Repository navigation
The trusted=yes that is refused is one on the project archive - #12
Merged
Merged
Conversation
bin/keel-archive-check refused a trusted=yes on any apt source in the build tree. The captured pool of decision 0012 sets Trusted: yes on purpose, for a file: index generated on this machine from files keel-pool verify checks against the same digests apt does, so the wider rule would have failed every pinned build. What is refused is now a source that names the project archive and switches verification off, which is the defect of tracker#7, in whichever file and in either of apt's two formats. What the pool does is the pool's business. Measured with the same suite: bin/keel-archive-check 100 percent (54/54) over 27 bats tests, three of them new: the pool's Trusted: yes passes, a trusted=yes on the project archive in another file fails, and the archive the rule applies to is overridable.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to tracker#7, on top of the verification fix merged an hour ago.
bin/keel-archive-checkrefused atrusted=yeson any apt source in thebuild tree. The captured pool of decision 0012 sets
Trusted: yeson purpose:So the wider rule would have failed every pinned build.
/srv/keel-pool/currentdoes not exist on the build host at the moment, which is the only reason
tonight's rebuild did not hit it.
What is refused is now a source that names the project archive and switches
verification off, which is the defect of tracker#7, in whichever file and in
either of apt's two formats. What the pool does is the pool's business: its
index is generated on the build host and its digests are checked twice.
Test plan
bin/keel-archive-check, three of them new: the pool'sTrusted: yespasses, atrusted=yeson the project archive in anotherfile fails, and the archive the rule applies to is overridable
(
KEEL_ARCHIVE_PATH)bin/keel-archive-check100 percent (54/54) under kcovshellcheck -S warning bin/keel-archive-checkcleanCOVERAGE_THRESHOLD=95 tests/coverage.sh: 99.66 percent (297/298) over 134 bats tests