From 040eabc02291c81cb1ef9c55a870db4ebf5946eb Mon Sep 17 00:00:00 2001 From: Luke Curley Date: Tue, 29 Sep 2026 19:28:52 -0700 Subject: [PATCH 1/2] chore(quest): claim quest/m1/rpm-signing Co-Authored-By: Claude Opus 5.5 From 86a367cd09db81a4bff1773bda0ec4e45a130ffd Mon Sep 17 00:00:00 2001 From: Luke Curley Date: Tue, 29 Sep 2026 19:33:00 -0700 Subject: [PATCH 2/2] fix(rpm): sign every package so gpgcheck=1 installs work moq.repo sets gpgcheck=1, but publish.sh only signed repomd.xml, so dnf rejected every package as unsigned. Sign the whole merged pool with the existing key before createrepo_c, so packages published earlier get signed too. rpmsign skips packages already signed by the key. Co-Authored-By: Claude Opus 5.5 --- infra/rpm/publish.sh | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) diff --git a/infra/rpm/publish.sh b/infra/rpm/publish.sh index d8a61ba142..f8d2be9e37 100755 --- a/infra/rpm/publish.sh +++ b/infra/rpm/publish.sh @@ -2,7 +2,8 @@ # # Regenerate yum/dnf repo metadata and push to the rpm-moq-dev R2 bucket. # Pull the current pool, merge in new .rpm files from $ARTIFACTS_DIR, -# rebuild repodata with createrepo_c, sign repomd.xml with GPG, and upload. +# sign every package, rebuild repodata with createrepo_c, sign repomd.xml +# with GPG, and upload. # # Required env: # ARTIFACTS_DIR directory containing new .rpm files to add @@ -12,7 +13,7 @@ # SIGNING_KEY ascii-armored GPG private key (shared with apt repo and maven publishing) # SIGNING_PASSWORD optional passphrase for SIGNING_KEY # -# Required tools: rclone, createrepo_c, gpg. +# Required tools: rclone, rpmsign, createrepo_c, gpg. set -euo pipefail @@ -86,11 +87,24 @@ if [[ ${#KEY_IDS[@]} -ne 1 ]]; then exit 1 fi KEY_ID="${KEY_IDS[0]}" +# Read the passphrase from a file so it never appears in a process list. GPG_PASS_ARGS=() if [[ -n "${SIGNING_PASSWORD:-}" ]]; then - GPG_PASS_ARGS=(--pinentry-mode loopback --passphrase "$SIGNING_PASSWORD") + printf '%s' "$SIGNING_PASSWORD" >"$GNUPGHOME/passphrase" + GPG_PASS_ARGS=(--pinentry-mode loopback --passphrase-file "$GNUPGHOME/passphrase") fi +# moq.repo sets gpgcheck=1, so dnf rejects any unsigned package. Sign the whole +# merged pool, not just the new artifacts: packages published before signing +# existed need it too. rpmsign skips any package already signed by this key, +# so only new or unsigned packages change and get re-uploaded. +echo ">> Sign packages..." +mapfile -t POOL < <(find "$WORK/${DIST}" -name '*.rpm') +rpmsign --addsign \ + --define "_gpg_name ${KEY_ID}" \ + --define "_gpg_sign_cmd_extra_args --batch ${GPG_PASS_ARGS[*]}" \ + "${POOL[@]}" + echo ">> Generate repodata per arch..." for arch in "${ARCHES[@]}"; do dir="$WORK/${DIST}/${arch}"