Page MenuHome GnuPG
Feed All Stories

May 20 2025

ebo added a member for Contributor: sj98ta.
May 20 2025, 10:44 AM
werner committed rG2bbcbbcbe8c5: doc: Add a note to READ on how to disable the systemd activation. (authored by werner).
doc: Add a note to READ on how to disable the systemd activation.
May 20 2025, 10:19 AM
CarlSchwan added a reverting change for rOJd668b9750efb: reencryption: Display logs and reencryption state in a dialog: rOJ5ef79c8110c1: Disable code that needs latest gpgmepp/gpgmeqt.
May 20 2025, 10:07 AM
CarlSchwan committed rOJ5ef79c8110c1: Disable code that needs latest gpgmepp/gpgmeqt (authored by CarlSchwan).
Disable code that needs latest gpgmepp/gpgmeqt
May 20 2025, 10:07 AM
gniibe committed rGeb9c39ac5bb5: agent: Refactor ECC KEM decap operation. (authored by gniibe).
agent: Refactor ECC KEM decap operation.
May 20 2025, 9:33 AM
ebo closed T7524: Release GPGME 1.24.2 as Resolved.
May 20 2025, 9:32 AM · gpgme, Release Info
sachint added a comment to D612: Add support for IBM z/OS.

Hi, Please review the change and feedback.

May 20 2025, 9:04 AM · ntbtls
sachint requested review of D612: Add support for IBM z/OS.
May 20 2025, 9:04 AM · ntbtls
sachint added a comment to D611: Add support for IBM z/OS.

Please review the changes and feedback

May 20 2025, 8:37 AM · libassuan
sachint requested review of D611: Add support for IBM z/OS.
May 20 2025, 8:37 AM · libassuan
sachint added a comment to D610: Add support for IBM z/OS.

Please review the patch and feedback.

May 20 2025, 8:30 AM · libksba
sachint requested review of D610: Add support for IBM z/OS.
May 20 2025, 8:29 AM · libksba
sachint added a comment to D609: Add support for IBM z/OS.

Please review the changes and feedback.

May 20 2025, 8:20 AM
sachint updated the summary of D609: Add support for IBM z/OS.
May 20 2025, 8:19 AM
sachint requested review of D609: Add support for IBM z/OS.
May 20 2025, 8:16 AM

May 19 2025

jukivili committed rCb100dd25eb68: Fix missing simd-common-riscv.h in libgcrypt tarball. (authored by collinfunk).
Fix missing simd-common-riscv.h in libgcrypt tarball.
May 19 2025, 5:59 PM
werner committed rM4a1ce4081cdc: Post release updates (authored by werner).
Post release updates
May 19 2025, 5:11 PM
werner committed rM6403435fa187: Release 1.24.3 (authored by werner).
Release 1.24.3
May 19 2025, 5:11 PM
werner committed rD2614e3bbb06f: swdb: gpgme 1.24.3 (authored by werner).
swdb: gpgme 1.24.3
May 19 2025, 4:50 PM
werner closed T7659: Release GPGME 1.24.3 as Resolved.
May 19 2025, 4:43 PM · Release Info, gpgme
werner updated the task description for T7524: Release GPGME 1.24.2.
May 19 2025, 4:36 PM · gpgme, Release Info
werner added a comment to T7627: gpgme(qt) testsuite error on 32bit archs with 64bit time_t.

We won't apply any fixes to the cpp, QT, or Python language bindings in the 1.24 branch. The Qt branch has been factored out to the gpgmeqt project on request from the KDE folks. And yes, we should add projects (tags) for gpgmepp and gpgmeqt.

May 19 2025, 4:34 PM · gpgme, Bug Report
werner updated the task description for T7524: Release GPGME 1.24.2.
May 19 2025, 4:26 PM · gpgme, Release Info
werner triaged T7659: Release GPGME 1.24.3 as Low priority.
May 19 2025, 4:25 PM · Release Info, gpgme
ikloecker committed rKLEOPATRA61187a1f06d2: Bump version number to match latest released VSD version (authored by ikloecker).
Bump version number to match latest released VSD version
May 19 2025, 4:17 PM
chengr28 added a comment to T7577: GnuPG could not work when TCP congestion provider is set to BBR2 in Windows.

Spent some time discovering and unfortunately it's Windows's bug in loopback interface.
I wrote a test demo (blocking mode) to exchange data and watched their packets, found that network stack would drop packets when congestion control algorithm is set to BBR2. It seems the second data exchange was broken.

May 19 2025, 3:20 PM · Support, Not A Bug, gnupg, Bug Report
ikloecker committed rGPGMEPPa13ba8a8170e: build: Don't compile with _FILE_OFFSET_BITS=64 on Windows (MinGW) (authored by ikloecker).
build: Don't compile with _FILE_OFFSET_BITS=64 on Windows (MinGW)
May 19 2025, 12:22 PM
ikloecker added a reverting change for rGPGMEPP629daa8492de: build: Always compile with _FILE_OFFSET_BITS=64 on Windows (MinGW): rGPGMEPPa13ba8a8170e: build: Don't compile with _FILE_OFFSET_BITS=64 on Windows (MinGW).
May 19 2025, 12:22 PM
ikloecker committed rGPGMEPP23c297d13e04: Move definition of functions declared in error.h to error.cpp (authored by ikloecker).
Move definition of functions declared in error.h to error.cpp
May 19 2025, 12:22 PM
werner closed T7647: cipher/simd-common-riscv.h missing from libgcrypt 1.11.1 tarball as Resolved.

Problem noted in T7166

May 19 2025, 12:16 PM · riscv, libgcrypt, Bug Report
werner added a comment to T7166: Release Libgcrypt 1.11.1.

Noet that one file is missing in the released tarball; when building for RISC-V please see T7647#201164

May 19 2025, 12:15 PM · Release Info, libgcrypt
werner added a comment to T7647: cipher/simd-common-riscv.h missing from libgcrypt 1.11.1 tarball.

Patch applied.

May 19 2025, 12:12 PM · riscv, libgcrypt, Bug Report
ebo moved T6584: Kleopatra / Gpgtar: Cancel on encrypt leaves a broken archive behind from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · vsd32 (vsd-3.2.0), Restricted Project, kleopatra
ebo moved T6793: Cleanup temporary files / dirs with decrypted content from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · needs discussion, gpd5x, kleopatra
ebo moved T6907: gpgme: Explicitly tell gpg that we want to verify signed data from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · gpgme, Restricted Project
ebo moved T6917: Kleopatra: write error when decrypting to network drive from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · vsd32 (vsd-3.2.0), Restricted Project, kleopatra
ebo moved T6926: No tray icon for Kleopatra in dark mode on Windows. from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · Restricted Project, Bug Report, Windows, kleopatra
ebo moved T6095: Kleopatra: Fix accessibility of group configuration from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:48 AM · kleopatra, Restricted Project
ebo moved T7021: Kleopatra: restart gpg-agent after stopping it from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · vsd32 (vsd-3.2.0), kleopatra, Restricted Project
ebo moved T7051: Kleopatra: Defunct processes when Kleopatra is running with elevated privileges from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · vsd32 (vsd-3.2.0), kleopatra, Restricted Project
ebo moved T6688: Kleopatra GPGME: Reported assert on exit from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · gpd5x (gpd-5.0.0), gpgme, kleopatra
ebo moved T7045: Kleopatra: Use "SCD DEVINFO --watch" also on Windows from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · gpd5x (gpd-5.0.0), kleopatra
ebo moved T7204: Kleopatra: Remove Option "Show tags attached to certificates" from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · vsd33 (vsd-3.3.0), kleopatra, Restricted Project
ebo moved T7272: Kleopatra: Look up missing OpenPGP certificates for card keys from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · gpd5x (gpd-5.0.0), LDAP, kleopatra
ebo moved T7297: Kleopatra: Improve support for V5 fingerprints from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · gpd5x (gpd-5.0.0), kleopatra
ebo moved T7489: Kleopatra: missing translations in kf5 from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · vsd33 (vsd-3.3.0), Restricted Project, kleopatra
ebo moved T7525: gpg4win: Add support for Wayland to the Qt5-based AppImage from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 19 2025, 11:47 AM · Restricted Project, gpg4win
gniibe committed rGd1c3bfda2a8c: gpg: Use the KEM API for ECC encryption. (authored by gniibe).
gpg: Use the KEM API for ECC encryption.
May 19 2025, 8:01 AM
gniibe added a comment to T7640: ML-DSA for libgcrypt.

Looking the FIPS 204 document, using the following functions (API) is good:

May 19 2025, 7:47 AM · PQC, libgcrypt
l10n daemon script <scripty@kde.org> committed rKLEOPATRAfd43796728bc: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 19 2025, 3:43 AM
gniibe renamed T7649: gnupg: Use KEM interface for encryption/decryption from gnupg: Use KEM interface for decryption to gnupg: Use KEM interface for encryption/decryption.
May 19 2025, 2:35 AM · gnupg26

May 18 2025

l10n daemon script <scripty@kde.org> committed rKLEOPATRA675cff6e38fe: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 18 2025, 5:20 AM
l10n daemon script <scripty@kde.org> committed rMTPb5b9105072d9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 18 2025, 3:44 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA30eabd76f72b: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 18 2025, 3:42 AM

May 17 2025

collinfunk added a comment to T7647: cipher/simd-common-riscv.h missing from libgcrypt 1.11.1 tarball.

I can confirm this. Here is the build error:

make[2]: Entering directory '/home/collinfunk/libgcrypt-1.11.1/cipher'
`echo /bin/bash ../libtool  --tag=CC   --mode=compile gcc -DHAVE_CONFIG_H -I. -I..  -I../src -I../src -I../mpi -I../mpi  -I/home/collinfunk/tmp/include -g -O2 -fvisibility=hidden -fno-delete-null-pointer-checks -Wall -O2 -march=rv64imafdcv -mstrict-align -c rijndael-vp-riscv.c | sed -e 's/-fsanitize[=,\-][=,a-z,A-Z,0-9,\,,\-]*//g' -e 's/-fprofile[=,\-][=,a-z,A-Z,0-9,\,,\-]*//g' -e 's/-fcoverage[=,\-][=,a-z,A-Z,0-9,\,,\-]*//g' `
libtool: compile:  gcc -DHAVE_CONFIG_H -I. -I.. -I../src -I../src -I../mpi -I../mpi -I/home/collinfunk/tmp/include -g -O2 -fvisibility=hidden -fno-delete-null-pointer-checks -Wall -O2 -march=rv64imafdcv -mstrict-align -c rijndael-vp-riscv.c  -fPIC -DPIC -o .libs/rijndael-vp-riscv.o
rijndael-vp-riscv.c:58:10: fatal error: simd-common-riscv.h: No such file or directory
   58 | #include "simd-common-riscv.h"
      |          ^~~~~~~~~~~~~~~~~~~~~
compilation terminated.
make[2]: *** [Makefile:1730: rijndael-vp-riscv.lo] Error 1

Patch here: https://lists.gnupg.org/pipermail/gcrypt-devel/2025-May/005854.html

May 17 2025, 6:13 AM · riscv, libgcrypt, Bug Report
l10n daemon script <scripty@kde.org> committed rMTP7f65aae26576: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 17 2025, 5:16 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAeff566397e25: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 17 2025, 5:16 AM
l10n daemon script <scripty@kde.org> committed rMTP034f08709d92: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 17 2025, 3:43 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA62058f59ad60: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 17 2025, 3:41 AM

May 16 2025

timegrid updated the task description for T7658: Okular: Dirmngr startup timeout on signature validation.
May 16 2025, 4:30 PM · gpd5x (gpd-5.0.0), Bug Report, okular
timegrid updated the task description for T7658: Okular: Dirmngr startup timeout on signature validation.
May 16 2025, 4:27 PM · gpd5x (gpd-5.0.0), Bug Report, okular
dkg added a comment to T5993: gpg should reject compressed packets outside of messages.

For example Poppler uses GnuPG comment packets to lower its own attack surface by leaving all OpenPGP handling to gpg. The patch (or at least the version we noticed in Fedora and Debian) entirely breaks this use.

May 16 2025, 4:12 PM · Feature Request, gnupg
timegrid created T7658: Okular: Dirmngr startup timeout on signature validation.
May 16 2025, 4:00 PM · gpd5x (gpd-5.0.0), Bug Report, okular
werner closed T5993: gpg should reject compressed packets outside of messages as Resolved.
May 16 2025, 2:46 PM · Feature Request, gnupg
werner added a comment to T5993: gpg should reject compressed packets outside of messages.

(The commits had a wrong bug it in their message)

May 16 2025, 2:44 PM · Feature Request, gnupg
werner committed rG23ccad05c680: gpg: Do not allow compressed key packets on import. (authored by werner).
gpg: Do not allow compressed key packets on import.
May 16 2025, 2:40 PM
werner committed rG8e529f922194: gpg: Do not allow compressed key packets on import. (authored by werner).
gpg: Do not allow compressed key packets on import.
May 16 2025, 2:33 PM
werner committed rG645cf7d8fc25: Revert "w32: On socket nonce mismatch close the socket." (authored by werner).
Revert "w32: On socket nonce mismatch close the socket."
May 16 2025, 2:33 PM
werner committed rGfcac10357e6d: gpg: Remove unused variable. (authored by werner).
gpg: Remove unused variable.
May 16 2025, 2:33 PM
CarlSchwan committed rOJcbd05b4cbc1d: Rework networking (authored by CarlSchwan).
Rework networking
May 16 2025, 2:22 PM
CarlSchwan committed rOJe2e5593cf61c: Fix typo (authored by CarlSchwan).
Fix typo
May 16 2025, 2:22 PM
werner added a comment to T5993: gpg should reject compressed packets outside of messages.

It might be useful to have samples of compressed keys:

May 16 2025, 2:20 PM · Feature Request, gnupg
werner committed rEcda4789a9f7d: Time for a new error code; this time GPG_ERR_UNEXPECTED_PACKET (authored by werner).
Time for a new error code; this time GPG_ERR_UNEXPECTED_PACKET
May 16 2025, 12:48 PM
TobiasFella added a comment to T7650: Kleopatra: Limit width of KMessageBoxes.

Apparently KMessageBoxes do actually wrap, just at a larger width than we'd have expected. Lowering this width should be a trivial patch that we could do locally, if we want to

May 16 2025, 12:09 PM · gpd5x, gpgpass, kleopatra
werner updated subscribers of T5993: gpg should reject compressed packets outside of messages.

No, we can't do much about this. It has always been easy to create compression bombs and the more relevant thing here is compressed signed or encrypted data. Or just compressed mails. The patch by @DemiMarie is way to complicated for what it wants to achieve and actually breaks existing use cases. For example Poppler uses GnuPG comment packets to lower its own attack surface by leaving all OpenPGP handling to gpg. The patch (or at least the version we noticed in Fedora and Debian) entirely breaks this use.

May 16 2025, 12:04 PM · Feature Request, gnupg
timegrid created T7657: Kleopatra: Refresh OpenPGP Certificates doesn't respect WKD setting.
May 16 2025, 11:19 AM · Feature Request, kleopatra
CarlSchwan committed rOJ76d54c30297d: Generate manifest.xml at runtime (authored by CarlSchwan).
Generate manifest.xml at runtime
May 16 2025, 11:03 AM
CarlSchwan committed rOJ18f0bb7e0efa: Reencrypt in a seperate folder (authored by CarlSchwan).
Reencrypt in a seperate folder
May 16 2025, 10:15 AM
CarlSchwan committed rOJ674254aebf70: Display name of folder to reencrypt (authored by CarlSchwan).
Display name of folder to reencrypt
May 16 2025, 10:15 AM
CarlSchwan committed rOJd668b9750efb: reencryption: Display logs and reencryption state in a dialog (authored by CarlSchwan).
reencryption: Display logs and reencryption state in a dialog
May 16 2025, 10:15 AM
timegrid created T7656: Kleopatra: Wrong update suggestion from 5.0.0 to 4.4.0.
May 16 2025, 9:25 AM · gpd5x (gpd-5.0.0), Bug Report, kleopatra
gniibe committed rG40cfa71281db: common: Add KEM constants for NIST curves. (authored by gniibe).
common: Add KEM constants for NIST curves.
May 16 2025, 7:08 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAa88aff617ab1: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 16 2025, 5:25 AM
l10n daemon script <scripty@kde.org> committed rMTP9a5f0d29218e: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 16 2025, 3:49 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO00921c0a63e9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 16 2025, 3:46 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA67a3d0167d91: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 16 2025, 3:44 AM

May 15 2025

werner added a comment to T7634: libgcrypt's test t-thread-local fails to link on some platforms..

Also pushed to 1.11

May 15 2025, 9:48 PM · NetBSD, libgcrypt, Bug Report
werner committed rDba2663cda232: swdb: gpgol 2.6.1 (authored by werner).
swdb: gpgol 2.6.1
May 15 2025, 4:08 PM
werner committed rO2ed92385c1d9: Post release updates (authored by werner).
Post release updates
May 15 2025, 4:03 PM
werner committed rO4a9196cbb492: Release 2.6.1 (authored by werner).
Release 2.6.1
May 15 2025, 4:03 PM
mmontkowski committed rO6cb4ccf4d8db: Handle filtered READ events (authored by mmontkowski).
Handle filtered READ events
May 15 2025, 3:43 PM
werner committed rObda9f5afc8e6: Handle non mail items in inbox events (authored by mmontkowski).
Handle non mail items in inbox events
May 15 2025, 3:43 PM
ebo renamed T7655: Kleopatra: show a progress window when updating a certificate from Kleopatra: show a progress window when update a certificate to Kleopatra: show a progress window when updating a certificate.
May 15 2025, 3:07 PM · gpd5x (gpd-5.0.0), kleopatra
ebo renamed T7655: Kleopatra: show a progress window when updating a certificate from Kleopatra: Trying to update a certificate takes too much time if there is no network to Kleopatra: show a progress window when update a certificate.
May 15 2025, 3:07 PM · gpd5x (gpd-5.0.0), kleopatra
ebo added a comment to T7495: Kleopatra: Improve success message on keyserver upload.

Hej thinks that she would expect the dialog to show which certificates were uploaded.
I think if we want to do that, we should make a new ticket for it. Here we wanted the easy quick fix.

May 15 2025, 2:42 PM · gpd5x (gpd-5.0.0), kleopatra
TobiasFella changed the status of T7495: Kleopatra: Improve success message on keyserver upload from Open to Testing.
May 15 2025, 1:33 PM · gpd5x (gpd-5.0.0), kleopatra
CarlSchwan added a comment to T7654: store app files in AppDate/Local/gpgol-web.

This is not really easy to change, since the proposed paths doesn't match QStandardPath

May 15 2025, 1:13 PM · gpgol2
m <meik.michalke@gnupg.com> committed rOJb0eec451de48: updated README.md (authored by m <meik.michalke@gnupg.com>).
updated README.md
May 15 2025, 1:12 PM
werner added a comment to D556: Disallow compressed signatures and certificates.

Way too complicate and thus has a high risk of regression,

May 15 2025, 11:58 AM
TobiasFella committed rKLEOPATRA0484fe5985be: Improve success message for key upload (authored by TobiasFella).
Improve success message for key upload
May 15 2025, 11:22 AM