<table><tr><td style="">knauss added inline comments.
</td><a style="text-decoration: none; padding: 4px 8px; margin: 0 8px 8px; float: right; color: #464C5C; font-weight: bold; border-radius: 3px; background-color: #F7F7F9; background-image: linear-gradient(to bottom,#fff,#f1f0f1); display: inline-block; border: 1px solid rgba(71,87,120,.2);" href="https://phabricator.kde.org/D3432" rel="noreferrer">View Revision</a></tr></table><br /><div><strong>INLINE COMMENTS</strong><div><div style="margin: 6px 0 12px 0;"><div style="border: 1px solid #C7CCD9; border-radius: 3px;"><div style="padding: 0; background: #F7F7F7; border-color: #e3e4e8; border-style: solid; border-width: 0 0 1px 0; margin: 0;"><div style="color: #74777d; background: #eff2f4; padding: 6px 8px; overflow: hidden;"><a style="float: right; text-decoration: none;" href="https://phabricator.kde.org/D3432#inline-13877" rel="noreferrer">View Inline</a><span style="color: #4b4d51; font-weight: bold;">defaultrenderer.cpp:1008</span></div>
<div style="font: 11px/15px "Menlo", "Consolas", "Monaco", monospace; white-space: pre-wrap; clear: both; padding: 4px 0; margin: 0;"><div style="padding: 0 8px; margin: 0 4px; background: #ffd0d0;">            <span class="bright"></span><span class="n"><span class="bright">block</span></span><span class="bright"></span><span class="p"><span class="bright">.</span></span><span class="bright"></span><span class="n"><span class="bright">setProperty</span></span><span class="bright"></span><span class="p"><span class="bright">(</span></span><span class="bright"></span><span style="color: #766510"><span class="bright">"keyT</span>rust<span class="bright">"</span></span><span class="bright"></span><span class="p"><span class="bright">,</span></span><span class="bright"> </span><span class="n"><span class="bright">QStringLiteral</span></span><span class="bright"></span><span class="p"><span class="bright">(</span></span><span class="bright"></span><span style="color: #766510"><span class="bright">"full"</span></span><span class="bright"></span><span class="p"><span class="bright">));</span></span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #ffd0d0;">        <span class="bright"></span><span class="p"><span class="bright">}</span></span><span class="bright"> </span><span style="color: #aa4000"><span class="bright">else</span></span> <span style="color: #aa4000">if</span> <span class="p">(</span><span class="n">metaData</span><span class="p">.</span><span class="n">keyTrust</span> <span style="color: #aa2211">==</span> <span class="n">GpgME</span><span style="color: #aa2211">::</span><span class="n">Signature</span><span style="color: #aa2211">::</span><span class="n">U<span class="bright">ltimate</span></span><span class="p">)</span> <span class="p">{</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #ffd0d0;">            <span class="n">block</span><span class="p">.</span><span class="n">setProperty</span><span class="p">(</span><span style="color: #766510">"keyTrust"</span><span class="p">,</span> <span class="n">QStringLiteral</span><span class="p">(</span><span style="color: #766510">"u<span class="bright">ltimate</span>"</span><span class="p">));</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">            <span class="bright"></span><span style="color: #74777d"><span class="bright">// Not enough TOFU trust, or key is well t</span>rust<span class="bright">ed/not trusted at all</span></span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">        <span class="bright">   </span> <span style="color: #aa4000">if</span> <span class="p">(</span><span class="n">metaData</span><span class="p">.</span><span class="n">keyTrust</span> <span style="color: #aa2211">==</span> <span class="n">GpgME</span><span style="color: #aa2211">::</span><span class="n">Signature</span><span style="color: #aa2211">::</span><span class="n">U<span class="bright">nknown</span></span><span class="p">)</span> <span class="p">{</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">            <span class="bright">    </span><span class="n">block</span><span class="p">.</span><span class="n">setProperty</span><span class="p">(</span><span style="color: #766510">"keyTrust"</span><span class="p">,</span> <span class="n">QStringLiteral</span><span class="p">(</span><span style="color: #766510">"u<span class="bright">nknown</span>"</span><span class="p">));</span>
</div></div></div>
<div style="margin: 8px 0; padding: 0 12px;"><p style="padding: 0; margin: 8px;">well if it is unknon we should better use Tofu, this is for sure better than Unknown.</p></div></div><br /><div style="border: 1px solid #C7CCD9; border-radius: 3px;"><div style="padding: 0; background: #F7F7F7; border-color: #e3e4e8; border-style: solid; border-width: 0 0 1px 0; margin: 0;"><div style="color: #74777d; background: #eff2f4; padding: 6px 8px; overflow: hidden;"><a style="float: right; text-decoration: none;" href="https://phabricator.kde.org/D3432#inline-13878" rel="noreferrer">View Inline</a><span style="color: #4b4d51; font-weight: bold;">defaultrenderer.cpp:1187</span></div>
<div style="font: 11px/15px "Menlo", "Consolas", "Monaco", monospace; white-space: pre-wrap; clear: both; padding: 4px 0; margin: 0;"><div style="padding: 0 8px; margin: 0 4px; background: #ffd0d0;">                    <span style="color: #aa4000">if</span> <span class="p">(</span><span class="n">metaData</span><span class="p">.</span><span class="n">isGoodSignature</span><span class="p">)</span> <span class="p">{</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #ffd0d0;">                        <span style="color: #aa4000">if</span> <span class="p">(</span><span class="n">m<span class="bright">etaData</span></span><span class="bright"></span><span class="p"><span class="bright">.</span></span><span class="bright"></span><span class="n"><span class="bright">keyTrust</span></span> <span style="color: #aa2211"><</span> <span class="n">GpgME</span><span style="color: #aa2211">::<span class="bright"></span></span><span class="bright"></span><span class="n"><span class="bright">Signature</span></span><span class="bright"></span><span style="color: #aa2211"><span class="bright">::</span></span><span class="bright"></span><span class="n"><span class="bright">Marginal</span></span><span class="p">)</span> <span class="p">{</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">                    <span style="color: #aa4000">if</span> <span class="p">(</span><span class="n">metaData</span><span class="p">.</span><span class="n">isGoodSignature<span class="bright"></span></span><span class="bright"> </span><span style="color: #aa2211"><span class="bright">&&</span></span><span class="bright"> </span><span class="n"><span class="bright">mp</span></span><span class="bright"></span><span style="color: #aa2211"><span class="bright">-></span></span><span class="bright"></span><span class="n"><span class="bright">tofuValidity</span></span><span class="bright"></span><span class="p"><span class="bright">()</span></span><span class="bright"> </span><span style="color: #aa2211"><span class="bright">!=</span></span><span class="bright"> </span><span class="n"><span class="bright">GpgME</span></span><span class="bright"></span><span style="color: #aa2211"><span class="bright">::</span></span><span class="bright"></span><span class="n"><span class="bright">TofuInfo</span></span><span class="bright"></span><span style="color: #aa2211"><span class="bright">::</span></span><span class="bright"></span><span class="n"><span class="bright">Conflict</span></span><span class="p">)</span> <span class="p">{</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">                        <span style="color: #aa4000">if</span> <span class="p">(</span><span class="n">m<span class="bright">p</span></span><span class="bright"></span><span style="color: #aa2211"><span class="bright">-></span></span><span class="bright"></span><span class="n"><span class="bright">tofuValidity</span></span><span class="bright"></span><span class="p"><span class="bright">()</span></span> <span style="color: #aa2211"><</span> <span class="n">GpgME</span><span style="color: #aa2211">::<span class="bright"></span></span><span class="bright"></span><span class="n"><span class="bright">TofuInfo</span></span><span class="bright"></span><span style="color: #aa2211"><span class="bright">::</span></span><span class="bright"></span><span class="n"><span class="bright">LargeHistory</span></span><span class="p">)</span> <span class="p">{</span>
</div><div style="padding: 0 8px; margin: 0 4px; ">                            <span class="n">mClass</span> <span style="color: #aa2211">=</span> <span class="n">QStringLiteral</span><span class="p">(</span><span style="color: #766510">"signOkKeyBad"</span><span class="p">);</span>
</div></div></div>
<div style="margin: 8px 0; padding: 0 12px;"><p style="padding: 0; margin: 8px;">here you have to support the same logic as above, if tofu < GpgME::TofuInfo::LittleHistory than keyTrust.</p></div></div><br /><div style="border: 1px solid #C7CCD9; border-radius: 3px;"><div style="padding: 0; background: #F7F7F7; border-color: #e3e4e8; border-style: solid; border-width: 0 0 1px 0; margin: 0;"><div style="color: #74777d; background: #eff2f4; padding: 6px 8px; overflow: hidden;"><a style="float: right; text-decoration: none;" href="https://phabricator.kde.org/D3432#inline-13882" rel="noreferrer">View Inline</a><span style="color: #4b4d51; font-weight: bold;">messagepart.cpp:732</span></div>
<div style="font: 11px/15px "Menlo", "Consolas", "Monaco", monospace; white-space: pre-wrap; clear: both; padding: 4px 0; margin: 0;"><div style="padding: 0 8px; margin: 0 4px; ">    <span class="n">mMetaData</span><span class="p">.</span><span class="n">status_code</span> <span style="color: #aa2211">=</span> <span class="n">GPGME_SIG_STAT_NONE</span><span class="p">;</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">    <span class="n">Q_ASSERT</span><span class="p">(</span><span style="color: #aa2211">!</span><span class="n">fromAddress</span><span class="p">.</span><span class="n">isEmpty</span><span class="p">());</span>
</div><div style="padding: 0 8px; margin: 0 4px; "><span class="p">}</span>
</div></div></div>
<div style="margin: 8px 0; padding: 0 12px;"><p style="padding: 0; margin: 8px;">Not good to have this in commited code except from tests, plase replace this with a qError or anything, that would allow a running program not to crash.</p></div></div><br /><div style="border: 1px solid #C7CCD9; border-radius: 3px;"><div style="padding: 0; background: #F7F7F7; border-color: #e3e4e8; border-style: solid; border-width: 0 0 1px 0; margin: 0;"><div style="color: #74777d; background: #eff2f4; padding: 6px 8px; overflow: hidden;"><a style="float: right; text-decoration: none;" href="https://phabricator.kde.org/D3432#inline-13881" rel="noreferrer">View Inline</a><span style="color: #4b4d51; font-weight: bold;">messagepart.cpp:865</span></div>
<div style="font: 11px/15px "Menlo", "Consolas", "Monaco", monospace; white-space: pre-wrap; clear: both; padding: 4px 0; margin: 0;"><div style="padding: 0 8px; margin: 0 4px; background: #ffd0d0;">        <span class="n">GpgME</span><span style="color: #aa2211">::</span><span class="n">Signature</span> <span class="n">signature<span class="bright"></span></span><span class="bright"> </span><span style="color: #aa2211"><span class="bright">=</span></span><span class="bright"> </span><span class="n"><span class="bright">mSignatures</span></span><span class="bright"></span><span class="p"><span class="bright">.</span></span><span class="bright"></span><span class="n"><span class="bright">front</span></span><span class="bright"></span><span class="p"><span class="bright">()</span>;</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">        <span class="n">GpgME</span><span style="color: #aa2211">::</span><span class="n">Signature</span> <span class="n">signature</span><span class="p">;</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">        <span class="n">GpgME</span><span style="color: #aa2211">::</span><span class="n">UserID</span> <span class="n">userId</span><span class="p">;</span>
</div></div></div>
<div style="margin: 8px 0; padding: 0 12px;"><p style="padding: 0; margin: 8px;">this variable is only set (l919,l933) but never read? So this can be deleted?</p></div></div><br /><div style="border: 1px solid #C7CCD9; border-radius: 3px;"><div style="padding: 0; background: #F7F7F7; border-color: #e3e4e8; border-style: solid; border-width: 0 0 1px 0; margin: 0;"><div style="color: #74777d; background: #eff2f4; padding: 6px 8px; overflow: hidden;"><a style="float: right; text-decoration: none;" href="https://phabricator.kde.org/D3432#inline-13880" rel="noreferrer">View Inline</a><span style="color: #4b4d51; font-weight: bold;">messagepart.cpp:889</span></div>
<div style="font: 11px/15px "Menlo", "Consolas", "Monaco", monospace; white-space: pre-wrap; clear: both; padding: 4px 0; margin: 0;"><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">            <span style="color: #74777d">// is well-trusted, so there's no need to bother with TOFU.</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">            <span style="color: #aa4000">if</span> <span class="p">(</span><span class="n">sig</span><span class="p">.</span><span class="n">validity</span><span class="p">()</span> <span style="color: #aa2211">==</span> <span class="n">GpgME</span><span style="color: #aa2211">::</span><span class="n">Signature</span><span style="color: #aa2211">::</span><span class="n">Validity</span><span style="color: #aa2211">::</span><span class="n">Marginal</span><span class="p">)</span> <span class="p">{</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">                <span style="color: #aa4000">const</span> <span style="color: #aa4000">auto</span> <span class="n">tofu</span> <span style="color: #aa2211">=</span> <span class="n">uid</span><span style="color: #aa2211">-></span><span class="n">tofuInfo</span><span class="p">();</span>
</div></div></div>
<div style="margin: 8px 0; padding: 0 12px;"><p style="padding: 0; margin: 8px;">and what about Validity::Unknown?</p></div></div><br /><div style="border: 1px solid #C7CCD9; border-radius: 3px;"><div style="padding: 0; background: #F7F7F7; border-color: #e3e4e8; border-style: solid; border-width: 0 0 1px 0; margin: 0;"><div style="color: #74777d; background: #eff2f4; padding: 6px 8px; overflow: hidden;"><a style="float: right; text-decoration: none;" href="https://phabricator.kde.org/D3432#inline-13879" rel="noreferrer">View Inline</a><span style="color: #4b4d51; font-weight: bold;">messagepart.cpp:920</span></div>
<div style="font: 11px/15px "Menlo", "Consolas", "Monaco", monospace; white-space: pre-wrap; clear: both; padding: 4px 0; margin: 0;"><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">                <span class="n">userId</span> <span style="color: #aa2211">=</span> <span style="color: #aa2211">*</span><span class="n">uid</span><span class="p">;</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">                <span style="color: #aa4000">if</span> <span class="p">(</span><span class="n">tofu</span><span class="p">.</span><span class="n">signCount</span><span class="p">()</span> <span style="color: #aa2211">></span> <span style="color: #601200">10</span><span class="p">)</span> <span class="p">{</span>
</div><div style="padding: 0 8px; margin: 0 4px; background: #d0ffd0;">                    <span style="color: #74777d">// Trusted-enough, let's use this signature!</span>
</div></div></div>
<div style="margin: 8px 0; padding: 0 12px;"><p style="padding: 0; margin: 8px;">this is a little bit strage, to read a number here and not anything from gpgme, does that means, that gpg do not give hints, when a key is trust worthy?</p>

<p style="padding: 0; margin: 8px;">why is 10 a good number? Is there any discussion about this threshold?</p></div></div></div></div></div><br /><div><strong>REPOSITORY</strong><div><div>R94 PIM: Message Library</div></div></div><br /><div><strong>REVISION DETAIL</strong><div><a href="https://phabricator.kde.org/D3432" rel="noreferrer">https://phabricator.kde.org/D3432</a></div></div><br /><div><strong>EMAIL PREFERENCES</strong><div><a href="https://phabricator.kde.org/settings/panel/emailpreferences/" rel="noreferrer">https://phabricator.kde.org/settings/panel/emailpreferences/</a></div></div><br /><div><strong>To: </strong>dvratil, aheinecke, knauss<br /><strong>Cc: </strong>kde-pim, spencerb, dvasin, winterz, vkrause, mlaurent, knauss, dvratil<br /></div>