From: "Michael S. Tsirkin" <mst@redhat.com>
To: Peter Maydell <peter.maydell@linaro.org>
Cc: QEMU Developers <qemu-devel@nongnu.org>,
Anthony Liguori <aliguori@amazon.com>
Subject: Re: [Qemu-devel] [PULL v3 00/14] acpi, pc, pci, virtio, memory bug fixes
Date: Tue, 11 Mar 2014 13:49:15 +0200 [thread overview]
Message-ID: <20140311114915.GA30708@redhat.com> (raw)
In-Reply-To: <CAFEAcA-MrspL9CFq4Thjqd8=aYQRJUq+f7GR08FjN3DxqKbZ2w@mail.gmail.com>
On Tue, Mar 11, 2014 at 11:32:41AM +0000, Peter Maydell wrote:
> On 11 March 2014 11:22, Michael S. Tsirkin <mst@redhat.com> wrote:
> > BTW I still see these warnings in the logs:
> > # gpg: WARNING: This key is not certified with a trusted signature!
> > # gpg: There is no indication that the signature belongs to
> > # the
> >
> > These seem counter-productive: people get used
> > to ignoring the warnings.
> > A bunch of people verified my key at the latest KVM forum
> > so how about importing keys from contributors
> > and denying pulls where keys don't match?
>
> That won't help with removing the warning. What gpg
> is saying here is "I found this key in the keyring,
> and the signature checks out, but there's no chain
> of trust between the person who applied the pull
> and that key". That is, I haven't signed your key.
Okay ... would you like to sign it?
Didn't you go to the key signing party at the forum?
If yes you have all the data :)
> The other kind of warning is:
> # gpg: Signature made Sat 08 Mar 2014 21:26:01 GMT using RSA key ID 5872D723
> # gpg: Can't check signature: public key not found
>
> which means "I didn't find the gpg key in the keyring".
>
> Genuinely mismatching signatures would be a gpg
> error rather than a mere warning, I think.
>
> Since we're still accepting unsigned pullrequests
> I don't think this matters too much. In either case
> if somebody really cares later they can attempt to
> establish a chain of trust between themselves and the
> submitter after the fact, I guess.
But the commit log will include the warning forever I think?
> Personally I think the next step we should take would
> be to get all the people currently submitting unsigned
> pull requests to move over to signing them.
>
> thanks
> -- PMM
I think this was agreed on the forum so you
can start enforcing this straight away if you wish :)
--
MST
next prev parent reply other threads:[~2014-03-11 11:53 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-03-09 19:19 [Qemu-devel] [PULL v3 00/14] acpi,pc,pci,virtio,memory bug fixes Michael S. Tsirkin
2014-03-09 19:19 ` [Qemu-devel] [PULL v3 01/14] acpi-build: append description for non-hotplug Michael S. Tsirkin
2014-03-09 19:19 ` [Qemu-devel] [PULL v3 02/14] acpi-test-data: update expected files Michael S. Tsirkin
2014-03-09 19:19 ` [Qemu-devel] [PULL v3 03/14] virtio-net: remove function calls from assert Michael S. Tsirkin
2014-03-09 19:19 ` [Qemu-devel] [PULL v3 04/14] memory_region_present: return false if address is not found in child MemoryRegion Michael S. Tsirkin
2014-03-09 19:19 ` [Qemu-devel] [PULL v3 05/14] PCIE: fix regression with coldplugged multifunction device Michael S. Tsirkin
2014-03-09 19:19 ` [Qemu-devel] [PULL v3 06/14] Rework --name to use QemuOpts Michael S. Tsirkin
2014-03-09 19:19 ` [Qemu-devel] [PULL v3 07/14] Add 'debug-threads' suboption to --name Michael S. Tsirkin
2014-03-09 19:20 ` [Qemu-devel] [PULL v3 08/14] Add a 'name' parameter to qemu_thread_create Michael S. Tsirkin
2014-03-11 15:31 ` Jan Kiszka
2014-03-11 15:49 ` [Qemu-devel] [PATCH] qemu-thread-posix: Fix build against older glibc version Jan Kiszka
2014-03-11 16:10 ` Peter Maydell
2014-03-11 16:13 ` Dr. David Alan Gilbert
2014-03-11 16:20 ` Peter Maydell
2014-03-11 16:36 ` Dr. David Alan Gilbert
2014-03-11 17:51 ` Peter Maydell
2014-03-11 18:39 ` Michael S. Tsirkin
2014-03-11 19:46 ` Dr. David Alan Gilbert
2014-03-11 19:53 ` Peter Maydell
2014-03-11 20:03 ` Michael S. Tsirkin
2014-03-11 20:27 ` Peter Maydell
2014-03-11 20:35 ` Michael S. Tsirkin
2014-03-11 20:39 ` Eric Blake
2014-03-11 20:04 ` Dr. David Alan Gilbert
2014-04-02 14:18 ` Ed Maste
2014-04-02 15:38 ` Dr. David Alan Gilbert
2014-03-11 18:08 ` Dr. David Alan Gilbert
2014-03-11 19:02 ` Peter Maydell
2014-03-11 15:55 ` [Qemu-devel] [PULL v3 08/14] Add a 'name' parameter to qemu_thread_create Dr. David Alan Gilbert
2014-03-09 19:20 ` [Qemu-devel] [PULL v3 09/14] MAINTAINERS: drop an out of date address Michael S. Tsirkin
2014-03-09 19:20 ` [Qemu-devel] [PULL v3 10/14] acpi-test: retain both asl and aml files on failure Michael S. Tsirkin
2014-03-09 19:20 ` [Qemu-devel] [PULL v3 11/14] acpi-test: issue errors instead of warnings when possible Michael S. Tsirkin
2014-03-09 19:20 ` [Qemu-devel] [PULL v3 12/14] pam: partly fix write-only mode Michael S. Tsirkin
2014-03-09 19:20 ` [Qemu-devel] [PULL v3 13/14] pckbd: return 'keyboard enabled' on read input port command Michael S. Tsirkin
2014-03-09 19:20 ` [Qemu-devel] [PULL v3 14/14] qemu: x86: ignore ioapic polarity Michael S. Tsirkin
2014-03-10 15:38 ` [Qemu-devel] [PULL v3 00/14] acpi, pc, pci, virtio, memory bug fixes Peter Maydell
2014-03-10 19:05 ` Michael S. Tsirkin
2014-03-11 10:55 ` Peter Maydell
2014-03-11 11:22 ` Michael S. Tsirkin
2014-03-11 11:32 ` Peter Maydell
2014-03-11 11:49 ` Michael S. Tsirkin [this message]
2014-03-11 12:09 ` Peter Maydell
2014-03-11 12:22 ` Michael S. Tsirkin
2014-03-11 12:31 ` Peter Maydell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140311114915.GA30708@redhat.com \
--to=mst@redhat.com \
--cc=aliguori@amazon.com \
--cc=peter.maydell@linaro.org \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.