Support tofu+pgp trust model in GnuPG
authorBenjamin Barenblat <bbaren@google.com>
Wed, 5 Jun 2024 11:30:31 +0000 (13:30 +0200)
committerRene Engelhard <rene@debian.org>
Wed, 5 Jun 2024 11:30:31 +0000 (13:30 +0200)
commit014b7c7ed07343c068a3c994954a020e5ac5973f
tree380f299df18dd38598c8ca6e0bdae06eecedc212
parent3c15bc9ba6022f88cf96e0b1261563f1e3f26dbc
Support tofu+pgp trust model in GnuPG

Bug-Debian: https://bugs.debian.org/955271
Forwarded: no

GnuPG supports a trust-on-first-use layer that sits on top of the
standard PGP trust model. If this is enabled, 'gpg --list-keys' needs
write and lock permissions on the TOFU database to return any useful
data. Allow this access through AppArmor.

Gbp-Pq: Name apparmor-gnupg-tofu.diff
sysui/desktop/apparmor/program.soffice.bin