Bug Report, gnupg
justus updated subscribers of T2853: Signature Verification returning 'gpg: DBG: tofu.c:2772: strtoul failed for DB returned string (tail=): Invalid argument'.
Nov 28 2016, 2:36 PM · Bug Report, gnupg
justus assigned T2853: Signature Verification returning 'gpg: DBG: tofu.c:2772: strtoul failed for DB returned string (tail=): Invalid argument' to neal.
Nov 28 2016, 2:36 PM · Bug Report, gnupg
justus added a comment to T2425: 2.1.14 intermittent `make check` failure on gpgtar.scm.

Let's use T2425 for the tar failure, and T2847 for the ssh failure. The
log you posted here shows exactly the same problem as in T2847.

Do you also see tar failing?

You can use

make -Ctests/openpgp check XTESTS="gpgtar.scm gpgtar.scm gpgtar.scm gpgtar.scm
gpgtar.scm"

to run the same test over and over again. That is how I measured how often we
see the failure. We updated our box since, and I haven't tried it again yet.

Nov 28 2016, 2:33 PM · MacOS, gnupg, Bug Report, gnupg (gpg22)
justus renamed T2847: ssh.scm fails to import ecdsa key on macOS from New "make check" failures (particularly IPC) on macOS for gnupg 2.1.16 to ssh.scm fails to import ecdsa key on macOS.
Nov 28 2016, 2:27 PM · MacOS, Bug Report, gnupg
justus added a comment to T2847: ssh.scm fails to import ecdsa key on macOS.

Thanks for the report.

I changed the title to reflect what I learned from the log.

Our test runs fine, here a recent the log:

http://jenkins.gnupg.org/job/gnupg/501/XTARGET=native,label=macos/consoleFull

I don't know how to compare the OS versions, but this is what I see:

$ uname -a
Darwin ... 16.0.0 Darwin Kernel Version 16.0.0: Mon Aug 29 17:56:20 PDT 2016;
root:xnu-3789.1.32~3/RELEASE_X86_64 x86_64
$ shasum /usr/bin/ssh-add
bdb1005292b0891edba78b3f1f00fe036c4e60f9 /usr/bin/ssh-add

Could you please arrange the tests to be called using 'make check verbose=2',
and post
the generated ssh.scm.log file? For reference, here is our log:

http://jenkins.gnupg.org/job/gnupg/XTARGET=native,label=macos/ws/obj/tests/openpgp/ssh-import.scm.log/*view*/

(Note that I just renamed the test to 'ssh-import.scm'.)

Nov 28 2016, 2:27 PM · MacOS, Bug Report, gnupg
justus added a comment to T2848: gpg 2.1.16 throws an assertion failure when used with '--export-ssh-key'.

Fixed in 4db9a425644dccaf81b51ebc97b32a9cc21941a4.
Test for --export-ssh-key added in 47b8b9e2ce5af7fba117ae0b00e10bec414dcfb0.

Nov 28 2016, 1:54 PM · Bug Report, gnupg
justus closed T2848: gpg 2.1.16 throws an assertion failure when used with '--export-ssh-key' as Resolved.
Nov 28 2016, 1:54 PM · Bug Report, gnupg
justus added a project to T2848: gpg 2.1.16 throws an assertion failure when used with '--export-ssh-key': Unreleased.
Nov 28 2016, 1:54 PM · Bug Report, gnupg
justus reassigned T2848: gpg 2.1.16 throws an assertion failure when used with '--export-ssh-key' from justus to werner.
Nov 28 2016, 1:54 PM · Bug Report, gnupg
aheinecke added a comment to T1448: gpgconf lists options which break gpg1 when gpg2 is also installed.

Just for the record:
It's gpg.conf-1 or gpg.conf-2 and not gpg.conf.1

My workaround for this problem also was to have a gpg.conf-2 which is then used
by gpgconf and a gpg.conf that is used by gpg 1.

Nov 28 2016, 10:31 AM · Not A Bug, Bug Report, gnupg
werner added a project to T2850: auto-key-locate is annoying: gnupg (gpg23).
Nov 28 2016, 10:26 AM · gnupg (gpg23), gnupg, Feature Request
werner added a comment to T2850: auto-key-locate is annoying.

The major trouble we have here is that dirmngr is not abale to detect network
failures. This is due to ADNS which keeps on trying to send UDP packets for 30
sesonds desipte a ENETUNREACH. I tried with a patched ADNS versions and did
not anymore suffer from these problems.

However, when a keyserver is not answering in time, there is indeed a problem.
A problem we may be able so solve with queuing the requests after a short
timeout. gpg already tells dirmngr that it is prepared for such a "soft
failure" but we need to implement this in dirmngr.

The whole thing is not new (except for ADNS) and has been with us since the
introduction of --auto-key-locate and --auto-key-retrive. WHich is a LONG time ago.

Nov 28 2016, 10:25 AM · gnupg (gpg23), gnupg, Feature Request
werner removed a project from T2825: WKS: Encrypt submission / confirmation also with the users key: Unreleased.
Nov 28 2016, 10:20 AM · gnupg, Feature Request
werner closed T2842: npth_init called too late in gpg-agent? as Resolved.
Nov 28 2016, 10:19 AM · gnupg, npth, Bug Report
werner added a comment to T1448: gpgconf lists options which break gpg1 when gpg2 is also installed.

gpgconf, which is a gnupg 2 tool, can't work with gpg version 1. As soon as you
use options not available in gpg 1 you will run into problems for which there
may or may not be a workaround.

The easy workaround is to use gpg.conf.1 which will be used by gpg 1 instead of
gpg.conf.

Nov 28 2016, 10:19 AM · Not A Bug, Bug Report, gnupg
werner added a project to T1448: gpgconf lists options which break gpg1 when gpg2 is also installed: Not A Bug.
Nov 28 2016, 10:19 AM · Not A Bug, Bug Report, gnupg

Nov 25 2016

thomas reopened T1448: gpgconf lists options which break gpg1 when gpg2 is also installed as "Open".
Nov 25 2016, 12:18 PM · Not A Bug, Bug Report, gnupg
thomas added a comment to T1448: gpgconf lists options which break gpg1 when gpg2 is also installed.

Werner, you closed this issue with (the now removed) T1448 (wk on Jun 24 2014, 01:42 PM / Roundup) stating:
"You may use --ignore-invalid-option to list options which are only implemented
by gpg2."

This option seems only to be supported in gpg.conf, not on the command line.
(but this is no problem for me)

And it generally works fine (thank you!), just not in this special case here,
becaue gpg1 accepts the option "--debug-level" as valid, but does not allow
any arguments (neither numbers nor e.g. "basic").

The result (with "debug-level basic" in line 42) is:

$ gpg
gpg: /home/thomas/.gnupg/gpg.conf:42: argument not expected

I'm currently using gpg (GnuPG) 1.4.18 from Debian jessie.

As I understand it, "debug-level" is intended to just be a dummy option in
gpg1 to avoid problems with this option appearing in gpg.conf, correct?
So we have two possible solutions:

  • either remove option "debug-level" (and rely on "ignore-invalid-option debug-level")
  • or accept an argument for "debug-level"
Nov 25 2016, 12:18 PM · Not A Bug, Bug Report, gnupg

Nov 24 2016

mazhe reopened T2842: npth_init called too late in gpg-agent? as "Open".
Nov 24 2016, 4:21 PM · gnupg, npth, Bug Report
mazhe added a comment to T2842: npth_init called too late in gpg-agent?.

Indeed, I confirm that the newly updated version 2.1.16 fix this issue, thanks a
lot for doing this portability work!

Nov 24 2016, 4:21 PM · gnupg, npth, Bug Report
grempe added projects to T2853: Signature Verification returning 'gpg: DBG: tofu.c:2772: strtoul failed for DB returned string (tail=): Invalid argument': gnupg, Bug Report.
Nov 24 2016, 8:55 AM · Bug Report, gnupg
grempe added a comment to T2853: Signature Verification returning 'gpg: DBG: tofu.c:2772: strtoul failed for DB returned string (tail=): Invalid argument'.

Nov 24 2016, 8:55 AM · Bug Report, gnupg

Nov 23 2016

pbor added a comment to T2852: scdaemon + forwarded ssh agent: 100% reproducible crash.

The same problem reproduces with gnupg2 installed from Homebrew (w/o GPGTools patches).

Nov 23 2016, 6:56 PM · Unreleased, gnupg (gpg20), Bug Report, gnupg
pbor added projects to T2852: scdaemon + forwarded ssh agent: 100% reproducible crash: gnupg, Bug Report.
Nov 23 2016, 5:42 PM · Unreleased, gnupg (gpg20), Bug Report, gnupg
headsup added projects to T2851: redefinition of typedef 'rfc822parse_t': gnupg, Bug Report.
Nov 23 2016, 4:36 PM · Bug Report, gnupg
headsup set Version to 2.1.16 on T2851: redefinition of typedef 'rfc822parse_t'.
Nov 23 2016, 4:36 PM · Bug Report, gnupg
neal updated subscribers of T2850: auto-key-locate is annoying.
Nov 23 2016, 3:25 PM · gnupg (gpg23), gnupg, Feature Request
neal added projects to T2850: auto-key-locate is annoying: Feature Request, gnupg.
Nov 23 2016, 3:25 PM · gnupg (gpg23), gnupg, Feature Request
neal added a comment to T2812: TOFU very slow on Windows.

Fixed in 03a65a5. The time for doing a tofu --with-tofu-info --with-colons
listing is now similar to doing a pgp listing.

Please reopen if there are still unresolved issues.

$ time gpg2 --with-tofu-info --with-colons --no-auto-check-trustdb
--no-default-keyring --keyring /usr/share/keyrings/debian-keyring.gpg
--trust-model pgp -k >/dev/null
gpg: Note: signatures using the MD5 algorithm are rejected

real 0m1.972s
user 0m1.940s
sys 0m0.028s
$ time gpg2 --with-tofu-info --with-colons --no-auto-check-trustdb
--no-default-keyring --keyring /usr/share/keyrings/debian-keyring.gpg
--trust-model tofu -k >/dev/null
gpg: Note: signatures using the MD5 algorithm are rejected

real 0m2.252s
user 0m2.172s
sys 0m0.020s

Nov 23 2016, 12:32 PM · Stalled, Bug Report, gnupg, Windows 32, TOFU, Windows
neal added a project to T2812: TOFU very slow on Windows: Restricted Project.
Nov 23 2016, 12:32 PM · Stalled, Bug Report, gnupg, Windows 32, TOFU, Windows

Nov 22 2016

neal added a comment to T2815: TOFU conflict not part of GpgME's sigsum.

I suspect that the problem is the same as T2817.

Nov 22 2016, 5:46 PM · Stalled, Bug Report, gnupg, TOFU
neal added a comment to T2817: TOFU validity conflict not set on conflict.

Andre and I chatted about this issue offline, and I now understand what the
problem is. The TOFU_STATS status line (as documented in gnupg/doc/DETAILS) has
a "validity" field that is a number between 0 and 4 where 1 to 4 indicate how
confident we are that the binding is valid, and 0 means that the binding has an
unresolved conflict. The problem that Andre has observed is that this field is
not set to 0 if there is a conflict.

As a matter of fact, the validity field is never set to 0. This is completely
redundant as the same TOFU_STATS status line has a policy parameter, which is
"ask" if there is a conflict. Moreover, overloading this field in this way
causes a loss of information. Just because there is a conflict doesn't mean
that gpg shouldn't report the validity, or that the client can't made use of it.

Thus, in my opinion, the right thing to do is to simply use the <policy> field
to detect whether there is a conflict. Werner has suggested that this is wrong,
but I couldn't follow his logic. Thus, I'm adding him to the nosy list and I
hope he can clarify what he wants here.

Nov 22 2016, 5:33 PM · Restricted Project, Bug Report, gnupg, TOFU
neal updated subscribers of T2817: TOFU validity conflict not set on conflict.
Nov 22 2016, 5:33 PM · Restricted Project, Bug Report, gnupg, TOFU

Nov 20 2016

ilovezfs added a comment to T2425: 2.1.14 intermittent `make check` failure on gpgtar.scm.

The ssh.scm failure is still happening intermittently with 2.1.16

https://bot.brew.sh/job/Homebrew%20Versions%20Pull%20Requests/1733/version=yosemite/console

$ ssh -V
OpenSSH_6.2p2, OSSLShim 0.9.8r 8 Dec 2011

Nov 20 2016, 6:53 PM · MacOS, gnupg, Bug Report, gnupg (gpg22)
ilovezfs added a comment to T2847: ssh.scm fails to import ecdsa key on macOS.

Ah I spoke too soon. Just got the ssh.scm:
https://bot.brew.sh/job/Homebrew%20Versions%20Pull%20Requests/1733/version=yosemite/console

Nov 20 2016, 6:49 PM · MacOS, Bug Report, gnupg
ilovezfs added a comment to T2846: Regression: build needs -lintl for macOS.

No problem. Thanks for looking into it.

Nov 20 2016, 6:47 PM · Bug Report, gnupg
werner added a comment to T2846: Regression: build needs -lintl for macOS.

My fault. Sorry.

Nov 20 2016, 6:45 PM · Bug Report, gnupg
ilovezfs added a comment to T2847: ssh.scm fails to import ecdsa key on macOS.

Everything looks fine now that I removed all of the dependencies and started
from a blank slate. Sorry for the noise.

So far I'm not seeing the old "FAIL: gpgtar.scm" and "FAIL: ssh.scm"

Were those specifically fixed in some new commit(s), or am I just lucky so far?

Nov 20 2016, 6:32 PM · MacOS, Bug Report, gnupg
werner added a project to T2811: please compare the timestamps of secring.gpg and .gpg-v21-migrated and consider re-migration: Won't Fix.
Nov 20 2016, 5:23 PM · Won't Fix, Feature Request, gnupg
werner added a comment to T1805: gpg-agent: Wakes up periodically.

Note that gpg-agent has been changed years ago to make up at the full second so
that all daemons with a need to wakeup are running at the same time.

Nov 20 2016, 5:22 PM · Feature Request, gnupg
werner removed a project from T2832: "Invalid elliptic curve" when specifying wrong algo for gpg --quick-gen-key: Unreleased.
Nov 20 2016, 5:17 PM · Bug Report, gnupg
werner added a comment to T2842: npth_init called too late in gpg-agent?.

It has been confirmed that 2.1.16 solves the problem.

The reason for the crash is that 2.1.15 is calling gpgrt_set_syscall_clamp
before nPth is initialized. The nPth initialization was changed in 2.1.15 so to
solve problems on some other platforms.

Nov 20 2016, 5:17 PM · gnupg, npth, Bug Report
werner closed T2842: npth_init called too late in gpg-agent? as Resolved.
Nov 20 2016, 5:17 PM · gnupg, npth, Bug Report
werner assigned T2847: ssh.scm fails to import ecdsa key on macOS to justus.
Nov 20 2016, 5:12 PM · MacOS, Bug Report, gnupg
werner updated subscribers of T2847: ssh.scm fails to import ecdsa key on macOS.
Nov 20 2016, 5:12 PM · MacOS, Bug Report, gnupg
werner added a project to T2847: ssh.scm fails to import ecdsa key on macOS: MacOS.
Nov 20 2016, 5:12 PM · MacOS, Bug Report, gnupg