[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#868497: debian-policy: Signed .dsc Files



Paul Hardy <unifoundry@gmail.com> writes:

> Package: debian-policy
> Version: 4.0.0.4
> Severity: wishlist

> Debian Policy Manual, Section 5.4, "Debian source control files - .dsc",
> states in the first sentence:

> "This file consists of a single paragraph, possibly surrounded by a PGP
> signature."

> This does not state whether someone who is creating a package to be
> uploaded by a sponsor can clearsign their own .dsc file, or if only the
> sponsor is able to do that without causing upload problems.

> What is permissible?  Can you clarify that in a future update to this
> section?

(I'm pretty sure the actual answer to this question is that nothing
cares.)

I assume you're talking about sponsorship via mentors.debian.org?  If so,
that's out of scope for Policy and one should refer to the local
documentation for how that system works (it's not the same as the regular
Debian archive).

All of the concepts you refer to in this bug report (sponsorship,
sponsors, someone else uploading a package for someone) are outside the
scope of Policy currently, so we'd have to define a whole bunch of terms
to even talk about this.

-- 
Russ Allbery (rra@debian.org)               <http://www.eyrie.org/~eagle/>


Reply to: