Skip to content

The build verifies the staging archive instead of reading it unverified - #11

Merged
marcos-mendez merged 1 commit into
mainfrom
fix/verify-staging-archive
Sep 27, 2026
Merged

marcos-mendez merged 1 commit into
mainfrom
fix/verify-staging-archive

Conversation

@marcos-mendez

Copy link
Copy Markdown
Contributor

Closes part of Keel-Linux/tracker#7 for this recipe.

The defect

The staging distribution was given its own signing key so that a nightly could
sign itself and so appliance recipes could stop reading it through
[trusted=yes], which switches verification off. Signing landed; verification
did not, so a layer build printed

W: OpenPGP signature verification failed: file:/srv/keel-apt/repo
   trixie-staging InRelease: Missing key
   8CFD1A4841448B2227341CEB202CACBD0E97090A

and carried on, installing the project's own packages unverified.

How the build verifies now

  • the public half of the staging key is installed into the build tree as
    /etc/apt/keyrings/keel-staging-keyring.asc, taken from
    /srv/keel-apt/keys/keel-staging-keyring.asc, where bin/publish of
    Keel-Linux/apt now leaves the keyring of whichever distribution it signed;
  • the source entry names it through signed-by and no longer says
    trusted=yes, which no file in any of the four recipes does any more;
  • apt-get update runs with --error-on=any, so a warning is an error;
  • bin/keel-archive-check makes the same checks itself, with gpgv, because
    the tree that is about to be configured is checked at a step where no
    apt-get update runs: the copied index is the live one, the entry names the
    keyring and the distribution, nothing in the tree says trusted=yes, and the
    signature on the copied InRelease verifies against the named fingerprint.

How it fails

Measured against the real archive on the build host, in a scratch apt root:

tree apt
[trusted=yes], no keyring W: ... Missing key, exit 0, packages installed
signed-by, no keyring E: The repository ... is not signed, exit 100
signed-by, the wrong key E: The repository ... is not signed, exit 100
signed-by, the staging key Get:1 ... InRelease, exit 0

bin/keel-archive-check exits 1 with a FATAL [archive-check <step>] line in
each of those failures, before a package is installed.

The keyring does not reach the image

The conf script removes it with the source entry and the copy of the archive,
and Keel-Linux/common#4 adds all three to common/removelists-final/turnkey,
which is the arrangement that holds whether or not a recipe remembers.

Also here

The tests workflow gains the package job. package / changelog is a required
status on main in this repository, and no job produced it: a check that is
required and never reported leaves every pull request blocked for good,
including this one. The job is the one keel-mariadb, keel-postgresql and
keel-wordpress already carry.

Test plan

  • COVERAGE_THRESHOLD=95 tests/coverage.sh: 99.66 percent (295/296) over
    132 bats tests, 100 percent bar the one line of the dialog loop that
    needs a terminal. bin/keel-archive-check 100 (52/52),
    zz-project-packages 100 (31/31)
  • shellcheck -S warning bin/keel-archive-check clean
  • appliance / build-and-boot against a rebuilt layer

…erified

The staging distribution was given its own signing key so that a nightly could
sign itself and so recipes could stop reading it through [trusted=yes], which
switches verification off. Signing landed; verification did not. A layer build
printed

    W: OpenPGP signature verification failed: file:/srv/keel-apt/repo
       trixie-staging InRelease: Missing key
       8CFD1A4841448B2227341CEB202CACBD0E97090A

and carried on, so it installed the project own packages unverified, which is
where it was before, only now it said so (tracker#7).

The public half of the staging key is installed into the build tree as
/etc/apt/keyrings/keel-staging-keyring.asc, from /srv/keel-apt/keys where
bin/publish of keel-linux/apt leaves it; the source entry names it through
signed-by; and apt-get update runs with --error-on=any. Measured against the
real archive: with signed-by named and no key, apt exits 100 and says the
repository is not signed, where before it warned and exited 0. A warning
nobody fails on is how this shipped.

bin/keel-archive-check makes the same checks itself rather than trusting apt to
have complained, because the tree that is about to be configured is checked at
a step where no apt-get update runs: the copied index is the live one, the
entry names the keyring and this distribution, no apt source in the tree says
trusted=yes, and the signature on the copied InRelease verifies against the
named key with gpgv. The keyring leaves the image with the source entry and the
copy of the archive, and common/removelists-final/turnkey takes all three out
as well.
@marcos-mendez
marcos-mendez merged commit 8674d7d into main Sep 27, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant