Page MenuHome GnuPG
Feed Advanced Search

Apr 20 2023

werner moved T6455: Bug in regexp library may lead to out-of-bounds read from QA to gnupg-2.2.42 on the gnupg22 board.
Apr 20 2023, 12:30 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Bug Report
werner moved T6455: Bug in regexp library may lead to out-of-bounds read from QA to gnupg-2.4.1 on the gnupg24 board.
Apr 20 2023, 12:29 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Bug Report
werner moved T6455: Bug in regexp library may lead to out-of-bounds read from Backlog to QA on the gnupg24 board.
Apr 20 2023, 12:29 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Bug Report
werner closed T6455: Bug in regexp library may lead to out-of-bounds read as Resolved.

Okay, that was easy to check.

Apr 20 2023, 12:29 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Bug Report
werner committed rG3ad4b339b886: common: Fix minor bug in the jimregexp code. (authored by werner).
common: Fix minor bug in the jimregexp code.
Apr 20 2023, 12:28 PM
werner committed rGa82e6f310a03: common: Fix minor bug in the jimregexp code. (authored by werner).
common: Fix minor bug in the jimregexp code.
Apr 20 2023, 12:28 PM
werner claimed T6455: Bug in regexp library may lead to out-of-bounds read.
Apr 20 2023, 12:17 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Bug Report
werner changed the status of T6462: gpg --edit-card does not display openpgp info on connected card from Open to Testing.

Not easy to fix because gpg --card-edit/-status has some support form other cards. Eventually these commands will be replaced by gpg-card. In the meantime we can use this hack:

Apr 20 2023, 12:14 PM · gnupg24 (gnupg-2.4.1), scd, Restricted Project
werner committed rGe1663c045049: gpg: New command "openpgp" for --card-edit. (authored by werner).
gpg: New command "openpgp" for --card-edit.
Apr 20 2023, 12:12 PM
werner triaged T6459: KOrganizer: Invitations are not signed with GPG although signing is enabled by default as Normal priority.
Apr 20 2023, 9:03 AM · Restricted Project, KDE
werner triaged T6460: KOrganizer: unable to display events with the same UID in multiple calendars as Normal priority.
Apr 20 2023, 9:02 AM · Restricted Project, KDE
werner triaged T6461: KOrganizer: Remote ICS file doesn't populate calendar as Normal priority.
Apr 20 2023, 9:02 AM · Restricted Project, KDE
werner triaged T6457: delete-secret-key does not delete all secret keys, when primary secret key is stripped in keyring as Normal priority.
Apr 20 2023, 9:01 AM · gnupg24, Feature Request

Apr 19 2023

werner committed rW742f50c7b2e2: More g4wihelp fixes for newer Unicode mingw API. (authored by werner).
More g4wihelp fixes for newer Unicode mingw API.
Apr 19 2023, 6:00 PM
werner committed rG80d4ae121565: Use keyboxd on a fresh install also on Windows. (authored by werner).
Use keyboxd on a fresh install also on Windows.
Apr 19 2023, 11:06 AM

Apr 18 2023

werner assigned T6455: Bug in regexp library may lead to out-of-bounds read to gniibe.

@gniibe, will you be so kind an check the provided patches

Apr 18 2023, 5:12 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Bug Report
werner triaged T6455: Bug in regexp library may lead to out-of-bounds read as High priority.
Apr 18 2023, 5:11 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Bug Report
werner added a comment to T6378: keytocard: invalid value.

To replicate the problem it is best to use Windows. Should be solved with my commit. Note that the bug is specific to 2.4 dues to irts multi-card and app support. There was no problem on 2.2.

Apr 18 2023, 5:09 PM · gnupg24 (gnupg-2.4.1), gnupg22 (gnupg-2.2.42), Bug Report, Restricted Project
werner committed rGfa4f716917e5: gpg: Make sure that we are not accidently working with the PIV app. (authored by werner).
gpg: Make sure that we are not accidently working with the PIV app.
Apr 18 2023, 5:07 PM
werner committed rGf7e00dc73dd0: scd: On a Yubikey re-select the last app after the use of APDU. (authored by werner).
scd: On a Yubikey re-select the last app after the use of APDU.
Apr 18 2023, 12:05 PM
werner moved T6212: The ssh keys are no longer returned in the order from control file after T5996 from QA to gnupg-2.4.1 on the gnupg24 board.
Apr 18 2023, 9:42 AM · gnupg24 (gnupg-2.4.1), ssh, Feature Request
werner moved T6437: Kleopatra: sign/encrypt folder results in general error from Backlog to QA for next release on the gpgme board.
Apr 18 2023, 9:20 AM · gpgme (gpgme 1.23.x), Bug Report, Restricted Project
werner edited projects for T6437: Kleopatra: sign/encrypt folder results in general error, added: gpgme, Bug Report; removed gnupg24, gnupg22.

The actual error is in gpgme. CreateProcess is called with "gpgtar" but "gpgtar.exe" must be used.
This has been fixed with commit rM0c29119e061c. The reason why we didn't noticed the real cause of the problem is that the CreateProcess error shows up in the gpgme-w32spawn helper which has no good way for returning errors.

Apr 18 2023, 9:20 AM · gpgme (gpgme 1.23.x), Bug Report, Restricted Project
werner committed rG98b8c518fa0b: ssh: Allow to prefer on-disk keys over active card keys. (authored by werner).
ssh: Allow to prefer on-disk keys over active card keys.
Apr 18 2023, 9:04 AM
werner triaged T6454: Release GnuPG 2.4.1 as Normal priority.
Apr 18 2023, 8:54 AM · gnupg24 (gnupg-2.4.1), Release Info
werner committed rGba67fea5b9bb: gpgtar: Read common.conf for the log-file option. (authored by werner).
gpgtar: Read common.conf for the log-file option.
Apr 18 2023, 8:07 AM

Apr 17 2023

werner committed rM7d1159c1e99b: core: Avoid printf format warnings due to gpgme_ssize_t. (authored by werner).
core: Avoid printf format warnings due to gpgme_ssize_t.
Apr 17 2023, 4:17 PM
werner committed rM0c29119e061c: core,w32: Fix invocation of gpgtar (authored by werner).
core,w32: Fix invocation of gpgtar
Apr 17 2023, 4:17 PM
werner added a comment to T6451: libgcrypt | gcry_cipher_setkey: 3DES-CBC key returns GPG_ERR_WEAK even with GCRYCTL_SET_ALLOW_WEAK_KEY.

Reading the commit rC5beadf201312: Add gcry_cipher_ctl command to allow weak keys in testing use-cases,
The test code in basic.c assumes that it is an application responsibility to confirm&ignore GPG_ERR_WEAK_KEY error when using GCRYCTL_SET_ALLOW_WEAK_KEY.

Apr 17 2023, 1:25 PM · Debian, libgcrypt, Bug Report
werner added a member for g10code: dvratil.
Apr 17 2023, 11:40 AM
werner added a member for Contributor: dvratil.
Apr 17 2023, 11:37 AM
werner committed rD81a281183ff9: Eliminare denoting (authored by olf).
Eliminare denoting
Apr 17 2023, 8:27 AM

Apr 16 2023

werner committed rC30840c2c45d7: cipher: Fix edge case for SET_ALLOW_WEAK_KEY. (authored by werner).
cipher: Fix edge case for SET_ALLOW_WEAK_KEY.
Apr 16 2023, 8:57 PM
werner triaged T6449: Support fetching S/MIME certificates over DNS via SMIMEA record as Wishlist priority.
Apr 16 2023, 8:34 PM · Feature Request, dirmngr
werner triaged T6451: libgcrypt | gcry_cipher_setkey: 3DES-CBC key returns GPG_ERR_WEAK even with GCRYCTL_SET_ALLOW_WEAK_KEY as Low priority.

Thanks for the report. Fix is easy. I only wonder why you want to use a weak DES key.

Apr 16 2023, 8:31 PM · Debian, libgcrypt, Bug Report

Apr 13 2023

werner added a comment to T6437: Kleopatra: sign/encrypt folder results in general error.

On Windows we always use --status-fd=1 but with gpg it is not a problem because we use a differenrt fd for output.

Apr 13 2023, 10:58 AM · gpgme (gpgme 1.23.x), Bug Report, Restricted Project
werner committed rE770a01e6dc52: Update autogen.sh to better support gpg4win (authored by werner).
Update autogen.sh to better support gpg4win
Apr 13 2023, 10:07 AM

Apr 12 2023

werner committed rGd965ee8d65f9: gpg: Curvenames may now compared case insensitive. (authored by werner).
gpg: Curvenames may now compared case insensitive.
Apr 12 2023, 5:32 PM
werner moved T6378: keytocard: invalid value from WiP to QA on the gnupg24 board.

Unfortunately I can't replicate that with my Yubikey on 2.4.1. Tried several variant and with and without keyboxd. My Yubikey has PIV disabled but I doubt that this is the problem.

Apr 12 2023, 5:15 PM · gnupg24 (gnupg-2.4.1), gnupg22 (gnupg-2.2.42), Bug Report, Restricted Project
werner claimed T6378: keytocard: invalid value.
Apr 12 2023, 2:43 PM · gnupg24 (gnupg-2.4.1), gnupg22 (gnupg-2.2.42), Bug Report, Restricted Project
werner added a comment to T6442: libgcrypt-1.10.2: getrandom() is not available everywhere.

Actually Linux already returns ENOSYS on older kernels where there is no getrandom libc call. Thus returning ENOSYS if we don't have the libc version of that syscall (i.e. getrandom) in FIPS mode seems to be the Right Thing to do. My whole comment was about fips mode - it does not make much sense to enable FIPS mode if the system is not appropriate for it.

Apr 12 2023, 8:58 AM · MacOS, libgcrypt, Bug Report
werner triaged T6445: Chunking armored messages and pubkeys? as Low priority.
Apr 12 2023, 8:45 AM · OpenPGP, Feature Request
werner triaged T6447: Kleopatra: "imported certificates" tab inconsistencies as Normal priority.
Apr 12 2023, 8:44 AM · vsd33 (vsd-3.3.0), Restricted Project, Bug Report, kleopatra

Apr 11 2023

werner committed rW5e041722c145: Partly rewrote gen-html.sh (authored by werner).
Partly rewrote gen-html.sh
Apr 11 2023, 5:30 PM
werner committed rW0fc432694c83: Fix gen-gnupg.sh output for wixlib files. (authored by werner).
Fix gen-gnupg.sh output for wixlib files.
Apr 11 2023, 4:48 PM
werner committed rWde7e54ffa9bd: Use the standard autogen.sh. (authored by werner).
Use the standard autogen.sh.
Apr 11 2023, 4:06 PM
werner committed rW296768f0d62f: Fix gen-gnupg.sh for gpg4win (authored by werner).
Fix gen-gnupg.sh for gpg4win
Apr 11 2023, 10:02 AM
werner committed rW17a4414b9aad: Add patch for gpgme 1.19.0 (authored by werner).
Add patch for gpgme 1.19.0
Apr 11 2023, 9:20 AM
werner committed rW3de962e582e3: Update libgpg-error and Libgcrypt (authored by werner).
Update libgpg-error and Libgcrypt
Apr 11 2023, 9:08 AM
werner committed rW24b28a0e4b6e: Temporary disable the RunOnce check (authored by werner).
Temporary disable the RunOnce check
Apr 11 2023, 9:08 AM
werner added a comment to T6442: libgcrypt-1.10.2: getrandom() is not available everywhere.

What about

Apr 11 2023, 8:19 AM · MacOS, libgcrypt, Bug Report
werner added a comment to T6445: Chunking armored messages and pubkeys?.

Indeed, this is not implemented. AFAIK, this feature was introduced by PGP 2 to support BBS systems. I would suggest that you use binary messages and implement the chunking at the application level.

Apr 11 2023, 8:14 AM · OpenPGP, Feature Request

Apr 7 2023

werner triaged T6442: libgcrypt-1.10.2: getrandom() is not available everywhere as High priority.
Apr 7 2023, 10:02 PM · MacOS, libgcrypt, Bug Report

Apr 6 2023

werner committed rD6d0e1bb0b09f: swdb: Libgcrypt 1.10.2 (authored by werner).
swdb: Libgcrypt 1.10.2
Apr 6 2023, 9:15 PM
werner committed rD1bf5d5912744: swdb: Gpgrt 1.47 (authored by werner).
swdb: Gpgrt 1.47
Apr 6 2023, 11:39 AM
werner closed T6231: Release Libgpg-error 1.47 as Resolved.
Apr 6 2023, 10:45 AM · Release Info, gpgrt
werner committed rE4b9baa8f58a7: Post release updates (authored by werner).
Post release updates
Apr 6 2023, 10:37 AM
werner committed rE6604887a7e96: po: Auto update (authored by werner).
po: Auto update
Apr 6 2023, 10:37 AM
werner committed rEa25cea92798a: Release 1.47 (authored by werner).
Release 1.47
Apr 6 2023, 10:37 AM
werner committed rEbcc16b4cd00f: build: Make distcheck work again (authored by werner).
build: Make distcheck work again
Apr 6 2023, 10:37 AM
werner committed rE0262cd3371cf: core: New error codes for PUKs and reset codes. (authored by werner).
core: New error codes for PUKs and reset codes.
Apr 6 2023, 10:37 AM
werner triaged T6441: Release libgpg-error 1.48 as Low priority.
Apr 6 2023, 10:34 AM · gpgrt, Release Info
werner committed rG3013137f744f: po: Fix in German translation (authored by ebo).
po: Fix in German translation
Apr 6 2023, 10:31 AM
werner committed rGd9a4517d62ad: po: Fix in German translation (authored by ebo).
po: Fix in German translation
Apr 6 2023, 10:30 AM
werner added a comment to T6421: Improve error message if no reset code (PUK) is set.

I'll add new error codes to gpgrt

Apr 6 2023, 10:05 AM · gnupg26, Feature Request, gpgrt
werner committed rGb349ceedfca2: gpg: Take care not to encrypt with OCB in de-vs mode (authored by werner).
gpg: Take care not to encrypt with OCB in de-vs mode
Apr 6 2023, 9:21 AM
werner triaged T6440: GpgME also need to find gpgconf under "/opt/homebrew/bin" by default as Normal priority.

You could configure gpgme with

Apr 6 2023, 9:12 AM · MacOS, Feature Request, gpgme

Apr 5 2023

werner committed rGc9e95b8dee05: gpg: New option --assert-signer. (authored by werner).
gpg: New option --assert-signer.
Apr 5 2023, 9:33 PM
werner committed rG42ccbd6c78e6: speedo,w32: Remove removed profiles and temporary disable runonce. (authored by werner).
speedo,w32: Remove removed profiles and temporary disable runonce.
Apr 5 2023, 3:04 PM
werner changed the status of T6363: Add progress status output to gpgtar from Open to Testing.
Apr 5 2023, 12:11 PM · gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Feature Request
werner moved T6280: Release GnuPG 2.2.41 from WiP to Attic on the gnupg22 board.
Apr 5 2023, 12:08 PM · gnupg22, Release Info
werner moved T6355: gpgtar: Does not allow decryption from stdin from QA to gnupg-2.2.42 on the gnupg22 board.
Apr 5 2023, 11:58 AM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Restricted Project
werner closed T6355: gpgtar: Does not allow decryption from stdin as Resolved.
Apr 5 2023, 11:38 AM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Restricted Project
werner closed T6355: gpgtar: Does not allow decryption from stdin, a subtask of T6342: GPGME/Kleopatra: Extend gpgme to use gpgtar, as Resolved.
Apr 5 2023, 11:38 AM · Restricted Project, gpgme, kleopatra

Apr 4 2023

werner committed rGd261f5e5d0d5: common: Change allocation of the comopt symbol. (authored by werner).
common: Change allocation of the comopt symbol.
Apr 4 2023, 5:06 PM
werner triaged T6438: Manual of gpgrt is missing on gnupg.org as Normal priority.

Any volunteers to write a manual? ;-)

Apr 4 2023, 4:45 PM · Documentation, Feature Request, gpgrt
werner committed rGd9e7488b17fd: Use the keyboxd for a fresh install (authored by werner).
Use the keyboxd for a fresh install
Apr 4 2023, 4:42 PM
werner committed rGdb6ae6f6f851: speedo: Remove deleted prf files from the Windows installer (authored by werner).
speedo: Remove deleted prf files from the Windows installer
Apr 4 2023, 1:11 PM
werner committed rGfcbb849c26e9: speedo: Fix regression due to switching from gcc 8.3 to 10.2 (authored by werner).
speedo: Fix regression due to switching from gcc 8.3 to 10.2
Apr 4 2023, 10:26 AM
werner moved T6378: keytocard: invalid value from QA to gnupg-2.2.42 on the gnupg22 board.
Apr 4 2023, 10:18 AM · gnupg24 (gnupg-2.4.1), gnupg22 (gnupg-2.2.42), Bug Report, Restricted Project
werner committed rG7bf57a794b77: gpg: Set the default digest algo for S2K to SHA256. (authored by werner).
gpg: Set the default digest algo for S2K to SHA256.
Apr 4 2023, 9:21 AM
werner triaged T6433: SHA-1 digest is not considered weak as Low priority.

No, it would break the verification of too many signatures.

Apr 4 2023, 8:53 AM · Bug Report
werner committed rG56d309133f0e: dirmngr: Return modifyTimestamp and add server option --newer. (authored by werner).
dirmngr: Return modifyTimestamp and add server option --newer.
Apr 4 2023, 8:51 AM

Apr 3 2023

werner moved T6332: GPG: Extend / rework "is_file_compressed" from QA to gnupg-2.4.1 on the gnupg24 board.
Apr 3 2023, 2:33 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Restricted Project
werner moved T6395: ADSK Feature from QA to gnupg-2.4.1 on the gnupg24 board.
Apr 3 2023, 2:33 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), OpenPGP
werner placed T3054: dirmngr only using cAcertificate attr type when querying LDAP directory up for grabs.
Apr 3 2023, 2:29 PM · Active Directory, dirmngr
werner closed T3054: dirmngr only using cAcertificate attr type when querying LDAP directory as Resolved.

After diligently reading the code I realized that this bug has long been fixed. For reference here is the patch I wrote to extend dirmngr_ldap during my tests:

Apr 3 2023, 2:28 PM · Active Directory, dirmngr
werner closed T5079: Add compliance flag to trustlist.txt as Resolved.

The flag has been implemented in 2.4 but as long as this version has no approval it does not make sense to do anything more. Let's re-open this task if we have a real request for this.

Apr 3 2023, 2:16 PM · gnupg22 (gnupg-2.2.45), gnupg24 (gnupg-2.4.1), Restricted Project, Feature Request
werner committed rGa5360ae4c7bf: agent: Add trustlist flag "de-vs". (authored by werner).
agent: Add trustlist flag "de-vs".
Apr 3 2023, 2:12 PM
werner claimed T5079: Add compliance flag to trustlist.txt.
Apr 3 2023, 1:51 PM · gnupg22 (gnupg-2.2.45), gnupg24 (gnupg-2.4.1), Restricted Project, Feature Request
werner lowered the priority of T5555: Cannot add existing ECDSA key as a signing subkey from High to Normal.
Apr 3 2023, 1:46 PM · gnupg24, Bug Report
werner removed a project from T5555: Cannot add existing ECDSA key as a signing subkey: gnupg (gpg23).
Apr 3 2023, 1:43 PM · gnupg24, Bug Report
werner claimed T6307: Release GnuPG 2.2.42.
Apr 3 2023, 1:14 PM · gnupg22 (gnupg-2.2.42), Release Info
werner created gnupg22 (gnupg-2.2.42).
Apr 3 2023, 1:07 PM
werner moved T6355: gpgtar: Does not allow decryption from stdin from QA to gnupg-2.4.1 on the gnupg24 board.
Apr 3 2023, 1:05 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Restricted Project
werner moved T6355: gpgtar: Does not allow decryption from stdin from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Apr 3 2023, 12:58 PM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), Restricted Project
werner committed rG8996b0b65595: gpgsm: Create binary detached sigs with definite form length octets. (authored by werner).
gpgsm: Create binary detached sigs with definite form length octets.
Apr 3 2023, 12:10 PM
werner committed rG4b9346492e3f: gpgsm: Remove conditional compilation for older libksba versions. (authored by werner).
gpgsm: Remove conditional compilation for older libksba versions.
Apr 3 2023, 12:10 PM
werner committed rC3660935d2d50: doc: Add remark that leading zeroes are stripped from printed MPIs. (authored by werner).
doc: Add remark that leading zeroes are stripped from printed MPIs.
Apr 3 2023, 10:23 AM
werner closed T6435: libgcrypt | gcry_mpi_ec_mul return a truncated point coordinate as Resolved.

I added a remark to the print function. Thanks for the suggestion.

Apr 3 2023, 10:22 AM · Debian, libgcrypt, Bug Report