2026-09-22  Werner Koch  <wk@gnupg.org>

	Release 2.5.23.
	+ commit 3f25cf821b4c4c59e4b73225087e5d1291e60d43


2026-09-22  NIIBE Yutaka  <gniibe@fsij.org>

	common: Fix composite DO parsing.
	+ commit 19d46956c34e3ec3374cd5fde6082f6aaf93fa71
	* common/tlv.c (do_find_tlv): Don't forget the maximum length to N
	when call it recursively.

	dirmngr: Add another validation in get_dns_cert_standard.
	+ commit 43a74a96ad25245ab564bd41a9169ea71744fc83
	* dirmngr/dns-stuff.c (get_dns_cert_standard): Add a validation just
	like get_dns_cert_libdns does.

2026-09-21  Werner Koch  <wk@gnupg.org>

	dirmngr: Add a mitigation for badly configured web key directories.
	+ commit bc7686ad7ca7fd71df83ca2f761b3f8c854043e5
	* dirmngr/server.c (proc_wkd_get): Retry if the subdomain mode failed
	with WRONG_NAME.

2026-09-18  Werner Koch  <wk@gnupg.org>

	gpg: Minor code fix for correctness.
	+ commit eb9d633dd4f75713169446988400882965170caa
	* g10/sign.c (mk_notation_policy_etc): Fix wrong code.  However it ND
	  was not used after that.

2026-09-17  Werner Koch  <wk@gnupg.org>

	gpg: Avoid wrong compiler warning.
	+ commit 0c67fae17343478b2ae7f9bc0df4b2c38915e9c2
	* g10/pkglue.c (do_encrypt_kem): Init variable.

	gpgconf: Print more info from VERSION if found.
	+ commit 7211ecc4121fb0e44719615a094a6ac3f03e42fd
	* tools/gpgconf.c (show_version_gnupg): Print more info.

2026-09-15  NIIBE Yutaka  <gniibe@fsij.org>

	scd:p15: Fix use of log_info.
	+ commit 556d109de767906856fb6cf19c2491b6276e4692
	* scd/app-p15.c (micardo_mse): Fix arguments to call log_info.

	gpgsm: Fix typo for debug output.
	+ commit 160fa97c10d7229e2ced978dc168fdcb5bf6a00b
	* sm/certcheck.c (gpgsm_check_cert_sig): Use log_printhex.

2026-09-14  Werner Koch  <wk@gnupg.org>

	Allow gettime.c to be build with -Wformat-nonliteral.
	+ commit 98871aadb70378343541128e80ffd391e413e248
	* configure.ac (mycflags): Add -Wformat-nonliteral.
	* common/gettime.c (asctimestamp): Factor code out to ...
	(format_time_nl_langinfo): new.  Disable the format-nonliteral
	warning.  Add a static initialization.

2026-09-11  Werner Koch  <wk@gnupg.org>

	gpg: Implictly set allow-9980 in de-vs compliance mode.
	+ commit 68558102f8a23a2af14ed96571144dab1c9e95c1
	* g10/gpg.c (set_compliance_option): Enable 9980 in de-vs mode.

	gpg: Always allow parsing of rfc-9980 packets.
	+ commit 925fa2b11cf676a6127aff2ea0c95c2360aa9dc5
	* g10/build-packet.c (do_key): Do not require --allow-9980 to write the
	  key.
	* g10/parse-packet.c (RFC9980): Do not require --allow-9980 to parse
	  key packets.

2026-09-10  Werner Koch  <wk@gnupg.org>

	gpgconf: Print the content of a versioninfo.txt file in verbose mode.
	+ commit e5251910f6290b3e61918534d967970e17805287
	* tools/gpgconf.c (show_versioninfo_txt): New.
	(show_versions): Call it in verbose mode.

2026-09-09  Werner Koch  <wk@gnupg.org>

	tests: Add a test for the new Brainpool and NIST 9980 encryption.
	+ commit fcc9b4d1841d3cf13a59f687450fe053c8e55f76
	* tests/openpgp/encrypt-mlk.scm: New.
	* tests/openpgp/defs.scm (create-gpghome): Make it a wrapper for ...
	(create-gpghome-with-mode): this.  Optionally add allow-9980.
	(setup-9980-environment): New.
	* tests/openpgp/privkeys/: Add 9 new private keys for the recently
	  added MLK public keys.
	* tests/openpgp/samplemsgs/: Add 4 samples for the new subkeys.

	gpg: New debug option to get the secret key as s-expression.
	+ commit 1e0261fe50089bbfd0bb9a8d0e3dfe2408a3d134
	* g10/options.h (LIST_DEBUG_SHOW_SEXP): New.
	* g10/gpg.c (parse_list_options): Add "debug-show-sexp".
	* g10/import.c (seckey_packet_to_nvc): New.  Add stubs as needed to
	  other modules.
	* g10/parse-packet.c (parse_key): Output the secret key in list mode
	  if the new options is used.

	gpg: Add Brainpool and NIST as specified by an RFC-9980 update.
	+ commit ab00af1cb8b1db599bebb397f4fb90696bbe3ffb
	* common/openpgpdefs.h (pubkey_algo_t): Add constants for algorithm
	  numbers proposed for the rfc-9980 update.  Also reserve one for
	  Dilithium.
	(IS_PUBKEY_ALGO_MLK768): New.
	(IS_PUBKEY_ALGO_MLK1024): New.
	(IS_PUBKEY_ALGO_MLK): New.
	* g10/misc.c (openpgp_pk_test_algo2): Add the new MLK algos.
	(openpgp_pk_algo_usage): Ditto.
	(openpgp_pk_algo_name): Ditto.
	(pubkey_get_npkey): Ditto.
	(pubkey_get_nskey): Ditto.
	(pubkey_get_nenc): Ditto.
	* g10/keyid.c (pubkey_string): Ditto.
	(keygrip_from_pk): Ditto.  Simplify by using the new macros.
	(hexkeygrip_from_pk): Simplify.
	* g10/pkglue.c (do_encrypt_kem): Use the new macros to handle the new
	  MLK algos.  Map the new algos to ECC curve names.
	(pk_encrypt): Support all MLK algos.
	* g10/pubkey-enc.c (get_session_key): Ditto.
	(get_it): Ditto.
	* g10/seskey.c (encode_session_key): Ditto.
	* g10/encrypt.c (create_dek_with_warnings): Ditto.
	(use_rfc9980_seipdv2): Ditto.
	(write_pubkey_enc): Ditto.
	* g10/keygen.c (PQC9980_STD_KEY_PARAM_SUB): Change to use mlk768_bp384.
	(ecckey_from_sexp): Support all MLK algos.
	(common_gen): Ditto.
	(gen_kyber): Add parameters for the new algos.
	(get_keysize_range): Support the new algos.
	(fixup_keysize): Support all MLK algos.
	(do_create): Ditto.
	(parse_key_parameter_part): Fix "mlk768" input to use "ietf25".  Add
	parameters for the new  MLK algos.
	* g10/import.c (build_mode1003_sexp): Support the new MLK algos.
	* g10/parse-packet.c (parse_pubkeyenc): Add support for the new MLK
	  algos.
	(parse_key): Ditto.
	* kbx/keybox-openpgp.c (keygrip_from_keyparm): Ditto.
	(parse_key): Ditto.
	* g10/build-packet.c (do_key): Ditto.
	(do_pubkey_enc_v6): Ditto.

2026-09-08  Werner Koch  <wk@gnupg.org>

	gpg: Improve debug diagnostics for invalid packets.
	+ commit f5f3c8d448d7e06c0421ae6d71ff0c7b3427e04a
	* g10/parse-packet.c (parse): print extra infor for an invalid packet
	  in double verbose mode.

2026-09-02  Werner Koch  <wk@gnupg.org>

	gpg: New --edit-key command "addpubkey"
	+ commit e835a43201014c04702eb9bd6b827cf4ae2569fc
	* g10/keyedit.c (cmdADDPUBKEY): New.
	(cmds): Add "addpubkey".
	(keyedit_menu): Implement.

	gpgconf,w32: Show more registry key of GpgOL.
	+ commit 53ee642e2cc10b6a0bcb69c6d3f788deef2eac7a
	* tools/gpgconf.c (show_other_registry_entries): Add more keys.

2026-09-02  NIIBE Yutaka  <gniibe@fsij.org>

	scd: Add Nitrokey 3 to pcsc-shared interference detection.
	+ commit bb7113d03dfc971cacdaae1c0e8fffc2ea21e5df
	* scd/app-common.h (CARDTYPE_NITROKEY): New.
	* scd/app-openpgp.c (do_reselect): It's only for Yubikey or Nitrokey.
	* scd/app-piv.c (struct app_local_s): Add nitrokey flag field.
	(do_reselect): It's only for Yubikey or Nitrokey.
	(app_select_piv): Check CARDTYPE_NITROKEY for the flag.
	* scd/app.c (strcardtype): Support CARDTYPE_NITROKEY.
	(check_application_conflict): Support CARDTYPE_NITROKEY.
	(app_new_register): Add detection of Nitrokey.
	(select_all_additional_applications_internal): Support
	CARDTYPE_NITROKEY.
	(check_external_interference): Likewise.

2026-09-02  Werner Koch  <wk@gnupg.org>

	dirmngr: Make the LDAP upload flags also work for KS_SEARCH.
	+ commit a6ed9bc75d8fba512972ca7612764389091acef2
	* dirmngr/ks-action.c (ks_action_search): Detect and skip upload only
	  server.

2026-08-31  Werner Koch  <wk@gnupg.org>

	Release 2.5.22.
	+ commit bd253e9fecedd4c0e699530826ee43264581634b


2026-08-26  Philip Le  <philip.le@gnupg.com>

	gpgsm: Fix condition for de-vs compliance status line.
	+ commit a09f16f2b17a47b3f215e2d257ef256f3b2b724e
	* sm/decrypt.c (gpgsm_decrypt): Also check other conditions for de-vs
	compliance before emitting status line.

2026-08-25  Philip Le  <philip.le@gnupg.com>

	gpgsm: Check keyboxd usage in keydb_get_flags.
	+ commit e338ea3de2d151fe718c11d7dcd2a2178b10a22e
	* sm/keydb.c (keydb_get_flags): Add condition that keyboxd is not
	used.

2026-08-25  Werner Koch  <wk@gnupg.org>

	gpg: Improve rfc9980 Kyber import.
	+ commit edae425c2a8ec204d537520a3be2d238762a9da0
	* g10/import.c (build_mode1003_sexp): Factor MLK code out to ...
	(build_sexp_from_mlk): new.  Check public key consistence and use
	s-expression API.

2026-08-21  Werner Koch  <wk@gnupg.org>

	gpgconf: Print a warning on Windows on insufficent /etc permissions.
	+ commit 56eb3148c7b88eb1c0804141b58cb54b9007f48d
	* README (Securing the global config files on Windows): New.

	* tools/gpgconf.c [W32]: Include aclapi.h.
	(enum cmd_and_opt_values): Add oDebug.
	(opts): Add option --debug.
	(debug_flags): New.
	(main): Parse debug flags.
	(w32_get_file_integrity_level) [W32]: New.
	(show_configs) [W32]: Check permissions of the gloab sysconfdir
	* tools/gpgconf.h (opt): Add field 'debug'.
	(DBG_W32_API): New.

2026-08-18  Philip Le  <philip.le@gnupg.com>

	gpg: Emit status line for failed write.
	+ commit 09ac242827c3bd002da2ff9d693a2db646d4e386
	* g10/plaintext.c (handle_plaintext): Emit error location and code in
	failure status.

2026-08-12  Philip Le  <philip.le@gnupg.com>
	    Werner Koch  <wk@gnupg.org>

	gpg: Fix regression introduced by partial file guards.
	+ commit 1b8debd65baaa05250ce26079fad15ac7bb16bd5
	* g10/main.h (gnupg_rollback_partial_file): New. Removes .part files.
	(gnupg_commit_partial_file): New. Renames .part files.
	* g10/misc.c (gnupg_rollback_partial_file): New.
	(gnupg_commit_partial_file): New.
	* g10/mainproc.c (proc_encrypted): Use gnupg_commit_partial_file.
	* g10/gpg.c (g10_exit): Use gnupg_commit_partial_file.
	(main): Remove .part files if decryption fails.

2026-08-12  NIIBE Yutaka  <gniibe@fsij.org>

	common,gpg: Don't enable the partial file guard if already done.
	+ commit 95ad7f7a5165b96e1a39afe70b1b1092b9ab6f45
	* common/stringhelp.c (has_suffix): New.
	* common/stringhelp.h (has_suffix): New.
	* g10/plaintext.c (get_output_file): Only enable the partial
	file guard when it doesn't have ".part" suffix.

2026-08-10  Werner Koch  <wk@gnupg.org>

	gpg: Fix TOFU trust models to actually check UTK signatures.
	+ commit 08611f5da8ad4b9cc80bb05f0f8610ec6baa6063
	* g10/tofu.c (signed_by_utk): Add arg ctrl.  Use macros fro the
	  sigclass.  Check the signature before returning true.

2026-08-06  Werner Koch  <wk@gnupg.org>

	gpg: Allow decryption of v4 keys using mlk768.
	+ commit f554e5ccd97fc6426746834c0c0b94e3887c7a5e
	* g10/parse-packet.c (parse_pubkeyenc): Fix for v4 mlk keys.  Support
	  mlk1024.

	gpg: Make sign and encrypt use the SEIPDv2.
	+ commit 81d1b088a332eab69c8fb3f7ca609fee1e558f5b
	* g10/encrypt.c (encrypt_crypt): Print a diagnostics if an rfc-9580
	  packet is used.
	(encrypt_filter): Setup for 9580 if needed.
	* g10/pubkey-enc.c (get_it): Take the session key algo from the pubkey
	  packet only if that has version 6.

	gpg: Make use of the new curve name "ietf25" in 9980 mode.
	+ commit 39b88c01e3ca908a34ce98ba0c1b00e16f0371f8
	* g10/pkglue.c (do_encrypt_kem): Replace Curve25519 by ietf25.  Move
	  the wipememory behind the gcry_kdf_close.
	* g10/import.c (build_mode1003_sexp): Replace Curve25519 by ietf25 for
	  X25519.  Add support for PUBKEY_ALGO_MLK1024_448.
	(internal_skey_object_to_sexp): Replace Curve25519 by ietf25 for
	  X25519.
	* kbx/keybox-openpgp.c (keygrip_from_keyparm): Ditto.
	* g10/keyid.c (keygrip_from_pk): Ditto.
	* g10/keygen.c (gen_ecc): Ditto.
	(gen_kyber): Ditto.
	* common/kem.c (ecc_table): Add curve ietf25.
	* common/openpgp-oid.c (oidtable): Ditto.  We use a new OID here
	  despite that RFC-9580 does not use an OID for this algo.  Our curve
	  registry however likes to have OIDs.

	gpg: Make GCM decryption work in fips mode.
	+ commit 18178bd06f83120255a2636e2ac125b83161e237
	* g10/decrypt-data.c (aead_set_nonce_and_ad): Add AEAD_ALGO_GCM.

2026-08-05  Werner Koch  <wk@gnupg.org>

	g13: Add sanity check on the syntax of the dmsetup algo string.
	+ commit 386c3e63b1cac7f506f974715dbf30c6d40663dd
	* g13/sh-dmcrypt.c (is_valid_algostr): New
	(sh_dmcrypt_mount_container): Use here
	(sh_dmcrypt_resume_container): and here.

	gpg: First take on adding a compliance mode "fips".
	+ commit 05c271f45a11db169d0171554cfc062bfa1beb5f
	* common/compliance.h (CO_FIPS): New.
	* common/compliance.c: Add basic support for CO_FIPS.
	(gnupg_pk_is_allowed): Factor code out to ...
	(gnupg_pk_is_allowed_de_vs): here and add
	(gnupg_pk_is_allowed_fips): new function.
	* common/openpgpdefs.h (AEAD_ALGO_GCM): New.
	* g10/cipher-aead.c (set_nonce_and_ad): Support GCM.
	* g10/options.h (GNUPG): Set macro also in FIPS mode.
	* g10/gpg.c (oFIPS): New.
	(gpgconf_list): Print a compliance_fips line.
	(compliance_options): Add "fips".
	(set_compliance_option): Set --allow-9980 in FIPS mode.
	* g10/keygen.c (write_keybinding): Provide fips compliance string.
	* g10/mainproc.c (check_sig_and_print): In require compliance mode
	  also fail in FIPS complaince mode.
	* g10/misc.c (openpgp_aead_test_algo): Support GCM.
	(openpgp_aead_algo_name): Ditto.
	(openpgp_aead_algo_info): Ditto.
	(compliance_failure): Add fips string.
	* g10/sign.c (mk_notation_policy_etc): Use value 140 for the "manu"
	  notation in FIPS mode.
	(write_signature_packets): Ditto.
	(make_keysig_packet): Ditto.
	* g10/encrypt.c (use_aead): In FIPS mode use GCM instead of OCB.
	* g10/pkclist.c (select_algo_from_prefs): For SHA256 in FIPS mode.

2026-08-04  Werner Koch  <wk@gnupg.org>

	gpg: Fix seipdv2 encryption using AES128.
	+ commit 987ba1a02add31af2f6bcd24c9fca68b38349b6e
	* g10/cipher-aead.c (write_header): Fix clearing the remainder of
	startiv.

	* tests/openpgp/encrypt-kyber.scm: Add test for AES variants.

2026-08-04  NIIBE Yutaka  <gniibe@fsij.org>

	gpg: Add a comment and minor fix for composing SEXP.
	+ commit e9b40fd1f0c0f6639c16346e895153561be93388
	* g10/import.c (internal_skey_object_to_sexp): Add comment.
	* g10/keyid.c (keygrip_from_pk): Compose correct SEXP with Ed448.

2026-08-02  Werner Koch  <wk@gnupg.org>

	gpg: Add import option debug-accept-no-uid for regression tests.
	+ commit 8f25dff5a65e0ea52025c3570d53bb362a876a97
	* g10/import.c (parse_import_options): Add option "debug-accept-no-uid".
	(import_one_real): Implement option.
	(import_secret_one): Ditto.

	gpg: Implement generation of ietf25 v6 keys.
	+ commit a94808489446902ecd523486a32d9cd7b521bbbb
	* common/kem.c (gnupg_ecc_kem_kdf): Replace arg is_pgp by kdf_algo and
	  adjust callers.
	* agent/pkdecrypt.c (ecc_kem_decrypt): Replace is_pgp by kemid.
	  Extract a new kdf_variant from the sexp and setup kdf_algo from it.
	  Add dedicated code path for the rfc9580 variant.
	(agent_kem_decrypt): Directly pass the kemid instead of the is_pgp
	flag.
	* common/compliance.c (gnupg_pk_is_compliant)
	(gnupg_pk_is_allowed): Add X25519.
	* common/openpgpdefs.h (pubkey_algo_t): Ditto.
	* kbx/keybox-openpgp.c (keygrip_from_keyparm): Support X25519.
	(parse_key): Ditto.
	* g10/parse-packet.c (parse_pubkeyenc, parse_key): Ditto.
	* g10/build-packet.c (do_key, do_pubkey_enc_v6): Ditto.
	* g10/call-agent.c (agent_pkdecrypt): Ditto.
	* g10/ecdh.c (ecc_build_kdf_params): Don't segv when called with wrong
	  algo.
	* g10/keyid.c (pubkey_string): Map X25519 to "ietf25".
	(keygrip_from_pk): Support X25519.
	* g10/misc.c (openpgp_pk_test_algo2): Ditto.
	(openpgp_pk_algo_usage, openpgp_pk_algo_name)
	(pubkey_get_npkey, pubkey_get_nskey): Ditto.
	* g10/encrypt.c (use_rfc9980_seipdv2, write_pubkey_enc): Ditto.
	* g10/pkglue.c (get_mpi_from_sexp_strip_0x40): New.
	(do_encrypt_kem): Support X25519.
	(pk_encrypt): Ditto.
	* g10/seskey.c (encode_session_key): Ditto.
	* g10/pubkey-enc.c (get_session_key): Ditto.
	(get_it): Ditto.  Move the special algo setup to the top.
	* g10/import.c (build_mode1003_sexp): Support X25519.
	(internal_skey_object_to_sexp): Ditto.
	* g10/keygen.c (ecckey_from_sexp): Add support for the MLK algos.
	(do_create_from_keygrip): Support ED25519.
	(common_gen): Support X25519 and the MLK algos.
	(gen_ecc): Support X25519.
	(gen_kyber): Support the MLK variants.
	(do_create): Support ED25519 and the MLK algos.
	(parse_key_parameter_part): Add parameter "ietf25".

2026-07-31  Werner Koch  <wk@gnupg.org>

	gpg,gpgsm,agent: New option --debug-no-libgcrypt.
	+ commit 48d6a8e60130e62291cea47ebd2564d4c78b2a2a
	* g10/gpg.c (oDebugNoLibgcrypt): New.
	(opts): Add --debug-no-libgcrypt
	(mopt): Add field no_libgcrypt_debug.
	(set_debug): Act upon it.
	(main): Set option.
	* agent/gpg-agent.c: Implement in the same way as above.
	* sm/gpgsm: Ditto.
	(cipher_algo_option_seen): Move to the new mopt struct.

2026-07-30  Philip Le  <philip.le@gnupg.com>
	    Werner Koch  <wk@gnupg.org>

	gpgsm: Emit issuer and serial no. when the certificate is not found.
	+ commit 82d5dc7782617cb7683b3769a3267e154ebdb067
	* doc/DETAILS: Update NO_PUBKEY for X.509 certificates.
	* sm/verify.c (gpgsm_verify): Print the issuer and serial no. of the
	signer's certificate when the certificate is not found.

2026-07-30  Philip Le  <philip.le@gnupg.com>

	gpg: Emit signing time as status output for bad signatures.
	+ commit e5acae48015751e21a04bf3113ba42d02c3db3f7
	* g10/mainproc.c (print_good_bad_signature): Emit signature creation
	time with STATUS_SIGINFO for bad signatures.

2026-07-30  Philip Le  <philip.le@gnupg.com>
	    Werner Koch  <wk@gnupg.org>

	gpgsm: Emit signing time as status output for bad signatures.
	+ commit 74305fa7d79700eb5ec03ab575260d640430bc71
	* common/status.h (enum): Add new STATUS_SIGINFO.
	* doc/DETAILS: Add description for new STATUS_SIGINFO.
	* sm/verify.c (gpgsm_verify): Add signature creation time with
	STATUS_SIGINFO for bad signatures.

2026-07-30  NIIBE Yutaka  <gniibe@fsij.org>

	scd: Allow switching APP when opt.pcsc_shared is enabled.
	+ commit f783c02525c3be9af14e84ec6456d4bde6018c74
	* scd/app.c (maybe_switch_app): Add opt.pcsc_shared condition.

2026-07-27  Werner Koch  <wk@gnupg.org>

	gpg: Implement generation of ietf27 v6 keys.
	+ commit cc68deb5f2d50a03fa92cee9d200ba83ae432961
	* g10/pkglue.c (get_r_s_mpi_from_sexp): New.
	* g10/keygen.c (PQC9980_STD_KEY_PARAM): New.
	(KEYGEN_FLAG_CREATE_V6_KEY): New.
	(ecckey_from_sexp): Support ED25519.
	(do_create_from_keygrip): Ditto.
	(common_gen): Support v6 key generation and ED25519.
	(gen_ecc): Support ED25519.
	(get_keysize_range): Add new algos.
	(fixup_keysize): Ditto.
	(do_create): Support ED25519.
	(parse_key_parameter_part): Add algonames mlk768, mlk1024, and
	ietf27.  Support ED25519 (aka ietf27).
	(parse_key_parameter_string): Support "pqc9980" as alternative default
	key parameters in rfc-9980 mode.
	(quick_generate_keypair): Ditto.

2026-07-26  Werner Koch  <wk@gnupg.org>

	gpg: Print a note for salted signatures.
	+ commit eb6dd6006db22b5139f97d33921424b63ad516b0
	* g10/mainproc.c (check_sig_and_print): Print note unless a weak hash
	  algo is used.

	common: Update compliance for new algos.
	+ commit 2d6d06a01ef42d2fce5e6e2182c0b0ba9289fc06
	* common/compliance.c (gnupg_pk_is_compliant): Add the newly
	implemented algorithms.
	(gnupg_pk_is_allowed) <DE_VS>: Allow the current MLK algorithms form
	decryption.

	gpg: Consider preferences from direct key signatures.
	+ commit 91357156096e8140e8d62121ea0f3f2f28dcc7ce
	* g10/packet.h (PKT_public_key): Add field 'dks_prefs'.
	* g10/free-packet.c (release_public_key_parts): Free dks_prefs.
	(copy_public_key_basics): Copy dks_prefs.
	* g10/pubkey-enc.c (is_algo_in_prefs): In rfc-9980 mode fallback to
	  preferences from direct key signatures.

	gpg: In rfc-9980 mode use the algo from the SEIPDv2 packet.
	+ commit 79ac1c50d96cbc6dd0bfe77c2a797c7a1566a152
	* g10/mainproc.c (proc_encrypted): Save the cipher algo from aa
	  SEIPDv2 packet and pass it to get_session_key.
	* g10/pubkey-enc.c (get_session_key): Add arg seipdv2_cipher_algo.
	(get_it): Ditto.  Use it in rfc-9980 mode for algo checks.

2026-07-24  Werner Koch  <wk@gnupg.org>

	gpg: Implement encryption according to rfc-9980.
	+ commit aa23856e154c1832e13ce999c605c3ebec3e09b3
	* g10/packet.h (PKT_pubkey_enc): Add fields fpr and fprlen.
	* g10/free-packet.c (copy_pubkey_enc_parts): Copy new fields.
	* g10/parse-packet.c (parse_pubkeyenc): Store the fingerprint.
	* g10/build-packet.c (do_pubkey_enc_v6): New.
	(do_pubkey_enc): Divert to v6 version.
	(do_encrypted_mdc): Implement version 2.
	* g10/misc.c (openpgp_pk_algo_name): Add MLK algos.
	* g10/seskey.c (encode_session_key): Handle MLK algos like Kyber.
	* g10/pkglue.c (pk_encrypt): Ditto.
	(do_encrypt_kem): Detect MLK algos and implement RFC-9980 encryption
	  scheme.
	* g10/filter.h (cipher_filter_context_t): Add field 'seipdv2'.
	* g10/encrypt.c (create_dek_with_warnings): Handle MLK algos like
	Kyber.
	(use_rfc9980_seipdv2): New.
	(encrypt_crypt): Request seipdv2 packet if use_rfc9980_seipdv2
	returned true.
	(write_pubkey_enc): Implement SEIPDV2.
	* g10/cipher-aead.c (set_nonce_and_ad): Implement the rfc9980 method.
	(write_header): Ditto.

2026-07-23  Werner Koch  <wk@gnupg.org>

	gpg: Handle RFC-9580 one-pass signatures.
	+ commit e951b3f7aceaf66010dc9762c59183632e1604a1
	* g10/packet.h (PKT_onepass_sig): Add fields 'salt' and 'version'.
	* g10/free-packet.c (free_onepass_sig): New.
	(free_packet): USe it here.
	* g10/parse-packet.c (parse_onepass_sig): Set version and parse and v6
	  salt and fingerprint.
	* g10/mainproc.c (proc_plaintext): For a v6 signature hash the salt
	  first.
	(proc_tree): Ditto.

2026-07-22  Werner Koch  <wk@gnupg.org>

	gpg: Implement the decryption of the v6 test message from rfc-9980.
	+ commit d0918e7a43e75e0ad290e9e6aa54b0318634320e
	* g10/packet.h (PKT_encrypted): Add flag 'seipd';
	* g10/parse-packet.c (parse_encrypted): Set it.
	(parse_encrypted_ocb): Clear it.

	* g10/decrypt-data.c (struct decode_filter_context_s): Add 'seipdv2'.
	(aead_set_nonce_and_ad): Handle AD for seipdv2.
	(aead_checktag): Improve debug messages.
	(decrypt_data): Implement seipdv2 encryption mode.

	gpg: Rename the PKT_ENCRYPTED_AEAD constant.
	+ commit fecd54252244afc77534b58ad2f3bf48a7f6fcd6
	* common/openpgpdefs.h (PKT_ENCRYPTED_AEAD): Rename to ...
	(PKT_ENCRYPTED_OCB): this.  Change all users.
	* g10/parse-packet.c (parse_encrypted_aeas): Rename to  ...
	(parse_encrypted_ocb): this.
	* g10/build-packet.c (do_encrypted_aead): Rename to ...
	(do_encrypted_ocb): this.

	gpg: Implement the decryption of the v4 test message from rfc-9980.
	+ commit d679550a6937b693a391ae1e199476e11e093c67
	* agent/pkdecrypt.c (ecc_extract_pk_from_key): Allow the use of plain
	  X25519 encryption keys, that is without the 0x40 prefix.  Return
	  BAD_PUBKEY instead of BAD_SECKEY.
	(ecc_extract_sk_from_key): Add arg no_reverse.
	(ecc_raw_kem): Ditto.
	(ecc_kem_decap): Add no_reverse arg.
	(composite_pgp_kem_decrypt): Support a new but optional s-expression
	parameter "t" to control which combiner shall be used.  Implement
	support for the RFC-9980 key combiner.

	* g10/misc.c (openpgp_pk_test_algo2): Support MLK768 and MLK1024 in
	  rfc9980 mode.
	(pubkey_get_nenc): Ditto.
	* g10/packet.h (PKT_encrypted): Add field 'version'.
	* g10/parse-packet.c (parse_pubkeyenc): Support v6 variant of this
	  packet.
	(parse_encrypted): Support v2 variant of this packet.
	(parse_encrypted_aead): Clear the new version field and set it to this
	 packet's version.
	* g10/pubkey-enc.c (get_session_key): Support MLK768 and MLK1024.
	(get_it): Ditto.  For now assume AES256 if a v6 pubkeyenc packet was
	used.

	common: Add new key combiner from RFC-9980.
	+ commit 52b9e54618f57002db3e219a5888e265b1c7d900
	* common/kem.c (gnupg_kem_combiner_sha3_256): New.

2026-07-21  NIIBE Yutaka  <gniibe@fsij.org>

	gpgsm: Fix keydb_get_flags with keyboxd.
	+ commit 766e9773cbc2a03d0392c2a2c94d0fe237741c5b
	* sm/keydb.c (struct keydb_handle): Add new field of last_is_revoked.
	(keydb_get_flag): Support keyboxd.
	(search_status_cb): Fill last_is_revoked field.

2026-07-20  Werner Koch  <wk@gnupg.org>

	gpg: Cleanup the use of read_octet_string in the parser.
	+ commit 3e3131727a6b226485883bf15e8094af560b0abf
	* g10/parse-packet.c (read_octet_string): Rename to
	  read_raw_octet_string and do not mark the result with the SOS flag.
	(read_sos_octet_string): New to replace the old read_octet_string.
	  Change callers.
	(parse_signature, parse_key): Use the raw version instead of clearing
	  the flag afterwards.  Also use it at a few otehr palces where we don't
	  have an SOS at all.

	* agent/command.c (cmd_import_key): Relax the unattended check for
	  mode1003.

	gpg: Get the keygrip right in gpg for the new MLKEM algos.
	+ commit dff43dae62eeec121d0385d2bb78afc3329357c6
	* g10/keyid.c (keygrip_from_pk): Fix the curve specs.

	gpg: Preliminary support for importing some rfc-9980 secret keys.
	+ commit 2e6549f5de5307e3e84c1ffa5e762d14266546ba
	* configure.ac (NEED_LIBGCRYPT_VERSION): Require version 1.12.
	* agent/cvt-openpgp.c (get_npkey_nskey): Add GCRY_PK_KEM.
	(struct try_do_unprotect_arg_s): Add field 'no_sos'.
	(do_unprotect): Add arg no_sos.
	(convert_from_openpgp_main): Set no_sos for the new algos.

	* g10/misc.c (openpgp_pk_algo_name): Name the new ed25519 algo
	"ietf27" to avoid confucion with the traditional name.
	* g10/import.c (build_mode1003_sexp): New.
	(internal_skey_object_to_sexp): Support the single ED25519.
	(transfer_secret_keys): Use mode1003 import functionality for
	unprotected keys.

2026-07-20  Philip Le  <philip.le@gnupg.com>

	gpgsm: Check args for special file names and dashes.
	+ commit 2efb4a6242e25a661eb60adf2cb2c5abf4185d04
	* sm/gpgsm.c (main): Use open_es_fread to check input args for special
	file names and dashes.

2026-07-19  Werner Koch  <wk@gnupg.org>

	gpg: Add preliminary support for RFC-9980 encryption keys.
	+ commit 1475a8f12b142eb34b13e71ae0a696c87af76242
	* common/openpgpdefs.h (PUBKEY_ALGO_ED25519)
	(PUBKEY_ALGO_MLD65_25519,PUBKEY_ALGO_MLD87_448)
	(PUBKEY_ALGO_MLK768_25519,PUBKEY_ALGO_MLK1024_448): New.
	(PUBKEY_ALGO_DIL3_25519,PUBKEY_ALGO_DIL5_448)
	(PUBKEY_ALGO_SPHINX_SHA2): Remove.  Never used.
	* g10/options.h (opt.flags): Add allow_9980 member.
	(RFC9980): New.
	* g10/packet.h (PKT_signature): Add field 'salt'.
	* g10/free-packet.c (free_seckey_enc)
	(copy_signature): Support that field.
	* g10/misc.c (openpgp_pk_test_algo2): Add PUBKEY_ALGO_ED25519.
	(openpgp_pk_algo_usage): Ditto.  Also add the other new algos and
	remove the unused removed algos.
	(pubkey_get_npkey): Add info for ED25529, MLK768, and MLK1024.
	(pubkey_get_nskey): Ditto.
	(pubkey_get_nsig): Add info for PUBKEY_ALGO_ED25519.
	* g10/keyid.c (pubkey_string): Add strings for new algos.
	(do_hash_public_key): Support the new algos.  Redefine use_v5 to
	force_v5 and add optional arg 'sig'.
	(hash_public_key): Add arg optional arg 'sig' and adjust callers.
	(compute_fingerprint): Support v6 fingerprints and new algos.
	* g10/parse-packet.c (parse_signature): Support v6 and new algos.
	(parse_key): Support v6 and reading of public keys.
	* g10/build-packet.c (gpg_mpi_write_opaque_8): New.
	(do_key): Support writing v6 keys and new algos.
	(do_signature): Ditto.
	* g10/pkglue.c (pk_verify): Support PUBKEY_ALGO_ED25519.
	* g10/seskey.c (encode_md_value): Ditto.
	* g10/sig-check.c (check_signature_end_simple): Support longer
	v6 subpacket length header.
	(check_signature_over_key_or_uid): Pass signature packet to the hash
	function.
	* g10/sign.c (update_keysig_packet): Ditto.
	* g10/keygen.c (parse_key_parameter_part): Replace unused ML-DSA and
	Sphinx by new algo names and codes.
	* kbx/keybox-blob.c (_keybox_create_openpgp_blob): Allow v6 keys.
	* kbx/keybox-openpgp.c (keygrip_from_keyparm): Adjust for new algos.
	(parse_key): Support new algos and v6 keys.  Note that this function
	is a simplified version from parse-packet.c.
	* g10/gpg.c (oAllow9980): New const.
	(opts): Add option --allow-9980".
	(main): Set corresponding flag.
	* tests/openpgp/samplekeys/ietf27-mlk768-v4-pub.asc: New sample.
	* tests/openpgp/samplekeys/ietf27-mlk768-v6-pub.asc: New sample.

2026-07-17  NIIBE Yutaka  <gniibe@fsij.org>

	scd: Put a workaround for buggy CCID device.
	+ commit 481b3dd50e744a6d4213abecd27ac1f497c6e1c5
	* scd/ccid-driver.c (bulk_in): Handle ZLP.

2026-07-16  Philip Le  <philip.le@gnupg.com>

	gpgsm: Return 0 if decryption of multi recipient file succeeeds.
	+ commit 890d16586beaa185b082a21e6a26b953181da3eb
	* sm/gpgsm.c (main): Reset error count when decryption succeeds.

2026-07-15  Werner Koch  <wk@gnupg.org>

	common: Make unix_rootdir work for macOS.
	+ commit 0be940905d70125866622c6f53b8d25bde87c21b
	* common/homedir.c [APPLE]: Include procinfo.h
	(macos_myproc_self) [APPLE]: New.
	(unix_rootdir, gnupg_myproc_self): Call macos specific version.

	gpg: Add option primary to the --card-edit generate command.
	+ commit a95da9e25362ea9f33c1e0b4441a86d6eca937f0
	* g10/card-util.c (generate_card_keys): Add arg arg_string and
	  implement option "primary".
	* g10/main.h (GENERATE_KEYPAIR_FULL): New.
	(GENERATE_KEYPAIR_CARDBACKUP): New.
	(GENERATE_KEYPAIR_CARDPRIMARY): New.
	* g10/keygen.c (generate_keypair): Remove args full and and
	  card_backup_key and replace by a new genflags args.  Implement the
	  new CARDPRIMARY feature.

	gpg: Fix long standing regression of "bkuptocard"
	+ commit f103eaee63f702278824967365de16b9757ecc83
	* g10/card-util.c (card_store_subkey): Add arg r_selected_use to
	  return the selected usage.
	* g10/keygen.c (append_subkey_to_keyblock): New.
	* g10/keyedit.c (keyedit_menu) <bkuptocard>:  Also append a
	  corresponding new subkey.

2026-07-14  Werner Koch  <wk@gnupg.org>

	doc: Improve comment on one function.
	+ commit 204d02da018e8aba0bdbae2b5d0c3151a810bf9f
	* g10/keygen.c (write_keybinding): Rename a variable.

2026-07-10  Daniel Cerqueira  <dan.git@lispclub.com>

	po: Update Portuguese Translation.
	+ commit 3913f7b167394cdf47c8f150247c2823f58966e7


2026-07-09  Philip Le  <philip.le@gnupg.com>

	gpgsm: Only display de-vs compliance status in de-vs compliance mode.
	+ commit 4a8f177f390b270df9a86ea47d8eced85420d7d4
	* sm/decrypt.c (gpgsm_decrypt): Check cert chain only in de-vs
	compliance mode.

2026-07-08  NIIBE Yutaka  <gniibe@fsij.org>

	gpg: Fix a memory leak.
	+ commit 6faaeca6b89a64763242cb8b586245085257b066
	* g10/trustdb.c (validate_keys): Release KEYBLOCK.

2026-07-07  Philip Le  <philip.le@gnupg.com>

	gpg: Fix possible double free in import_revoke_cert.
	+ commit a19534b70e27df101a0ad8f653aee8eefdbe8469
	* g10/import.c (import_revoke_cert): Fix possible double free. Use
	LEAVE label on errors.

	gpg: Fix assertion.
	+ commit e319d82d7e3ad9cf2eff3642e23b63304eda55f2
	* g10/build-packet.c (build_sig_subpkt_from_sig): Fix assertion.
	Check fingerprint version before creating the signature subpacket.

2026-07-07  NIIBE Yutaka  <gniibe@fsij.org>

	common:dotlock:unix: Don't emit wrong error message.
	+ commit f454e9372ae0e2a2a0ec034dbdbfa9c8c6d68f77
	* common/dotlock.c (dotlock_take_unix): It's not an error when
	it encounters disappeared lockfile.

2026-07-06  Philip Le  <philip.le@gnupg.com>

	gpg: Fix using wrong fingerprint length.
	+ commit 42e6677f7ab5617ce605cad08079a48095be09cf
	g10/build-packet.c (build_sig_subpkt_from_sig): Use the fpr length of
	the to be revoked key.

2026-07-03  NIIBE Yutaka  <gniibe@fsij.org>

	gpg: Fix trustdb recursive lock problem.
	+ commit 7752c7dcad8942e4227384282e6c8eb85b284d6f
	* g10/tdbio.c (take_write_lock): It's the callee to handle the
	recursive lock.
	(tdbio_sync): Simply use take_write_lock and release_write_lock.

2026-07-02  Werner Koch  <wk@gnupg.org>

	Release 2.5.21.
	+ commit 363096d9c9a973ac8dcad8ee4efd479f50add290


2026-06-30  Werner Koch  <wk@gnupg.org>

	speedo: Create a pkgversioninfo.txt file.
	+ commit 8716b4dac4a79b600d18847b8bc0193bd06e1fc1
	* build-aux/mk-sbom.sh: New.  Taken from gpg4win and extended.
	* Makefile.am (EXTRA_DIST): Add it.
	* build-aux/speedo.mk (gnupg_ver_this): Use sed to extract version.
	(gnupg_commit_id): new.
	(00-unpack): Call mk-sbom.sh.
	(clean-pkg-versions: Clear version files.
	($(bdir)/pkgversioninfo.txt): New.
	(all-speedo,installer): Depend on above.
	(dist-source): Exclude autom4te.cache just in case
	* build-aux/speedo/w32/inst.nsi: Install pkgversioninfo.txt.

2026-06-30  NIIBE Yutaka  <gniibe@fsij.org>

	scd: Fix condition to retrieve ATR.
	+ commit ca25a7a61bebbe4e27dd5568c5b049675b7aa4ae
	* scd/app.c (atr_to_cardtype): Call apdu_get_atr when ATR is NULL.

2026-06-29  Werner Koch  <wk@gnupg.org>

	speedo: Fix passing configure args to w32 builds.
	+ commit 7af73849a5dbbc5c70e43c3a3f5d70c639c80ab4
	* build-aux/speedo.mk (pkgcfg): Use correct number of dollar signs.

	common: Prepare to get rid of map_w32_to_errno.
	+ commit bf808091534f587e8cdacf351b0e7ba060165fd8
	* common/sysutils.c (gnupg_w32_set_errno): Use gpgrt function if
	  available.

	agent: Make batch import of Kyber keys work.
	+ commit 4fca79b67bba04bc5ef2a4402e948c01821ceac5
	* agent/command.c (cmd_import_key): Allow --unattended also for
	  composite keys.

2026-06-26  NIIBE Yutaka  <gniibe@fsij.org>

	dirmngr: Add a validation check in get_dns_cert_standard.
	+ commit c3ec7678799a161b9265969e7ad3fd59605b18ab
	* dirmngr/dns-stuff.c (get_dns_cert_standard): Validate the length.

2026-06-19  NIIBE Yutaka  <gniibe@fsij.org>

	build: Update ldap.m4 for POSIX with no LDAP_DEPRECATED.
	+ commit d3822099fdd4d84323afae4bacaadfeab9cb3e27
	* m4/ldap.m4: Check ldap_err2string, instead.

2026-06-18  Werner Koch  <wk@gnupg.org>

	gpgsm: Require a minimum tag length for GCM decryption.
	+ commit 4c7e68cf3d335328821bdbb70db309a60d0e4fd4
	* sm/decrypt.c (gpgsm_decrypt): Require a minimum authtaglen.

2026-06-18  NIIBE Yutaka  <gniibe@fsij.org>

	w32:common: Fix usleep in w32_wait_when_sharing_violation.
	+ commit ab9ce5f5e775a3a6a37923299685ac371f740103
	* common/sysutils.c (w32_wait_when_sharing_violation): WTIME is
	in milliseconds.

2026-06-17  Philip Le  <philip.le@gnupg.com>

	gpg: Fix copy_signature.
	+ commit 56e11ffe971d5cc58185b4e8d02b82dc432c634b
	* g10/free-packet.c (copy_signature): Set the signers_uid of the new
	copy to NULL if it is not present in the source signature.

	gpg: Use the INT_RCP_FPR subpacket in revocation signatures.
	+ commit 9e0e5547d2a008332873a9b632f82f9414ad887f
	* common/openpgpdefs.h (sigsubpkttype_t): Add Intended Recipient
	Fingerprint signature subpacket.
	* g10/build-packet.c (build_sig_subpkt): Build the Intended Recipient
	Fingerprint signature subpacket for v4 and v5 keys.
	* g10/free-packet.c (free_seckey_enc): Free rev_subject_info.
	(copy_signature): Copy the rev_subject_info struct too.
	* g10/import.c (import_one): Print info that addtional revocation
	signatures are checked.
	(import_revoke_cert): Use the new INT_RCP_FPR subpacket to check
	revocation signature if the subpacket is present.
	* g10/packet.h (rev_subject_info_s): New. Contains the fingerprint of
	the to be revoked key in a revocation signature.
	(PKT_signature): Add rev_subject_info.
	* g10/parse-packet.c (dump_sig_subpkt): Print info line about
	INT_RCP_FPR signature subpacket.
	(parse_signature): Parse INT_RCP_FPR signature subpacket.
	* g10/sig-check.c (check_key_signature): Check the revocation
	signature and ignore revocation for already revoked keys.
	* g10/sign.c (make_keysig_packet): Write the fingerprint of the to be
	revoked key into sig->rev_subject_info.

2026-06-15  NIIBE Yutaka  <gniibe@fsij.org>

	gpg: Fix partial file handling.
	+ commit a54dff1b151b85837714b199f316cbb339275ddc
	* g10/misc.c (gnupg_register_partial_file): Fix possible memory leaks.
	(gnupg_process_partial_file): Better error message.
	* g10/plaintext.c (pfg_close_file): Likewise.

2026-06-12  NIIBE Yutaka  <gniibe@fsij.org>

	gpg: Defer renaming at exit, so that it can remove on failure.
	+ commit ab2e64e4b490bf9ea45f7aff2060e16e7b2b7119
	* g10/main.h (gnupg_register_partial_file): New.
	(gnupg_process_partial_file): New.
	* g10/misc.c (gnupg_register_partial_file): New.
	(gnupg_process_partial_file): New.
	* g10/plaintext.c (pfg_close_file): Add log_info when remove.
	Register the file rename.
	* g10/gpg.c (g10_exit): Call gnupg_process_partial_file.

2026-06-11  Werner Koch  <wk@gnupg.org>

	gpg-authcode-sign: Avoid syntax error if input file does not exist.
	+ commit a9c9435cd4471232a252785b69e4dd44379bc49f
	* tools/gpg-authcode-sign.sh (cleanup): Check that file exists.

2026-06-09  Mikhail Filippov  <mikhail@filippov.me>

	scd:openpgp: Fix CHV1 retry counter byte index.
	+ commit 245330ebeaf67f8e87fef979777c24b983f1a519
	* scd/app-openpgp.c (get_remaining_tries): Read value[4] not value[1]
	for chvno==1.

2026-06-09  NIIBE Yutaka  <gniibe@fsij.org>

	gpg: Fix error propagation in encrypted->compressed->plaintext chain.
	+ commit 91bff8b9fd5e130a3ebf46f0afc6c8ad723ca1e4
	* g10/compress.c (do_uncompress): Return an error of input failure.
	* g10/decrypt-data.c (aead_underflow): Remove modifying an error code,
	because ->checktag_failed is enough for this.
	* g10/plaintext.c (handle_plaintext): Pick up an error code from input
	failure.

2026-06-09  NIIBE Yutaka  <gniibe@fsij.org>
	    Philip Le  <philip.le@gnupg.com>

	gpg: Use partial file on decryption, remove on failure.
	+ commit 8f8b2bdcc3c93f7586ce2c18ddbaff2efe5ba5d3
	* g10/options.h (COMPAT_NO_PARTIALFILEGUARD): New.
	* g10/gpg.c (compatibility_flags_s compatibility_flags): Add
	COMPAT_NO_PARTIALFILEGUARD.
	* sm/gpgsm.c (compatibility_flags_s compatibility_flags): Fix the
	option name.
	* g10/packet.h (struct pfg, pfg_open_file, pfg_close_file): New.
	* g10/decrypt-data.c (decrypt_data): Use pfg_open_file,
	pfg_close_file, instead of get_output_file.  Add log_error for MDC
	failure just like AEAD failure.
	* g10/plaintext.c (get_output_file): Mofify using PFG.
	(pfg_open_file, pfg_close_file): New.
	(handle_plaintext): Use PFG.
	Add iobuf_error check to ensure aead filter failure is detected
	correctly.

2026-06-02  NIIBE Yutaka  <gniibe@fsij.org>

	gpgsm: Use partial file on decryption, remove on failure.
	+ commit ca8633c55edffd9ee46fe80735ee125120e0bc2c
	* sm/gpgsm.c (main): Prepare .part file and rename on success, remove
	on failure.
	* sm/gpgsm.h (COMPAT_NO_PARTIALFILEGUARD): New.

	tools:gpgconf: Raise an error on parse error.
	+ commit f99e4291200d507f5ac8a73066a2ea259a1d7eb8
	* tools/gpgconf-comp.c (change_options_program): Return an
	error, replacing assertion.

	scd: Limit the size of data object returned from a device.
	+ commit ab3b9c7709fdd41b37e44632cc1569e85c6d1e6e
	* scd/apdu.c (send_le, apdu_send_direct): Raise an error
	of SW_WRONG_LENGTH, when it's too large.

2026-06-02  NIIBE Yutaka  <gniibe@fsij.org>
	    Jakub Jelen  <jjelen@redhat.com>

	gpg:keygen: Fix setting keyserver_url in key generation.
	+ commit b42f8da77c5a709ea9fd163ad7c4d73ddeee9dba
	* g10/keygen.c (proc_parameter_file): Save and restore global
	variable opt.def_keyserver_url.

2026-05-29  Philip Le  <philip.le@gnupg.com>

	gpgsm: Fix regression in gpgsm_verify with expired certificates.
	+ commit 32f56a2732f0ac6204aad946388789cdbb0e26eb
	* sm/verify.c (gpgsm_verify): Display information about signers with
	expired certificate.

2026-05-29  Werner Koch  <wk@gnupg.org>

	gpg: Improve diagnostics for faulty secret key packets.
	+ commit 91defad97deca5ce1b9cc8e792ae5fe13c201f7a
	* g10/parse-packet.c (parse_key): Add a note about a mising checksum.

2026-05-26  NIIBE Yutaka  <gniibe@fsij.org>

	tests:gpgscm: Support signed-char machine.
	+ commit 31c8f42bb30306d2bef3e315730c379a19f0af26
	* tests/gpgscm/ffi.c (rl_gets, ffi_schemify_name): Add coercion to
	unsigned char explicitly.
	* tests/gpgscm/main.c: Remove unused <ctype.h>.
	* tests/gpgscm/scheme.c (stricmp, mk_atom, readstrexp)
	(printslashstring, hash_fn): Add coercion to unsigned char explicitly.
	(basic_inchar): Add coercion to unsigned char * explicitly.

2026-05-18  Werner Koch  <wk@gnupg.org>

	gpgscm: Allow building on systems with MUSL libc.
	+ commit a0d4d936424e945966de9314cbb2765a8819efbf
	* tests/gpgscm/scheme.c: Include time.h.
