From 8c96c3d1e3d8670c4d99c1e7c61cba0735794059 Mon Sep 17 00:00:00 2001 From: navigator Date: Fri, 2 Oct 2026 14:49:46 +0000 Subject: [PATCH 1/2] fix: drop the overlay's Keel source and 1001 pin; pin staging for the build only The overlay shipped /etc/apt/sources.list.d/keel.sources (apt.keellinux.org, disabled) and /etc/apt/preferences.d/keel at 1001. At 1001 apt downgrades every package newer than the archive's (tracker#23), and at those paths both files override the source and the 990 pin Keel-Linux/common#30 ships. The 1001 pin was also what let the build time archive beat TurnKey's 999 pin during the upgrade in conf.d/main. That is now a build-only pin on the staging Label, removed with the build time source, and the build fails if any apt file of the image still names the build time archive. --- Makefile | 7 +-- changelog | 12 +++++ conf.d/main | 29 ++++++++--- overlay/etc/apt/preferences.d/keel | 5 -- overlay/etc/apt/sources.list.d/keel.sources | 17 ------ tests/apt-files.bats | 58 +++++++++++++++++++++ 6 files changed, 96 insertions(+), 32 deletions(-) delete mode 100644 overlay/etc/apt/preferences.d/keel delete mode 100644 overlay/etc/apt/sources.list.d/keel.sources create mode 100644 tests/apt-files.bats diff --git a/Makefile b/Makefile index b1878cb..5e258ba 100644 --- a/Makefile +++ b/Makefile @@ -29,9 +29,10 @@ include $(FAB_PATH)/common/mk/turnkey.mk # is installed as a keyring, the source entry names it through signed-by, # nothing in the tree says trusted=yes, and apt runs with --error-on=any, so a # signature that cannot be checked fails the build instead of warning about it -# and carrying on. conf.d/main removes the copy of the archive, the source -# entry and the keyring from the image and leaves the future apt.keellinux.org -# entry in place, disabled. +# and carrying on. conf.d/main pins the archive for the build only and +# removes the copy of the archive, the source entry, the pin and the keyring +# from the image. The appliance's own Keel source and pin are common's +# (overlays/turnkey.d/keel-apt). # # None of the three build time files is for an installed appliance, because # the staging key signs whatever the build host produced. The removelist at diff --git a/changelog b/changelog index bdbd3e3..5bd7df1 100644 --- a/changelog +++ b/changelog @@ -1,5 +1,17 @@ turnkey-postgresql-19.0 (4) turnkey; urgency=low + * The overlay no longer ships /etc/apt/sources.list.d/keel.sources + (apt.keellinux.org, disabled) or /etc/apt/preferences.d/keel (the Keel + origin at 1001). At 1001 apt downgraded every package newer than the + archive's (tracker#23), and both files, at the paths common uses, would + override the source and the 990 pin Keel-Linux/common#30 ships. The + build time archive still wins over TurnKey's 999 pin during the build: + conf.d/main pins it by its Label, l=Keel Linux staging, at 1001 before + the upgrade and removes that pin with the build time source. The build + then fails if any apt source or pin of the image still names the build + time archive, in place of the check that keel.sources was disabled. + tests/apt-files.bats checks the recipe. + * bin/keel-archive-check refuses a trusted=yes on the project archive rather than on every apt source in the build tree. The captured pool of decision 0012 sets Trusted: yes on purpose, for a file: index generated on this diff --git a/conf.d/main b/conf.d/main index 17fc47f..516f89b 100755 --- a/conf.d/main +++ b/conf.d/main @@ -86,6 +86,15 @@ dpkg-query -W -f '${Status}' webmin-postgresql | grep -qx 'install ok installed' # to do with it. The conf script runs with stdin closed, dpkg reads end of # file at the prompt and leaves confconsole "install ok unpacked", which # fails this script. Keep the overlay's file without asking. +# +# The build time archive has to win over every other source here: a +# bootstrap from before Keel-Linux/common#30 pins TurnKey's archive at 999. +# It used to win through the overlay's /etc/apt/preferences.d/keel at 1001, +# which then shipped in the image and downgraded every package newer than the +# archive's (tracker#23). This pin names the staging distribution by its +# Label, exists only during the build and goes with the build time source. +printf 'Package: *\nPin: release l=Keel Linux staging\nPin-Priority: 1001\n' \ + > /etc/apt/preferences.d/keel-staging export DEBIAN_FRONTEND=noninteractive apt-get install -y --only-upgrade \ -o Dpkg::Options::=--force-confdef \ @@ -114,14 +123,20 @@ EOF dpkg-query -W -f '${Package} ${Version} ${Status}\n' inithooks confconsole keel # The build time package source is not for appliances: remove the source -# entry, the copy of the archive it names and the keyring the build verified -# that archive with, and keep the documented, disabled entry for the future -# signed repository (overlay). The staging key signs whatever the build host -# produced, so an image that kept it would carry trust in a nightly -# (tracker#7). common/removelists-final/turnkey removes the same three paths -# at the end of the build, whatever a recipe does. +# entry, its build time pin, the copy of the archive it names and the keyring +# the build verified that archive with. The staging key signs whatever the +# build host produced, so an image that kept it would carry trust in a +# nightly (tracker#7). common/removelists-final/turnkey removes the same +# paths at the end of the build, whatever a recipe does. The appliance's own +# Keel source and its 990 pin are common's (overlays/turnkey.d/keel-apt), so +# nothing the image keeps may still name the build time archive. rm -f /etc/apt/sources.list.d/keel-staging.list +rm -f /etc/apt/preferences.d/keel-staging rm -f /etc/apt/keyrings/keel-staging-keyring.asc rm -rf /srv/keel-apt rm -rf /var/lib/apt/lists/* -grep -q '^Enabled: no' /etc/apt/sources.list.d/keel.sources +if grep -rlsE 'trixie-staging|/srv/keel-apt|l=Keel Linux staging' /etc/apt/sources.list \ + /etc/apt/sources.list.d /etc/apt/preferences /etc/apt/preferences.d; then + echo "the apt files above still name the build time archive" >&2 + exit 1 +fi diff --git a/overlay/etc/apt/preferences.d/keel b/overlay/etc/apt/preferences.d/keel deleted file mode 100644 index dcfdba2..0000000 --- a/overlay/etc/apt/preferences.d/keel +++ /dev/null @@ -1,5 +0,0 @@ -# Keel Linux: prefer the project's packages over every other archive. -# Generated by bin/pin-file of the apt tooling; the same file keel-transition installs. -Package: * -Pin: release o=Keel Linux -Pin-Priority: 1001 diff --git a/overlay/etc/apt/sources.list.d/keel.sources b/overlay/etc/apt/sources.list.d/keel.sources deleted file mode 100644 index 75032bc..0000000 --- a/overlay/etc/apt/sources.list.d/keel.sources +++ /dev/null @@ -1,17 +0,0 @@ -# Keel Linux package repository (brief section 5.4). -# -# Disabled until the repository is published and signed: the signing subkey -# is being rotated and apt.keellinux.org is not serving yet. The evaluation -# build took inithooks, confconsole and keel from the build host's unsigned -# staging distribution through a source that existed only during the build -# and was removed from this image (conf.d/main). Never point this file at -# trixie-staging: it is unsigned by design. -# -# To enable once the key is installed as /usr/share/keyrings/keel-archive-keyring.gpg: -# change "Enabled: no" to "Enabled: yes" and run apt update. -Types: deb -URIs: https://apt.keellinux.org -Suites: trixie -Components: main -Enabled: no -Signed-By: /usr/share/keyrings/keel-archive-keyring.gpg diff --git a/tests/apt-files.bats b/tests/apt-files.bats new file mode 100644 index 0000000..bf129b5 --- /dev/null +++ b/tests/apt-files.bats @@ -0,0 +1,58 @@ +#!/usr/bin/env bats +# The apt files this recipe leaves in the image (Keel-Linux/common#30, +# tracker#23). Common ships the appliance's Keel source and its pin at 990 +# (overlays/turnkey.d/keel-apt); a recipe overlay at the same paths would win +# over them, so this recipe ships neither. The build time archive still has +# to win over TurnKey's 999 pin while the recipe upgrades the project +# packages, so conf.d/main pins it by its Label for the build only. +# +# conf.d/main runs inside a chroot during the build; what it leaves is proved +# on the booted machine by the boot test. These check the recipe itself. + +bats_require_minimum_version 1.5.0 + +setup() { + REPO="$(cd "$BATS_TEST_DIRNAME/.." && pwd)" + MAIN="$REPO/conf.d/main" +} + +# line LITERAL: the line number of the first line of conf.d/main equal to it +line() { + grep -nxF -- "$1" "$MAIN" | head -n 1 | cut -d: -f1 +} + +@test "the overlay ships no Keel source and no Keel pin" { + [ ! -e "$REPO/overlay/etc/apt/sources.list.d/keel.sources" ] + [ ! -e "$REPO/overlay/etc/apt/preferences.d/keel" ] + run ! grep -rlsE 'Pin-Priority: *1001' "$REPO/overlay" +} + +@test "the build time pin names the staging Label, and is written before the upgrade" { + local pin upgrade + pin="$(line "printf 'Package: *\nPin: release l=Keel Linux staging\nPin-Priority: 1001\n' \\")" + # the backslash is the script's line continuation, matched literally + # shellcheck disable=SC1003 + upgrade="$(line 'apt-get install -y --only-upgrade \')" + [ -n "$pin" ] + [ -n "$upgrade" ] + [ "$pin" -lt "$upgrade" ] + grep -qxF ' > /etc/apt/preferences.d/keel-staging' "$MAIN" +} + +@test "the build time pin goes with the build time source" { + local list pin + list="$(line 'rm -f /etc/apt/sources.list.d/keel-staging.list')" + pin="$(line 'rm -f /etc/apt/preferences.d/keel-staging')" + [ -n "$list" ] + [ -n "$pin" ] + [ "$pin" -eq $((list + 1)) ] +} + +@test "the build fails when an apt file still names the build time archive" { + grep -qF "grep -rlsE 'trixie-staging|/srv/keel-apt|l=Keel Linux staging'" "$MAIN" + run ! grep -q "Enabled: no' /etc/apt/sources.list.d/keel.sources" "$MAIN" +} + +@test "conf.d/main parses" { + bash -n "$MAIN" +} From 689031a064c0532ae88b7c33a2ccdc65f998b80e Mon Sep 17 00:00:00 2001 From: navigator Date: Fri, 2 Oct 2026 15:50:45 +0000 Subject: [PATCH 2/2] fix: the overlay change gets its own changelog entry require-changelog wants a new top entry, not a bullet in the base branch's. --- changelog | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/changelog b/changelog index 5bd7df1..7eb3ef8 100644 --- a/changelog +++ b/changelog @@ -1,4 +1,4 @@ -turnkey-postgresql-19.0 (4) turnkey; urgency=low +turnkey-postgresql-19.0 (5) turnkey; urgency=low * The overlay no longer ships /etc/apt/sources.list.d/keel.sources (apt.keellinux.org, disabled) or /etc/apt/preferences.d/keel (the Keel @@ -12,6 +12,10 @@ turnkey-postgresql-19.0 (4) turnkey; urgency=low time archive, in place of the check that keel.sources was disabled. tests/apt-files.bats checks the recipe. + -- Marcos Mendez Fri, 02 Oct 2026 17:00:00 +0000 + +turnkey-postgresql-19.0 (4) turnkey; urgency=low + * bin/keel-archive-check refuses a trusted=yes on the project archive rather than on every apt source in the build tree. The captured pool of decision 0012 sets Trusted: yes on purpose, for a file: index generated on this