Skip to content

PQC support via new pysequoia version - #8011

Merged
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia
Aug 31, 2026
Merged

PQC support via new pysequoia version#8011
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia

Conversation

@dralley

Copy link
Copy Markdown
Contributor

Rebase the minimum bound of pysequoia to one which adds support for post-quantum cryptography / RFC 9980.

Add tests for gpg_verify function and PQC signing services

Assisted-By: Claude Sonnet 4.5

Comment threadpyproject.toml Outdated
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia @ git+https://github.com/wiktor-k/pysequoia.git",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not released yet, just testing the rest of the changes.

@dralley

dralley commented Aug 25, 2026

Copy link
Copy Markdown
ContributorAuthor

Using ephemeral keys turns out to be much faster than downloading keys from fixtures, 0.09s vs 5.38s. The exception is RSA which is slower (keygen is expensive by comparison to other algos) but I'm not adding any tests using RSA here.


from pulpcore.pytest_plugin import (
KEY_V4_RSA4K_PRIVATE,
KEY_V6_MLDSA65_ED25519_PRIVATE,

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, OK, we still download the fixture keys here.

@dralleydralley changed the title [do not merge] PQC support via new pysequoia versionPQC support via new pysequoia versionAug 30, 2026
@dralley
dralley marked this pull request as ready for review August 30, 2026 16:27
Rebase the minimum bound of pysequoia to one which adds support for
post-quantum cryptography / RFC 9980.
Add tests for gpg_verify function and PQC signing services
Assisted-By: Claude Sonnet 4.5
]


@pytest.fixture(params=TEST_KEYS, ids=[k[0] for k in TEST_KEYS], scope="module")

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think these tests have some value, because they do test our own API wrapper around pysequoia, but if you think they (or any individual test(s) are) more of a glorified pysequoia unit test, I can drop it.

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alternatively we can deprecate the gpg_verify function completely and remove it in the next breaking change release, because it's only a thin wrapper around pysequoia anyway, which plugins could just use directly if they wanted to.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, didn't we keep the interface of gpg_verify stable with this change? Then it already won. Why would we remove it?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It predated having any kind of usable library for this purpose - python-gnupg was kind of a pain to use because you had to set up ephemeral directories all the time - at this point the wrapper is probably not needed.

Of course we did keep the API stable anyway, but that doesn't mean we can't move away from it over the longer term. Question is just whether we ought to mark it deprecated or not.

@dralley
dralley requested a review from mdellwegAugust 30, 2026 16:39
Comment threadpyproject.toml
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia>=0.1.35,<0.2.0",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we know about the specific versioning policy here?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It hasn't been the most consistent. Personally I think it ought to have been a 0.2.0 release given the major changes, but there were no breaking changes at least.

@dralley
dralley merged commit c44c2d1 into pulp:mainAug 31, 2026
13 of 14 checks passed
@dralley
dralley deleted the update-pysequoia branch August 31, 2026 12:47
@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.105: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.105/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8025

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.116: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.116/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8026

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dralley@mdellweg
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
PQC support via new pysequoia version by dralley · Pull Request #8011 · pulp/pulpcore · GitHub
Skip to content

PQC support via new pysequoia version - #8011

Merged
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia
Aug 31, 2026
Merged

PQC support via new pysequoia version#8011
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia

Conversation

@dralley

Copy link
Copy Markdown
Contributor

Rebase the minimum bound of pysequoia to one which adds support for post-quantum cryptography / RFC 9980.

Add tests for gpg_verify function and PQC signing services

Assisted-By: Claude Sonnet 4.5

Comment threadpyproject.toml Outdated
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia @ git+https://github.com/wiktor-k/pysequoia.git",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not released yet, just testing the rest of the changes.

@dralley

dralley commented Aug 25, 2026

Copy link
Copy Markdown
ContributorAuthor

Using ephemeral keys turns out to be much faster than downloading keys from fixtures, 0.09s vs 5.38s. The exception is RSA which is slower (keygen is expensive by comparison to other algos) but I'm not adding any tests using RSA here.


from pulpcore.pytest_plugin import (
KEY_V4_RSA4K_PRIVATE,
KEY_V6_MLDSA65_ED25519_PRIVATE,

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, OK, we still download the fixture keys here.

@dralleydralley changed the title [do not merge] PQC support via new pysequoia versionPQC support via new pysequoia versionAug 30, 2026
@dralley
dralley marked this pull request as ready for review August 30, 2026 16:27
Rebase the minimum bound of pysequoia to one which adds support for
post-quantum cryptography / RFC 9980.
Add tests for gpg_verify function and PQC signing services
Assisted-By: Claude Sonnet 4.5
]


@pytest.fixture(params=TEST_KEYS, ids=[k[0] for k in TEST_KEYS], scope="module")

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think these tests have some value, because they do test our own API wrapper around pysequoia, but if you think they (or any individual test(s) are) more of a glorified pysequoia unit test, I can drop it.

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alternatively we can deprecate the gpg_verify function completely and remove it in the next breaking change release, because it's only a thin wrapper around pysequoia anyway, which plugins could just use directly if they wanted to.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, didn't we keep the interface of gpg_verify stable with this change? Then it already won. Why would we remove it?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It predated having any kind of usable library for this purpose - python-gnupg was kind of a pain to use because you had to set up ephemeral directories all the time - at this point the wrapper is probably not needed.

Of course we did keep the API stable anyway, but that doesn't mean we can't move away from it over the longer term. Question is just whether we ought to mark it deprecated or not.

@dralley
dralley requested a review from mdellwegAugust 30, 2026 16:39
Comment threadpyproject.toml
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia>=0.1.35,<0.2.0",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we know about the specific versioning policy here?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It hasn't been the most consistent. Personally I think it ought to have been a 0.2.0 release given the major changes, but there were no breaking changes at least.

@dralley
dralley merged commit c44c2d1 into pulp:mainAug 31, 2026
13 of 14 checks passed
@dralley
dralley deleted the update-pysequoia branch August 31, 2026 12:47
@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.105: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.105/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8025

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.116: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.116/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8026

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dralley@mdellweg
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' PQC support via new pysequoia version by dralley · Pull Request #8011 · pulp/pulpcore · GitHub
Skip to content

PQC support via new pysequoia version - #8011

Merged
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia
Aug 31, 2026
Merged

PQC support via new pysequoia version#8011
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia

Conversation

@dralley

Copy link
Copy Markdown
Contributor

Rebase the minimum bound of pysequoia to one which adds support for post-quantum cryptography / RFC 9980.

Add tests for gpg_verify function and PQC signing services

Assisted-By: Claude Sonnet 4.5

Comment threadpyproject.toml Outdated
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia @ git+https://github.com/wiktor-k/pysequoia.git",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not released yet, just testing the rest of the changes.

@dralley

dralley commented Aug 25, 2026

Copy link
Copy Markdown
ContributorAuthor

Using ephemeral keys turns out to be much faster than downloading keys from fixtures, 0.09s vs 5.38s. The exception is RSA which is slower (keygen is expensive by comparison to other algos) but I'm not adding any tests using RSA here.


from pulpcore.pytest_plugin import (
KEY_V4_RSA4K_PRIVATE,
KEY_V6_MLDSA65_ED25519_PRIVATE,

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, OK, we still download the fixture keys here.

@dralleydralley changed the title [do not merge] PQC support via new pysequoia versionPQC support via new pysequoia versionAug 30, 2026
@dralley
dralley marked this pull request as ready for review August 30, 2026 16:27
Rebase the minimum bound of pysequoia to one which adds support for
post-quantum cryptography / RFC 9980.
Add tests for gpg_verify function and PQC signing services
Assisted-By: Claude Sonnet 4.5
]


@pytest.fixture(params=TEST_KEYS, ids=[k[0] for k in TEST_KEYS], scope="module")

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think these tests have some value, because they do test our own API wrapper around pysequoia, but if you think they (or any individual test(s) are) more of a glorified pysequoia unit test, I can drop it.

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alternatively we can deprecate the gpg_verify function completely and remove it in the next breaking change release, because it's only a thin wrapper around pysequoia anyway, which plugins could just use directly if they wanted to.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, didn't we keep the interface of gpg_verify stable with this change? Then it already won. Why would we remove it?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It predated having any kind of usable library for this purpose - python-gnupg was kind of a pain to use because you had to set up ephemeral directories all the time - at this point the wrapper is probably not needed.

Of course we did keep the API stable anyway, but that doesn't mean we can't move away from it over the longer term. Question is just whether we ought to mark it deprecated or not.

@dralley
dralley requested a review from mdellwegAugust 30, 2026 16:39
Comment threadpyproject.toml
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia>=0.1.35,<0.2.0",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we know about the specific versioning policy here?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It hasn't been the most consistent. Personally I think it ought to have been a 0.2.0 release given the major changes, but there were no breaking changes at least.

@dralley
dralley merged commit c44c2d1 into pulp:mainAug 31, 2026
13 of 14 checks passed
@dralley
dralley deleted the update-pysequoia branch August 31, 2026 12:47
@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.105: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.105/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8025

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.116: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.116/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8026

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dralley@mdellweg
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' PQC support via new pysequoia version by dralley · Pull Request #8011 · pulp/pulpcore · GitHub
Skip to content

PQC support via new pysequoia version - #8011

Merged
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia
Aug 31, 2026
Merged

PQC support via new pysequoia version#8011
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia

Conversation

@dralley

Copy link
Copy Markdown
Contributor

Rebase the minimum bound of pysequoia to one which adds support for post-quantum cryptography / RFC 9980.

Add tests for gpg_verify function and PQC signing services

Assisted-By: Claude Sonnet 4.5

Comment threadpyproject.toml Outdated
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia @ git+https://github.com/wiktor-k/pysequoia.git",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not released yet, just testing the rest of the changes.

@dralley

dralley commented Aug 25, 2026

Copy link
Copy Markdown
ContributorAuthor

Using ephemeral keys turns out to be much faster than downloading keys from fixtures, 0.09s vs 5.38s. The exception is RSA which is slower (keygen is expensive by comparison to other algos) but I'm not adding any tests using RSA here.


from pulpcore.pytest_plugin import (
KEY_V4_RSA4K_PRIVATE,
KEY_V6_MLDSA65_ED25519_PRIVATE,

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, OK, we still download the fixture keys here.

@dralleydralley changed the title [do not merge] PQC support via new pysequoia versionPQC support via new pysequoia versionAug 30, 2026
@dralley
dralley marked this pull request as ready for review August 30, 2026 16:27
Rebase the minimum bound of pysequoia to one which adds support for
post-quantum cryptography / RFC 9980.
Add tests for gpg_verify function and PQC signing services
Assisted-By: Claude Sonnet 4.5
]


@pytest.fixture(params=TEST_KEYS, ids=[k[0] for k in TEST_KEYS], scope="module")

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think these tests have some value, because they do test our own API wrapper around pysequoia, but if you think they (or any individual test(s) are) more of a glorified pysequoia unit test, I can drop it.

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alternatively we can deprecate the gpg_verify function completely and remove it in the next breaking change release, because it's only a thin wrapper around pysequoia anyway, which plugins could just use directly if they wanted to.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, didn't we keep the interface of gpg_verify stable with this change? Then it already won. Why would we remove it?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It predated having any kind of usable library for this purpose - python-gnupg was kind of a pain to use because you had to set up ephemeral directories all the time - at this point the wrapper is probably not needed.

Of course we did keep the API stable anyway, but that doesn't mean we can't move away from it over the longer term. Question is just whether we ought to mark it deprecated or not.

@dralley
dralley requested a review from mdellwegAugust 30, 2026 16:39
Comment threadpyproject.toml
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia>=0.1.35,<0.2.0",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we know about the specific versioning policy here?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It hasn't been the most consistent. Personally I think it ought to have been a 0.2.0 release given the major changes, but there were no breaking changes at least.

@dralley
dralley merged commit c44c2d1 into pulp:mainAug 31, 2026
13 of 14 checks passed
@dralley
dralley deleted the update-pysequoia branch August 31, 2026 12:47
@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.105: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.105/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8025

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.116: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.116/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8026

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dralley@mdellweg
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' PQC support via new pysequoia version by dralley · Pull Request #8011 · pulp/pulpcore · GitHub
Skip to content

PQC support via new pysequoia version - #8011

Merged
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia
Aug 31, 2026
Merged

PQC support via new pysequoia version#8011
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia

Conversation

@dralley

Copy link
Copy Markdown
Contributor

Rebase the minimum bound of pysequoia to one which adds support for post-quantum cryptography / RFC 9980.

Add tests for gpg_verify function and PQC signing services

Assisted-By: Claude Sonnet 4.5

Comment threadpyproject.toml Outdated
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia @ git+https://github.com/wiktor-k/pysequoia.git",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not released yet, just testing the rest of the changes.

@dralley

dralley commented Aug 25, 2026

Copy link
Copy Markdown
ContributorAuthor

Using ephemeral keys turns out to be much faster than downloading keys from fixtures, 0.09s vs 5.38s. The exception is RSA which is slower (keygen is expensive by comparison to other algos) but I'm not adding any tests using RSA here.


from pulpcore.pytest_plugin import (
KEY_V4_RSA4K_PRIVATE,
KEY_V6_MLDSA65_ED25519_PRIVATE,

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, OK, we still download the fixture keys here.

@dralleydralley changed the title [do not merge] PQC support via new pysequoia versionPQC support via new pysequoia versionAug 30, 2026
@dralley
dralley marked this pull request as ready for review August 30, 2026 16:27
Rebase the minimum bound of pysequoia to one which adds support for
post-quantum cryptography / RFC 9980.
Add tests for gpg_verify function and PQC signing services
Assisted-By: Claude Sonnet 4.5
]


@pytest.fixture(params=TEST_KEYS, ids=[k[0] for k in TEST_KEYS], scope="module")

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think these tests have some value, because they do test our own API wrapper around pysequoia, but if you think they (or any individual test(s) are) more of a glorified pysequoia unit test, I can drop it.

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alternatively we can deprecate the gpg_verify function completely and remove it in the next breaking change release, because it's only a thin wrapper around pysequoia anyway, which plugins could just use directly if they wanted to.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, didn't we keep the interface of gpg_verify stable with this change? Then it already won. Why would we remove it?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It predated having any kind of usable library for this purpose - python-gnupg was kind of a pain to use because you had to set up ephemeral directories all the time - at this point the wrapper is probably not needed.

Of course we did keep the API stable anyway, but that doesn't mean we can't move away from it over the longer term. Question is just whether we ought to mark it deprecated or not.

@dralley
dralley requested a review from mdellwegAugust 30, 2026 16:39
Comment threadpyproject.toml
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia>=0.1.35,<0.2.0",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we know about the specific versioning policy here?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It hasn't been the most consistent. Personally I think it ought to have been a 0.2.0 release given the major changes, but there were no breaking changes at least.

@dralley
dralley merged commit c44c2d1 into pulp:mainAug 31, 2026
13 of 14 checks passed
@dralley
dralley deleted the update-pysequoia branch August 31, 2026 12:47
@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.105: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.105/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8025

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.116: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.116/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8026

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dralley@mdellweg
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' PQC support via new pysequoia version by dralley · Pull Request #8011 · pulp/pulpcore · GitHub
Skip to content

PQC support via new pysequoia version - #8011

Merged
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia
Aug 31, 2026
Merged

PQC support via new pysequoia version#8011
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia

Conversation

@dralley

Copy link
Copy Markdown
Contributor

Rebase the minimum bound of pysequoia to one which adds support for post-quantum cryptography / RFC 9980.

Add tests for gpg_verify function and PQC signing services

Assisted-By: Claude Sonnet 4.5

Comment threadpyproject.toml Outdated
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia @ git+https://github.com/wiktor-k/pysequoia.git",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not released yet, just testing the rest of the changes.

@dralley

dralley commented Aug 25, 2026

Copy link
Copy Markdown
ContributorAuthor

Using ephemeral keys turns out to be much faster than downloading keys from fixtures, 0.09s vs 5.38s. The exception is RSA which is slower (keygen is expensive by comparison to other algos) but I'm not adding any tests using RSA here.


from pulpcore.pytest_plugin import (
KEY_V4_RSA4K_PRIVATE,
KEY_V6_MLDSA65_ED25519_PRIVATE,

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, OK, we still download the fixture keys here.

@dralleydralley changed the title [do not merge] PQC support via new pysequoia versionPQC support via new pysequoia versionAug 30, 2026
@dralley
dralley marked this pull request as ready for review August 30, 2026 16:27
Rebase the minimum bound of pysequoia to one which adds support for
post-quantum cryptography / RFC 9980.
Add tests for gpg_verify function and PQC signing services
Assisted-By: Claude Sonnet 4.5
]


@pytest.fixture(params=TEST_KEYS, ids=[k[0] for k in TEST_KEYS], scope="module")

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think these tests have some value, because they do test our own API wrapper around pysequoia, but if you think they (or any individual test(s) are) more of a glorified pysequoia unit test, I can drop it.

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alternatively we can deprecate the gpg_verify function completely and remove it in the next breaking change release, because it's only a thin wrapper around pysequoia anyway, which plugins could just use directly if they wanted to.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, didn't we keep the interface of gpg_verify stable with this change? Then it already won. Why would we remove it?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It predated having any kind of usable library for this purpose - python-gnupg was kind of a pain to use because you had to set up ephemeral directories all the time - at this point the wrapper is probably not needed.

Of course we did keep the API stable anyway, but that doesn't mean we can't move away from it over the longer term. Question is just whether we ought to mark it deprecated or not.

@dralley
dralley requested a review from mdellwegAugust 30, 2026 16:39
Comment threadpyproject.toml
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia>=0.1.35,<0.2.0",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we know about the specific versioning policy here?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It hasn't been the most consistent. Personally I think it ought to have been a 0.2.0 release given the major changes, but there were no breaking changes at least.

@dralley
dralley merged commit c44c2d1 into pulp:mainAug 31, 2026
13 of 14 checks passed
@dralley
dralley deleted the update-pysequoia branch August 31, 2026 12:47
@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.105: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.105/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8025

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.116: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.116/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8026

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dralley@mdellweg
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' PQC support via new pysequoia version by dralley · Pull Request #8011 · pulp/pulpcore · GitHub
Skip to content

PQC support via new pysequoia version - #8011

Merged
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia
Aug 31, 2026
Merged

PQC support via new pysequoia version#8011
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia

Conversation

@dralley

Copy link
Copy Markdown
Contributor

Rebase the minimum bound of pysequoia to one which adds support for post-quantum cryptography / RFC 9980.

Add tests for gpg_verify function and PQC signing services

Assisted-By: Claude Sonnet 4.5

Comment threadpyproject.toml Outdated
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia @ git+https://github.com/wiktor-k/pysequoia.git",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not released yet, just testing the rest of the changes.

@dralley

dralley commented Aug 25, 2026

Copy link
Copy Markdown
ContributorAuthor

Using ephemeral keys turns out to be much faster than downloading keys from fixtures, 0.09s vs 5.38s. The exception is RSA which is slower (keygen is expensive by comparison to other algos) but I'm not adding any tests using RSA here.


from pulpcore.pytest_plugin import (
KEY_V4_RSA4K_PRIVATE,
KEY_V6_MLDSA65_ED25519_PRIVATE,

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, OK, we still download the fixture keys here.

@dralleydralley changed the title [do not merge] PQC support via new pysequoia versionPQC support via new pysequoia versionAug 30, 2026
@dralley
dralley marked this pull request as ready for review August 30, 2026 16:27
Rebase the minimum bound of pysequoia to one which adds support for
post-quantum cryptography / RFC 9980.
Add tests for gpg_verify function and PQC signing services
Assisted-By: Claude Sonnet 4.5
]


@pytest.fixture(params=TEST_KEYS, ids=[k[0] for k in TEST_KEYS], scope="module")

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think these tests have some value, because they do test our own API wrapper around pysequoia, but if you think they (or any individual test(s) are) more of a glorified pysequoia unit test, I can drop it.

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alternatively we can deprecate the gpg_verify function completely and remove it in the next breaking change release, because it's only a thin wrapper around pysequoia anyway, which plugins could just use directly if they wanted to.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, didn't we keep the interface of gpg_verify stable with this change? Then it already won. Why would we remove it?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It predated having any kind of usable library for this purpose - python-gnupg was kind of a pain to use because you had to set up ephemeral directories all the time - at this point the wrapper is probably not needed.

Of course we did keep the API stable anyway, but that doesn't mean we can't move away from it over the longer term. Question is just whether we ought to mark it deprecated or not.

@dralley
dralley requested a review from mdellwegAugust 30, 2026 16:39
Comment threadpyproject.toml
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia>=0.1.35,<0.2.0",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we know about the specific versioning policy here?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It hasn't been the most consistent. Personally I think it ought to have been a 0.2.0 release given the major changes, but there were no breaking changes at least.

@dralley
dralley merged commit c44c2d1 into pulp:mainAug 31, 2026
13 of 14 checks passed
@dralley
dralley deleted the update-pysequoia branch August 31, 2026 12:47
@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.105: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.105/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8025

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.116: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.116/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8026

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dralley@mdellweg
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); PQC support via new pysequoia version by dralley · Pull Request #8011 · pulp/pulpcore · GitHub
Skip to content

PQC support via new pysequoia version - #8011

Merged
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia
Aug 31, 2026
Merged

PQC support via new pysequoia version#8011
dralley merged 1 commit into
pulp:mainfrom
dralley:update-pysequoia

Conversation

@dralley

Copy link
Copy Markdown
Contributor

Rebase the minimum bound of pysequoia to one which adds support for post-quantum cryptography / RFC 9980.

Add tests for gpg_verify function and PQC signing services

Assisted-By: Claude Sonnet 4.5

Comment threadpyproject.toml Outdated
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia @ git+https://github.com/wiktor-k/pysequoia.git",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not released yet, just testing the rest of the changes.

@dralley

dralley commented Aug 25, 2026

Copy link
Copy Markdown
ContributorAuthor

Using ephemeral keys turns out to be much faster than downloading keys from fixtures, 0.09s vs 5.38s. The exception is RSA which is slower (keygen is expensive by comparison to other algos) but I'm not adding any tests using RSA here.


from pulpcore.pytest_plugin import (
KEY_V4_RSA4K_PRIVATE,
KEY_V6_MLDSA65_ED25519_PRIVATE,

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, OK, we still download the fixture keys here.

@dralleydralley changed the title [do not merge] PQC support via new pysequoia versionPQC support via new pysequoia versionAug 30, 2026
@dralley
dralley marked this pull request as ready for review August 30, 2026 16:27
Rebase the minimum bound of pysequoia to one which adds support for
post-quantum cryptography / RFC 9980.
Add tests for gpg_verify function and PQC signing services
Assisted-By: Claude Sonnet 4.5
]


@pytest.fixture(params=TEST_KEYS, ids=[k[0] for k in TEST_KEYS], scope="module")

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think these tests have some value, because they do test our own API wrapper around pysequoia, but if you think they (or any individual test(s) are) more of a glorified pysequoia unit test, I can drop it.

@dralleydralleyAug 30, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alternatively we can deprecate the gpg_verify function completely and remove it in the next breaking change release, because it's only a thin wrapper around pysequoia anyway, which plugins could just use directly if they wanted to.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, didn't we keep the interface of gpg_verify stable with this change? Then it already won. Why would we remove it?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It predated having any kind of usable library for this purpose - python-gnupg was kind of a pain to use because you had to set up ephemeral directories all the time - at this point the wrapper is probably not needed.

Of course we did keep the API stable anyway, but that doesn't mean we can't move away from it over the longer term. Question is just whether we ought to mark it deprecated or not.

@dralley
dralley requested a review from mdellwegAugust 30, 2026 16:39
Comment threadpyproject.toml
"psycopg[binary]>=3.3.4,<3.4", # SemVer, not explicitely stated, but mentioned on multiple changes.
"pyparsing>=3.1.0,<3.4", # Looks like only bugfixes in z-Stream.
"pysequoia>=0.1.33,<0.2",
"pysequoia>=0.1.35,<0.2.0",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we know about the specific versioning policy here?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It hasn't been the most consistent. Personally I think it ought to have been a 0.2.0 release given the major changes, but there were no breaking changes at least.

@dralley
dralley merged commit c44c2d1 into pulp:mainAug 31, 2026
13 of 14 checks passed
@dralley
dralley deleted the update-pysequoia branch August 31, 2026 12:47
@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.105: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.105/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8025

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

@patchback

patchbackBot commented Aug 31, 2026

Copy link
Copy Markdown

Backport to 3.116: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.116/c44c2d18da0b9b73793bd3a8ad2388db5fc4199d/pr-8011

Backported as #8026

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dralley@mdellweg