Support tofu+pgp trust model in GnuPG
authorBenjamin Barenblat <bbaren@google.com>
Wed, 18 Dec 2024 16:10:23 +0000 (17:10 +0100)
committerRene Engelhard <rene@debian.org>
Wed, 18 Dec 2024 16:10:23 +0000 (17:10 +0100)
commit7500a304813a8f756e42bcc92aa3de96a6985e49
tree390f0c45e8f7875e5617b6a734689e0c42f7792a
parentbbc11e01399adc750fed53cf47d48749b103803a
Support tofu+pgp trust model in GnuPG

Bug-Debian: https://bugs.debian.org/955271
Forwarded: no

GnuPG supports a trust-on-first-use layer that sits on top of the
standard PGP trust model. If this is enabled, 'gpg --list-keys' needs
write and lock permissions on the TOFU database to return any useful
data. Allow this access through AppArmor.

Gbp-Pq: Name apparmor-gnupg-tofu.diff
sysui/desktop/apparmor/program.soffice.bin