diff --git a/quest/m1/README.md b/quest/m1/README.md index 5b99fdc6e0..742d635823 100644 --- a/quest/m1/README.md +++ b/quest/m1/README.md @@ -38,6 +38,7 @@ transport, benchmark tooling); worktrees isolate commits, not semantics. - [JS closed-track leak](/quest/m1/js-closed-track-leak.md) - on dev, a subscriber that joins a closed JS track with unlimited retention is released instead of cached forever - [Session death parity](/quest/m1/session-death.md) - a local close ends tracks cleanly in both languages, and JS group readers see the session's error on session death - [Watch and publish under CSP](/quest/m1/csp-assets.md) - blob workers stay the default; strict-CSP apps host the files and set a base URL +- [Signed RPMs](/quest/m1/rpm-signing.md) - `dnf install` from rpm.moq.dev succeeds with `gpgcheck=1`, and the docs add the repo in a form dnf5 accepts - [More tests under load](/quest/m1/test-flakes-2.md) - the second round of load-only failures, fixed at the cause - [CI runner stalls](/quest/m1/ci-runner-stalls.md) - the 0.4 to 0.8 s freezes of both interop tracks on CI are attributed from a week of nightlies and fixed or told apart from playback bugs - [Catalog estimate rate](/quest/m1/catalog-estimate-rate.md) - a rising `jitter`/`delay` estimate republishes the catalog at most once a second, in js/publish and moq-mux diff --git a/quest/m1/rpm-signing.md b/quest/m1/rpm-signing.md new file mode 100644 index 0000000000..33c7d1d8e5 --- /dev/null +++ b/quest/m1/rpm-signing.md @@ -0,0 +1,36 @@ +# [S] Signed RPMs install from rpm.moq.dev + +## Goal + +`dnf install moq moq-relay gstreamer1-moq` from rpm.moq.dev succeeds on +Fedora and RHEL with the repository's `gpgcheck=1` left on, following the +install lines the docs print. + +## Plan + +- Today every install fails. `moq.repo` sets `gpgcheck=1` and + `repo_gpgcheck=1`, but `infra/rpm/publish.sh` signs only `repomd.xml`, so + dnf refuses each package: "The package is not signed". Reproduced on a + Fedora 43 container against `gstreamer1-moq-0.4.8` and `moq-0.12.8`; + `rpm -Kv` shows digests and no signature. +- Sign each package with the existing `SIGNING_KEY` (`rpmsign --addsign`, + `%_gpg_name` set to the imported key id) before `createrepo_c`, so the + repodata checksums cover the signed files. The pool is pulled back from R2 + on every run, so sign the whole merged pool, not just the new artifacts; the + packages already published are unsigned and must be replaced. +- Keep `gpgcheck=1`. Dropping it to lean on `repo_gpgcheck` alone would + paper over the gap rather than close it. +- The docs print `sudo dnf config-manager --add-repo`, which is dnf4 syntax; + Fedora 41+ ships dnf5, which rejects it. Replace it with + `sudo curl -fsSL https://rpm.moq.dev/moq.repo -o /etc/yum.repos.d/moq.repo`, + which works on both, in `doc/setup/install.md`, `rs/moq-relay/README.md`, + and `rs/moq-gst/README.md`. The "Fedora 39+" note in the install doc goes + with it. +- Verify with a `workflow_dispatch` of `rpm-repo.yml`, then a clean Fedora and + a clean Rocky 9 container: add the repo as documented, install all three + packages with `gpgcheck=1`, and check `rpm -Kv` reports the project key. + +## Related + +- [Workflows call just](/quest/m1/tooling/workflows-call-just.md) - moves the + rpm publish step behind `just infra rpm publish`; either can land first