Support tofu+pgp trust model in GnuPG
authorBenjamin Barenblat <bbaren@google.com>
Sat, 12 Nov 2022 08:28:58 +0000 (08:28 +0000)
committerRene Engelhard <rene@debian.org>
Sat, 12 Nov 2022 08:28:58 +0000 (08:28 +0000)
commit3ef6a20c646fdfd50e8b6a99051fd4d2db5d0b29
treed0353c19f813683260c699fb296fde6b956200ca
parent03697de5c52c766f6771899854199c7c1786c0ae
Support tofu+pgp trust model in GnuPG

Bug-Debian: https://bugs.debian.org/955271
Forwarded: no

GnuPG supports a trust-on-first-use layer that sits on top of the
standard PGP trust model. If this is enabled, 'gpg --list-keys' needs
write and lock permissions on the TOFU database to return any useful
data. Allow this access through AppArmor.

Gbp-Pq: Name apparmor-gnupg-tofu.diff
sysui/desktop/apparmor/program.soffice.bin