Devuan bug report logs - #777
cron-apt does not report repositories with GPG problems

version graph

Package: cron-apt; Maintainer for cron-apt is (unknown); Source for cron-apt is src:cron-apt.

Reported by: Koos van den Hout <koos@kzdoos.xs4all.nl>

Date: Wed, 30 Aug 2023 08:12:01 UTC

Severity: normal

Merged with 778

Found in version 0.13.0

Done: Mark Hindley <mark@hindley.org.uk>

Full log


Message #5 received at submit@bugs.devuan.org (full text, mbox, reply):

Received: (at submit) by bugs.devuan.org; 30 Aug 2023 08:10:31 +0000
Return-Path: <koos@kzdoos.xs4all.nl>
Delivered-To: bugs@devuan.org
Received: from email.devuan.org [2a01:4f8:140:32a1::58c6:6473]
	by doc.devuan.org with IMAP (fetchmail-6.4.16)
	for <debbugs@localhost> (single-drop); Wed, 30 Aug 2023 08:10:31 +0000 (UTC)
Received: from email.devuan.org
	by email.devuan.org with LMTP
	id CDtgAiL57mSMNwAAmSBk0A
	(envelope-from <koos@kzdoos.xs4all.nl>)
	for <bugs@devuan.org>; Wed, 30 Aug 2023 08:09:06 +0000
Received: by email.devuan.org (Postfix, from userid 109)
	id F3C4F8CF; Wed, 30 Aug 2023 08:09:05 +0000 (UTC)
X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on email.devuan.org
X-Spam-Level: 
X-Spam-Status: No, score=-0.0 required=5.0 tests=SPF_HELO_PASS autolearn=ham
	autolearn_force=no version=3.4.6
Received-SPF: Pass (sender SPF authorized) identity=helo; client-ip=2a10:3781:1669:1::23; helo=gosper.idefix.net; envelope-from=koos@kzdoos.xs4all.nl; receiver=<UNKNOWN> 
Received: from gosper.idefix.net (gosper.idefix.net [IPv6:2a10:3781:1669:1::23])
	by email.devuan.org (Postfix) with ESMTPS id D0D241D
	for <submit@bugs.devuan.org>; Wed, 30 Aug 2023 08:09:03 +0000 (UTC)
Received: from gosper.idefix.net (localhost [IPv6:0:0:0:0:0:0:0:1])
	by gosper.idefix.net (8.15.2/8.15.2/Debian-14~deb10u1) with ESMTPS id 37U88xFG024804
	(version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT);
	Wed, 30 Aug 2023 10:09:00 +0200
Received: (from koos@localhost)
	by gosper.idefix.net (8.15.2/8.15.2/Submit) id 37U88xWv024803;
	Wed, 30 Aug 2023 10:08:59 +0200
X-Authentication-Warning: gosper.idefix.net: koos set sender to koos@kzdoos.xs4all.nl using -f
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Koos van den Hout <koos@kzdoos.xs4all.nl>
To: Devuan Bug Tracking System <submit@bugs.devuan.org>
Subject: cron-apt does not report repositories with GPG problems
Message-ID: <169338293943.22928.1126947161839227298.reportbug@gosper.idefix.net>
X-Mailer: reportbug 7.5.3+devuan3
Date: Wed, 30 Aug 2023 10:08:59 +0200
X-Virus-Scanned: clamav-milter 0.103.9 at gosper
X-Virus-Status: Clean
Package: cron-apt
Version: 0.13.0
Severity: normal

Dear Maintainer,

I noticed the following using cron-apt: when a repository rotates its
GPG keys, cron-apt does not act on the error message about the unavailable
GPG key. This makes cron-apt not report about updates until a manual run
of apt update shows there is a problem with this repository and this is
fixed.

I expected cron-apt to report this error because this holds back updates
when the GPG key for a repository is updated.

I ran into this with the Grafana repository. There were no messages from
cron-apt, but by hand I saw the key had changed:

root@gosper:~# apt update
Get:1 https://packages.grafana.com/oss/deb stable InRelease [5,984 B]
Err:1 https://packages.grafana.com/oss/deb stable InRelease
  The following signatures couldn't be verified because the public key is not av
ailable: NO_PUBKEY 963FA27710458545
Hit:2 http://deb.devuan.org/merged beowulf InRelease
Hit:3 http://deb.devuan.org/merged beowulf-security InRelease
Hit:4 http://deb.devuan.org/merged beowulf-updates InRelease
Reading package lists... Done
Building dependency tree
Reading state information... Done
All packages are up to date.
W: An error occurred during the signature verification. The repository is not up
dated and the previous index files will be used. GPG error: https://packages.gra
fana.com/oss/deb stable InRelease: The following signatures couldn't be verified
 because the public key is not available: NO_PUBKEY 963FA27710458545
W: Failed to fetch https://packages.grafana.com/oss/deb/dists/stable/InRelease
The following signatures couldn't be verified because the public key is not avai
lable: NO_PUBKEY 963FA27710458545
W: Some index files failed to download. They have been ignored, or old ones used
 instead.


-- System Information:
Distributor ID:	Devuan
Description:	Devuan GNU/Linux 3 (beowulf)
Release:	3
Codename:	beowulf
Architecture: x86_64

Kernel: Linux 4.19.0-24-amd64 (SMP w/6 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)
LSM: AppArmor: enabled

Versions of packages cron-apt depends on:
ii  apt  1.8.2.3

Versions of packages cron-apt recommends:
ii  cron [cron-daemon]                   3.0pl1-134+deb10u1
ii  liblockfile1                         1.14-1.1
ii  sendmail-bin [mail-transport-agent]  8.15.2-14~deb10u1

cron-apt suggests no packages.

-- Configuration Files:
/etc/cron-apt/config changed:
MAILON="upgrade"


-- no debconf information

Send a report that this bug log contains spam.


Devuan BTS -- Powered by Debian bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.

Devuan Bugs Owner <owner@bugs.devuan.org>.
Last modified: Sat Sep 28 23:18:05 2024;