Page MenuHome GnuPG
Feed All Stories

May 19 2025

werner closed T7647: cipher/simd-common-riscv.h missing from libgcrypt 1.11.1 tarball as Resolved.

Problem noted in T7166

May 19 2025, 12:16 PM · riscv, libgcrypt, Bug Report
werner added a comment to T7166: Release Libgcrypt 1.11.1.

Noet that one file is missing in the released tarball; when building for RISC-V please see T7647#201164

May 19 2025, 12:15 PM · Release Info, libgcrypt
werner added a comment to T7647: cipher/simd-common-riscv.h missing from libgcrypt 1.11.1 tarball.

Patch applied.

May 19 2025, 12:12 PM · riscv, libgcrypt, Bug Report
ebo moved T6584: Kleopatra / Gpgtar: Cancel on encrypt leaves a broken archive behind from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · vsd32 (vsd-3.2.0), Restricted Project, kleopatra
ebo moved T6793: Cleanup temporary files / dirs with decrypted content from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · gpd5x, vsd32 (vsd-3.2.0), kleopatra
ebo moved T6907: gpgme: Explicitly tell gpg that we want to verify signed data from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · gpgme, Restricted Project
ebo moved T6917: Kleopatra: write error when decrypting to network drive from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · vsd32 (vsd-3.2.0), Restricted Project, kleopatra
ebo moved T6926: No tray icon for Kleopatra in dark mode on Windows. from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · Restricted Project, Bug Report, Windows, kleopatra
ebo moved T6095: Kleopatra: Fix accessibility of group configuration from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · kleopatra, Restricted Project
ebo moved T7021: Kleopatra: restart gpg-agent after stopping it from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · vsd32 (vsd-3.2.0), kleopatra, Restricted Project
ebo moved T7051: Kleopatra: Defunct processes when Kleopatra is running with elevated privileges from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · vsd32 (vsd-3.2.0), kleopatra, Restricted Project
ebo moved T6688: Kleopatra GPGME: Reported assert on exit from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · gpd5x, gpgme, kleopatra
ebo moved T7045: Kleopatra: Use "SCD DEVINFO --watch" also on Windows from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · gpd5x, kleopatra
ebo moved T7204: Kleopatra: Remove Option "Show tags attached to certificates" from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · vsd33 (vsd-3.3.0), kleopatra, Restricted Project
ebo moved T7272: Kleopatra: Look up missing OpenPGP certificates for card keys from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · LDAP, gpd5x, kleopatra
ebo moved T7297: Kleopatra: Improve support for V5 fingerprints from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · gpd5x, kleopatra
ebo moved T7489: Kleopatra: missing translations in kf5 from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · vsd33 (vsd-3.3.0), Restricted Project, kleopatra
ebo moved T7525: gpg4win: Add support for Wayland to the Qt5-based AppImage from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · Restricted Project, gpg4win
gniibe committed rGd1c3bfda2a8c: gpg: Use the KEM API for ECC encryption. (authored by gniibe).
gpg: Use the KEM API for ECC encryption.
May 19 2025, 8:01 AM
gniibe added a comment to T7640: ML-DSA for libgcrypt.

Looking the FIPS 204 document, using the following functions (API) is good:

May 19 2025, 7:47 AM · PQC, libgcrypt
l10n daemon script <scripty@kde.org> committed rKLEOPATRAfd43796728bc: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 19 2025, 3:43 AM
gniibe renamed T7649: gnupg: Use KEM interface for encryption/decryption from gnupg: Use KEM interface for decryption to gnupg: Use KEM interface for encryption/decryption.
May 19 2025, 2:35 AM · gnupg26

May 18 2025

l10n daemon script <scripty@kde.org> committed rKLEOPATRA675cff6e38fe: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 18 2025, 5:20 AM
l10n daemon script <scripty@kde.org> committed rMTPb5b9105072d9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 18 2025, 3:44 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA30eabd76f72b: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 18 2025, 3:42 AM

May 17 2025

collinfunk added a comment to T7647: cipher/simd-common-riscv.h missing from libgcrypt 1.11.1 tarball.

I can confirm this. Here is the build error:

make[2]: Entering directory '/home/collinfunk/libgcrypt-1.11.1/cipher'
`echo /bin/bash ../libtool  --tag=CC   --mode=compile gcc -DHAVE_CONFIG_H -I. -I..  -I../src -I../src -I../mpi -I../mpi  -I/home/collinfunk/tmp/include -g -O2 -fvisibility=hidden -fno-delete-null-pointer-checks -Wall -O2 -march=rv64imafdcv -mstrict-align -c rijndael-vp-riscv.c | sed -e 's/-fsanitize[=,\-][=,a-z,A-Z,0-9,\,,\-]*//g' -e 's/-fprofile[=,\-][=,a-z,A-Z,0-9,\,,\-]*//g' -e 's/-fcoverage[=,\-][=,a-z,A-Z,0-9,\,,\-]*//g' `
libtool: compile:  gcc -DHAVE_CONFIG_H -I. -I.. -I../src -I../src -I../mpi -I../mpi -I/home/collinfunk/tmp/include -g -O2 -fvisibility=hidden -fno-delete-null-pointer-checks -Wall -O2 -march=rv64imafdcv -mstrict-align -c rijndael-vp-riscv.c  -fPIC -DPIC -o .libs/rijndael-vp-riscv.o
rijndael-vp-riscv.c:58:10: fatal error: simd-common-riscv.h: No such file or directory
   58 | #include "simd-common-riscv.h"
      |          ^~~~~~~~~~~~~~~~~~~~~
compilation terminated.
make[2]: *** [Makefile:1730: rijndael-vp-riscv.lo] Error 1

Patch here: https://lists.gnupg.org/pipermail/gcrypt-devel/2025-May/005854.html

May 17 2025, 6:13 AM · riscv, libgcrypt, Bug Report
l10n daemon script <scripty@kde.org> committed rMTP7f65aae26576: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 17 2025, 5:16 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAeff566397e25: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 17 2025, 5:16 AM
l10n daemon script <scripty@kde.org> committed rMTP034f08709d92: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 17 2025, 3:43 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA62058f59ad60: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 17 2025, 3:41 AM

May 16 2025

timegrid updated the task description for T7658: Okular: Dirmngr startup timeout on signature validation.
May 16 2025, 4:30 PM · Bug Report, gpd5x, okular
timegrid updated the task description for T7658: Okular: Dirmngr startup timeout on signature validation.
May 16 2025, 4:27 PM · Bug Report, gpd5x, okular
dkg added a comment to T5993: gpg should reject compressed packets outside of messages.

For example Poppler uses GnuPG comment packets to lower its own attack surface by leaving all OpenPGP handling to gpg. The patch (or at least the version we noticed in Fedora and Debian) entirely breaks this use.

May 16 2025, 4:12 PM · Feature Request, gnupg
timegrid created T7658: Okular: Dirmngr startup timeout on signature validation.
May 16 2025, 4:00 PM · Bug Report, gpd5x, okular
werner closed T5993: gpg should reject compressed packets outside of messages as Resolved.
May 16 2025, 2:46 PM · Feature Request, gnupg
werner added a comment to T5993: gpg should reject compressed packets outside of messages.

(The commits had a wrong bug it in their message)

May 16 2025, 2:44 PM · Feature Request, gnupg
werner committed rG23ccad05c680: gpg: Do not allow compressed key packets on import. (authored by werner).
gpg: Do not allow compressed key packets on import.
May 16 2025, 2:40 PM
werner committed rG8e529f922194: gpg: Do not allow compressed key packets on import. (authored by werner).
gpg: Do not allow compressed key packets on import.
May 16 2025, 2:33 PM
werner committed rG645cf7d8fc25: Revert "w32: On socket nonce mismatch close the socket." (authored by werner).
Revert "w32: On socket nonce mismatch close the socket."
May 16 2025, 2:33 PM
werner committed rGfcac10357e6d: gpg: Remove unused variable. (authored by werner).
gpg: Remove unused variable.
May 16 2025, 2:33 PM
CarlSchwan committed rOJcbd05b4cbc1d: Rework networking (authored by CarlSchwan).
Rework networking
May 16 2025, 2:22 PM
CarlSchwan committed rOJe2e5593cf61c: Fix typo (authored by CarlSchwan).
Fix typo
May 16 2025, 2:22 PM
werner added a comment to T5993: gpg should reject compressed packets outside of messages.

It might be useful to have samples of compressed keys:

May 16 2025, 2:20 PM · Feature Request, gnupg
werner committed rEcda4789a9f7d: Time for a new error code; this time GPG_ERR_UNEXPECTED_PACKET (authored by werner).
Time for a new error code; this time GPG_ERR_UNEXPECTED_PACKET
May 16 2025, 12:48 PM
TobiasFella added a comment to T7650: Kleopatra: Limit width of KMessageBoxes.

Apparently KMessageBoxes do actually wrap, just at a larger width than we'd have expected. Lowering this width should be a trivial patch that we could do locally, if we want to

May 16 2025, 12:09 PM · gpd5x, gpgpass, kleopatra
werner updated subscribers of T5993: gpg should reject compressed packets outside of messages.

No, we can't do much about this. It has always been easy to create compression bombs and the more relevant thing here is compressed signed or encrypted data. Or just compressed mails. The patch by @DemiMarie is way to complicated for what it wants to achieve and actually breaks existing use cases. For example Poppler uses GnuPG comment packets to lower its own attack surface by leaving all OpenPGP handling to gpg. The patch (or at least the version we noticed in Fedora and Debian) entirely breaks this use.

May 16 2025, 12:04 PM · Feature Request, gnupg
timegrid created T7657: Kleopatra: Refresh OpenPGP Certificates doesn't respect WKD setting.
May 16 2025, 11:19 AM · Feature Request, kleopatra
CarlSchwan committed rOJ76d54c30297d: Generate manifest.xml at runtime (authored by CarlSchwan).
Generate manifest.xml at runtime
May 16 2025, 11:03 AM
CarlSchwan committed rOJ18f0bb7e0efa: Reencrypt in a seperate folder (authored by CarlSchwan).
Reencrypt in a seperate folder
May 16 2025, 10:15 AM
CarlSchwan committed rOJ674254aebf70: Display name of folder to reencrypt (authored by CarlSchwan).
Display name of folder to reencrypt
May 16 2025, 10:15 AM
CarlSchwan committed rOJd668b9750efb: reencryption: Display logs and reencryption state in a dialog (authored by CarlSchwan).
reencryption: Display logs and reencryption state in a dialog
May 16 2025, 10:15 AM
timegrid created T7656: Kleopatra: Wrong update suggestion from 5.0.0 to 4.4.0.
May 16 2025, 9:25 AM · Bug Report, gpd5x, kleopatra
gniibe committed rG40cfa71281db: common: Add KEM constants for NIST curves. (authored by gniibe).
common: Add KEM constants for NIST curves.
May 16 2025, 7:08 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAa88aff617ab1: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 16 2025, 5:25 AM
l10n daemon script <scripty@kde.org> committed rMTP9a5f0d29218e: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 16 2025, 3:49 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO00921c0a63e9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 16 2025, 3:46 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA67a3d0167d91: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 16 2025, 3:44 AM

May 15 2025

werner added a comment to T7634: libgcrypt's test t-thread-local fails to link on some platforms..

Also pushed to 1.11

May 15 2025, 9:48 PM · NetBSD, libgcrypt, Bug Report
werner committed rDba2663cda232: swdb: gpgol 2.6.1 (authored by werner).
swdb: gpgol 2.6.1
May 15 2025, 4:08 PM
werner committed rO2ed92385c1d9: Post release updates (authored by werner).
Post release updates
May 15 2025, 4:03 PM
werner committed rO4a9196cbb492: Release 2.6.1 (authored by werner).
Release 2.6.1
May 15 2025, 4:03 PM
mmontkowski committed rO6cb4ccf4d8db: Handle filtered READ events (authored by mmontkowski).
Handle filtered READ events
May 15 2025, 3:43 PM
werner committed rObda9f5afc8e6: Handle non mail items in inbox events (authored by mmontkowski).
Handle non mail items in inbox events
May 15 2025, 3:43 PM
ebo renamed T7655: Kleopatra: show a progress window when updating a certificate from Kleopatra: show a progress window when update a certificate to Kleopatra: show a progress window when updating a certificate.
May 15 2025, 3:07 PM · gpd5x, kleopatra
ebo renamed T7655: Kleopatra: show a progress window when updating a certificate from Kleopatra: Trying to update a certificate takes too much time if there is no network to Kleopatra: show a progress window when update a certificate.
May 15 2025, 3:07 PM · gpd5x, kleopatra
ebo added a comment to T7495: Kleopatra: Improve success message on keyserver upload.

Hej thinks that she would expect the dialog to show which certificates were uploaded.
I think if we want to do that, we should make a new ticket for it. Here we wanted the easy quick fix.

May 15 2025, 2:42 PM · kleopatra, gpd5x
TobiasFella changed the status of T7495: Kleopatra: Improve success message on keyserver upload from Open to Testing.
May 15 2025, 1:33 PM · kleopatra, gpd5x
CarlSchwan added a comment to T7654: store app files in AppDate/Local/gpgol-web.

This is not really easy to change, since the proposed paths doesn't match QStandardPath

May 15 2025, 1:13 PM · gpgol2
m <meik.michalke@gnupg.com> committed rOJb0eec451de48: updated README.md (authored by m <meik.michalke@gnupg.com>).
updated README.md
May 15 2025, 1:12 PM
werner added a comment to D556: Disallow compressed signatures and certificates.

Way too complicate and thus has a high risk of regression,

May 15 2025, 11:58 AM
TobiasFella committed rKLEOPATRA0484fe5985be: Improve success message for key upload (authored by TobiasFella).
Improve success message for key upload
May 15 2025, 11:22 AM
TobiasFella changed the status of T7652: Kleopatra: Add plural in verification messages for multiple signatures from Open to Testing.
May 15 2025, 11:22 AM · gpd5x, kleopatra
TobiasFella committed rKLEOPATRA73ca288b2ef5: Use plural when verifying multiple signatures from the same file (authored by TobiasFella).
Use plural when verifying multiple signatures from the same file
May 15 2025, 11:15 AM
TobiasFella committed rKLEOPATRA94bafa83d1fc: Apply 1 suggestion(s) to 1 file(s) (authored by TobiasFella).
Apply 1 suggestion(s) to 1 file(s)
May 15 2025, 11:12 AM
ikloecker committed rLIBKLEO0270587fe3cb: Use new startCreate overload (authored by ikloecker).
Use new startCreate overload
May 15 2025, 10:05 AM
ikloecker committed rGPGMEQT1a063ce9332e: Remove long obsolete feature checks (authored by ikloecker).
Remove long obsolete feature checks
May 15 2025, 10:00 AM
ikloecker committed rGPGMEQT3032aee35248: Modernize interface of QuickJob::startCreate and ::startAddSubkey (authored by ikloecker).
Modernize interface of QuickJob::startCreate and ::startAddSubkey
May 15 2025, 10:00 AM
ikloecker committed rGPGMEPPee85d38a2f9e: Remove long obsolete feature checking API (authored by ikloecker).
Remove long obsolete feature checking API
May 15 2025, 9:57 AM
ikloecker committed rGPGMEPP9200517f23c5: Remove deprecated functions and types (authored by ikloecker).
Remove deprecated functions and types
May 15 2025, 9:57 AM
ikloecker committed rGPGMEPPd3559c8abcfe: Add CreationFlags and simplify API of createKey and createSubkey (authored by ikloecker).
Add CreationFlags and simplify API of createKey and createSubkey
May 15 2025, 9:57 AM
ikloecker committed rGPGMEPP8b853b09d542: New decrypt flag DecryptListOnly (authored by ikloecker).
New decrypt flag DecryptListOnly
May 15 2025, 9:57 AM
hej added a comment to T7581: Kleopatra: Create team key.

"Geheimen Team-Schlüssel zum internen Teilen abspeichern." is grammatically correct, but it sound very formal and clunky for a UI tooltip. It lacks clarity, therefore I suggest:

May 15 2025, 9:31 AM · Feature Request, gpd5x, kleopatra
ikloecker added a comment to T7655: Kleopatra: show a progress window when updating a certificate.

It's pretty much impossible to speed up the situation of unavailable network because network access typically uses long timeouts because networks can be notoriously slow to respond. The only thing we can do is show a progress window so that the users know that Kleopatra is actually doing something.

May 15 2025, 9:11 AM · gpd5x, kleopatra
l10n daemon script <scripty@kde.org> committed rKLEOPATRA107e52b24cf9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 15 2025, 3:44 AM
gniibe committed rC0bd4c77be6e0: mpi:ec: Least leak with k^(-1) for ECDSA. (authored by gniibe).
mpi:ec: Least leak with k^(-1) for ECDSA.
May 15 2025, 2:51 AM
gniibe committed rCaa089ec89bad: mpi:ec: Use ec_mulm_lli in _gcry_mpi_ec_get_affine. (authored by gniibe).
mpi:ec: Use ec_mulm_lli in _gcry_mpi_ec_get_affine.
May 15 2025, 2:51 AM
gniibe changed the status of T7648: Decryption to a Ky768_Cv25519 key does not work if the Cv25519 key is on a token from Open to Testing.
May 15 2025, 1:54 AM · PQC, Bug Report
gniibe closed T7621: libgpg-error: __non_string for GCC 15 or later, a subtask of T7617: libgcrypt: Add __nonstring__ attribute for data for GCC 15 or later, as Resolved.
May 15 2025, 1:51 AM · libgcrypt, Bug Report
gniibe closed T7621: libgpg-error: __non_string for GCC 15 or later as Resolved.
May 15 2025, 1:51 AM · gpgrt, Bug Report

May 14 2025

ikloecker committed rKLEOPATRAb1f3736de7ed: Use Error::isError() to check if an error occurred (authored by ikloecker).
Use Error::isError() to check if an error occurred
May 14 2025, 5:34 PM
ikloecker committed rKLEOPATRA10b618703d74: Include QGpgME/Debug for QDebug operator for GpgME::Error (authored by ikloecker).
Include QGpgME/Debug for QDebug operator for GpgME::Error
May 14 2025, 5:34 PM
ikloecker committed rKLEOPATRAd4f777ffa137: Remove long obsolete feature check (authored by ikloecker).
Remove long obsolete feature check
May 14 2025, 5:34 PM
werner committed rW0929cd3b6783: Rename packages.common to packages.list (authored by werner).
Rename packages.common to packages.list
May 14 2025, 4:16 PM
werner committed rW383eb8586161: Update Okular for gnupg >= 2.4 to the correct version. (authored by werner).
Update Okular for gnupg >= 2.4 to the correct version.
May 14 2025, 4:07 PM
werner committed rWe42e2d1d6037: Merge branch 'gpg4win-5-branch' (authored by werner).
Merge branch 'gpg4win-5-branch'
May 14 2025, 3:58 PM
werner committed rW14ee2719e291: Merge branch 'gpg4win-5-branch' (authored by werner).
Merge branch 'gpg4win-5-branch'
May 14 2025, 3:56 PM
ebo renamed T7655: Kleopatra: show a progress window when updating a certificate from Kleopatra: Trying to update a certificat takes too much time if there is no network to Kleopatra: Trying to update a certificate takes too much time if there is no network.
May 14 2025, 3:55 PM · gpd5x, kleopatra
ebo triaged T7655: Kleopatra: show a progress window when updating a certificate as Normal priority.
May 14 2025, 3:55 PM · gpd5x, kleopatra
m.eik triaged T7654: store app files in AppDate/Local/gpgol-web as Normal priority.
May 14 2025, 3:45 PM · gpgol2
m.eik renamed T7613: GpgOL/Web shows wrong path to manifest in Gpg4Win from Gpg4Win is missing GpgOL/Web's manifest file to GpgOL/Web shows wrong path to manifest in Gpg4Win.
May 14 2025, 3:41 PM · gpgol2