-
-
Notifications
You must be signed in to change notification settings - Fork 252
fix(rpm): sign every package so gpgcheck=1 installs work #4571
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
2 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[P2] Preserve signed RPM bytes when re-publishing the same tag
On a later rerun of rpm-repo.yml for an already-published tag, the unconditional copies at lines 65/69 replace that tag鈥檚 signed pool entries with the original unsigned GitHub artifacts. This --addsign call therefore cannot take its identical-signature skip path: GPG creates a fresh timestamped signature and the same package URL gets a different whole-file checksum. Clients holding still-valid pre-rerun repository metadata then download the new bytes and fail DNF checksum verification; no HTTP intermediary cache is required. Preserve the existing signed entry when re-ingesting the same artifact, or use a new immutable object path. Add a two-run, same-artifact regression asserting every published RPM鈥檚 SHA-256 stays unchanged, including the incoming artifact rather than only untouched pool packages.
(Written by OpenAI)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Reproduced this locally with rpm 4.20.1 (the version the nix
packagingoutput hands to CI), and the finding holds:rpmsign --addsignon a package this key already signed printsalready contains identical signature, skippingand leaves the bytes untouched. The skip path really does exist.cpat lines 65/69 runs first and overwrites the signed pool entry with the unsigned GitHub artifact, so that skip path is unreachable for any re-ingested package. Signing the same source again mints a fresh timestamped signature, so the whole-file SHA-256 at a stable URL changes.So this is real, and it is not limited to a hypothetical rerun: the first
workflow_dispatchafter this merges, against the latest release tag, hits exactly this path, because that tag's packages are already in the pool from the auto-triggered unsigned run.I am not fixing it here because the fix is a release-semantics decision, not a mechanical one. Two things have to be answered first:
Recommendation: option A, make the pool immutable per package filename. Skip the copy when the destination already exists. A rerun then becomes a no-op for package bytes, which is what makes
rpmsign's skip path worth having, and the whole run becomes idempotent. It also matches how the repo is consumed: the package URL is a stable identity, and the repodata checksum is what clients verify against.The cost is that a rebuilt same-version artifact can no longer be republished under the same name. I think that cost is correct. Re-cutting a release should mint a new version, and the escape hatch should be a deliberate bucket edit rather than a routine workflow run.
Worth pairing with it, in the same follow-up:
metadata_expireinmoq.repo. It is unset today, so the stale-metadata window is whatever dnf's default is, and that window is the only thing standing between a rerun and aCHKERRon a client.trigger-repo-publish.sha no-op when the tag's artifacts are already in the pool, so a re-run release workflow does not start the cycle at all.The two-run regression in this comment is worth having, but it has to assert whichever option we pick, and there is no harness for
publish.shat all today, so I would scope it with the fix rather than bolt a fake rclone and GPG stack onto a release-infra PR.Suggested as a follow-up quest rather than landed here.
Scope note on what I could and could not verify: I exercised the GPG plumbing locally with a throwaway key, and both new paths work,
rpmsignwith_gpg_sign_cmd_extra_args --batch --pinentry-mode loopback --passphrase-file, and the existingrepomd.xmldetached signature now that it uses--passphrase-fileinstead of--passphrase. I could not run the real flow: no signing key, no R2 bucket.(Written by Space Bunny Free)