GNU bug report logs -
#17625
details of package signing mechanism
Previous Next
Reported by: Eric Abrahamsen <eric <at> ericabrahamsen.net>
Date: Thu, 29 May 2014 03:12:01 UTC
Severity: important
Tags: security
Found in version 24.4.50
Done: Stefan Monnier <monnier <at> iro.umontreal.ca>
Bug is archived. No further changes may be made.
Full log
Message #5 received at submit <at> debbugs.gnu.org (full text, mbox):
[Message part 1 (text/plain, inline)]
I'm using the most recent git version of emacs, updated ten minutes ago
or so. I (require 'package), then add-to-list both Melpa and Marmalade
to package-archives. I have a dozen or so packages installed already,
from ELPA, Melpa, and Marmalade.
The command `list-packages' then gives me a *Package* buffer in which
all installed packages are marked as "unsigned", in a bright red face,
and the "archive" column is empty. Getting info on any of these
installed packages shows a *Help* screen where the "Archive" heading
reads n/a, but "Version" obviously matches on of the versions mentioned
in "Other versions". I've attached a screenshot which should make all of
this obvious. Apparently it's not supposed to be like this.
Thanks,
Eric
[packages.png (image/png, attachment)]
[Message part 3 (text/plain, inline)]
In GNU Emacs 24.4.50.1 (i686-pc-linux-gnu, GTK+ Version 3.12.2)
of 2014-05-29 on pellet
Windowing system distributor `The X.Org Foundation', version 11.0.11501000
Configured using:
`configure --with-gif=no'
Configured features:
XPM JPEG TIFF PNG RSVG IMAGEMAGICK SOUND GPM DBUS GCONF GSETTINGS NOTIFY
ACL GNUTLS LIBXML2 FREETYPE M17N_FLT LIBOTF XFT ZLIB
Important settings:
value of $LANG: en_US.UTF-8
value of $XMODIFIERS: @im=fcitx
locale-coding-system: utf-8-unix
Major mode: Help
Minor modes in effect:
tooltip-mode: t
electric-indent-mode: t
mouse-wheel-mode: t
tool-bar-mode: t
menu-bar-mode: t
file-name-shadow-mode: t
global-font-lock-mode: t
font-lock-mode: t
blink-cursor-mode: t
auto-composition-mode: t
auto-encryption-mode: t
auto-compression-mode: t
buffer-read-only: t
line-number-mode: t
transient-mark-mode: t
Recent input:
C-x C-f . e m a s c <tab> <backspace> <backspace> c
s <tab> i n i t . e l <return> <down> <down> <down>
C-e C-g <down> <down> C-x C-e <down> <down> C-e C-x
C-e <down> <down> C-x C-e C-v M-v <up> <up> <up> C-x
C-f l i s p / i n i t - b a r e b o n e s . e l <return>
<down> <down> <down> <down> <down> <down> <down> <down>
<down> C-e M-b M-b M-b M-d a b s M-f - g i t / s r
c / n o t m u c h C-x C-s <down> C-x <left> M-x l i
s p - <backspace> <backspace> t = <backspace> - p a
c k a g e s <return> C-v C-v C-v C-v M-> M-v M-v M-v
<down> <up> <up> <up> <up> <up> <up> <up> <up> C-l
<up> <up> <up> <up> <up> <up> ? C-x 1 C-x 3 C-x o C-x
b <tab> H <backspace> * H e <tab> <return> C-x 1 M-x
r e p o r t - m e <backspace> <backspace> e m a c s
- b u g <return>
Recent messages:
(("marmalade" . "http://marmalade-repo.org/packages/") ("gnu" . "http://elpa.gnu.org/packages/"))
(("melpa" . "http://melpa.milkbox.net/packages/") ("marmalade" . "http://marmalade-repo.org/packages/") ("gnu" . "http://elpa.gnu.org/packages/"))
Saving file /home/eric/.emacs.d/lisp/init-barebones.el...
Wrote /home/eric/.emacs.d/lisp/init-barebones.el
Contacting host: melpa.milkbox.net:80 [2 times]
Contacting host: marmalade-repo.org:80
Contacting host: elpa.gnu.org:80
Mark set
Type C-x 1 to delete the help window.
Making completion list...
Load-path shadows:
None found.
Features:
(shadow sort mail-extr emacsbug sendmail lisp-mnt help-mode mule-util
parse-time mm-archive message dired format-spec rfc822 mml easymenu
mml-sec mailabbrev gmm-utils mailheader mm-decode mm-bodies mm-encode
mail-utils network-stream starttls url-http tls mail-parse rfc2231
rfc2047 rfc2045 ietf-drums url-gw url-cache url-auth url url-proxy
url-privacy url-expand url-methods url-history url-cookie url-domsuf
url-util mailcap url-handlers url-parse auth-source eieio byte-opt
bytecomp byte-compile cconv eieio-core gnus-util mm-util help-fns
mail-prsvr password-cache url-vars finder-inf package time-date tooltip
electric uniquify ediff-hook vc-hooks lisp-float-type mwheel x-win x-dnd
tool-bar dnd fontset image regexp-opt fringe tabulated-list newcomment
lisp-mode prog-mode register page menu-bar rfn-eshadow timer select
scroll-bar mouse jit-lock font-lock syntax facemenu font-core frame cham
georgian utf-8-lang misc-lang vietnamese tibetan thai tai-viet lao
korean japanese hebrew greek romanian slovak czech european ethiopic
indian cyrillic chinese case-table epa-hook jka-cmpr-hook help simple
abbrev minibuffer nadvice loaddefs button faces cus-face macroexp files
text-properties overlay sha1 md5 base64 format env code-pages mule
custom widget hashtable-print-readable backquote make-network-process
dbusbind gfilenotify dynamic-setting system-font-setting
font-render-setting move-toolbar gtk x-toolkit x multi-tty emacs)
Memory information:
((conses 8 594477 75145)
(symbols 24 22881 0)
(miscs 20 43 272)
(strings 16 53845 11297)
(string-bytes 1 1465016)
(vectors 8 24545)
(vector-slots 4 1240364 40700)
(floats 8 82 558)
(intervals 28 78465 2398)
(buffers 512 16)
(heap 1024 21565 1004))
This bug report was last modified 10 years and 236 days ago.
Previous Next
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson.