tags 646993 + confirmed
quit

Hi Jonathan,

On 2011-10-29 00:47, Jonathan Nieder wrote:
[...]
> Something like
> 
>       apt-key exportall |
>       apt-key --keyring /var/lib/cupt/trusted.gpg add -
> 
> in place of
> 
>       install -m644 /etc/apt/trusted.gpg /var/lib/cupt
> 
> in the postinst and cpp/lib/src/cache.cpp seems to take care of it.

Too bad this will add 'Depends: apt' to the package, which I would like
to avoid.

> By the way, the code in cache.cpp makes me wonder: why does cupt need
> to copy the keyring to a private location when it is treating APT's
> keyring as authoritative anyway?

See #647001. I should have filed it years ago, but better later than
never. I have also added a comment to a code with a reference to the
bug.


I am generally not happy at all with the current keyring handling in
Cupt. If you have some improvement ideas, please tell.

-- 
Eugene V. Lyubimkin aka JackYF, JID: jackyf.devel(maildog)gmail.com
C++/Perl developer, Debian Developer



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to