I should point out that there is a very obvious "fix" here:
Rip out the code in lib/verify.c that attempts to verify signatures.
This is new functionality in rpm-5.4 (that was back ported to rpm-5.3).
There's no reason why the code MUST be included in Mandriva/ROSA
for any reason that I am aware of.
The code WILL be repaired as part of mandatory signature checking
and multithreading, if those "features" survive into ROSA 2012 deliverables
(the features are ESSENTIAL in @rpm5.org ROADMAP's).
I should point out that there is a very obvious "fix" here:
Rip out the code in lib/verify.c that attempts to verify signatures.
This is new functionality in rpm-5.4 (that was back ported to rpm-5.3).
There's no reason why the code MUST be included in Mandriva/ROSA
for any reason that I am aware of.
The code WILL be repaired as part of mandatory signature checking
and multithreading, if those "features" survive into ROSA 2012 deliverables
(the features are ESSENTIAL in @rpm5.org ROADMAP's).