Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions quest/m1/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,7 @@ transport, benchmark tooling); worktrees isolate commits, not semantics.
- [JS closed-track leak](/quest/m1/js-closed-track-leak.md) - on dev, a subscriber that joins a closed JS track with unlimited retention is released instead of cached forever
- [Session death parity](/quest/m1/session-death.md) - a local close ends tracks cleanly in both languages, and JS group readers see the session's error on session death
- [Watch and publish under CSP](/quest/m1/csp-assets.md) - blob workers stay the default; strict-CSP apps host the files and set a base URL
- [Signed RPMs](/quest/m1/rpm-signing.md) - `dnf install` from rpm.moq.dev succeeds with `gpgcheck=1`, and the docs add the repo in a form dnf5 accepts
- [More tests under load](/quest/m1/test-flakes-2.md) - the second round of load-only failures, fixed at the cause
- [CI runner stalls](/quest/m1/ci-runner-stalls.md) - the 0.4 to 0.8 s freezes of both interop tracks on CI are attributed from a week of nightlies and fixed or told apart from playback bugs
- [Catalog estimate rate](/quest/m1/catalog-estimate-rate.md) - a rising `jitter`/`delay` estimate republishes the catalog at most once a second, in js/publish and moq-mux
Expand Down
36 changes: 36 additions & 0 deletions quest/m1/rpm-signing.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# [S] Signed RPMs install from rpm.moq.dev

## Goal

`dnf install moq moq-relay gstreamer1-moq` from rpm.moq.dev succeeds on
Fedora and RHEL with the repository's `gpgcheck=1` left on, following the
install lines the docs print.

## Plan

- Today every install fails. `moq.repo` sets `gpgcheck=1` and
`repo_gpgcheck=1`, but `infra/rpm/publish.sh` signs only `repomd.xml`, so
dnf refuses each package: "The package is not signed". Reproduced on a
Fedora 43 container against `gstreamer1-moq-0.4.8` and `moq-0.12.8`;
`rpm -Kv` shows digests and no signature.
- Sign each package with the existing `SIGNING_KEY` (`rpmsign --addsign`,
`%_gpg_name` set to the imported key id) before `createrepo_c`, so the
Comment on lines +16 to +17

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Pass the signing password to rpmsign

With the passphrase-protected project key configured as SIGNING_PASSWORD in infra/README.md, the pinned RPM 4.20.1 rpmsign --addsign invoked with only %_gpg_name calls pinentry and exits with signing failed: Inappropriate ioctl for device in the noninteractive workflow; its --help exposes key selection but no password option. Require a secure noninteractive handoff of SIGNING_PASSWORD, such as priming gpg-agent, or the planned publisher will fail before regenerating the repository.

Useful? React with 馃憤聽/ 馃憥.

repodata checksums cover the signed files. The pool is pulled back from R2
on every run, so sign the whole merged pool, not just the new artifacts; the
packages already published are unsigned and must be replaced.
Comment on lines +19 to +20

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Invalidate caches before replacing unsigned RPMs

When this migration overwrites the existing unsigned R2 objects at the same URLs, infra/rpm/src/worker.ts has already served every .rpm with public, max-age=2592000, immutable. Any HTTP cache holding an old URL may therefore serve the unsigned bytes for 30 days while the regenerated metadata advertises the signed file's checksum, causing installs to fail even after publishing succeeds. Include a cache purge, versioned object URLs, or a staged cache-policy change before replacing the pool.

Useful? React with 馃憤聽/ 馃憥.

- Keep `gpgcheck=1`. Dropping it to lean on `repo_gpgcheck` alone would
paper over the gap rather than close it.
- The docs print `sudo dnf config-manager --add-repo`, which is dnf4 syntax;
Fedora 41+ ships dnf5, which rejects it. Replace it with
`sudo curl -fsSL https://rpm.moq.dev/moq.repo -o /etc/yum.repos.d/moq.repo`,
which works on both, in `doc/setup/install.md`, `rs/moq-relay/README.md`,
and `rs/moq-gst/README.md`. The "Fedora 39+" note in the install doc goes
with it.
- Verify with a `workflow_dispatch` of `rpm-repo.yml`, then a clean Fedora and
a clean Rocky 9 container: add the repo as documented, install all three
packages with `gpgcheck=1`, and check `rpm -Kv` reports the project key.

## Related

- [Workflows call just](/quest/m1/tooling/workflows-call-just.md) - moves the
rpm publish step behind `just infra rpm publish`; either can land first