[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#401114: marked as done (debian-archive-keyring: should probably depend on apt >= 0.6)



Your message dated Tue, 05 Dec 2006 11:32:03 +0000
with message-id <E1GrYWp-0002Vo-7y@ries.debian.org>
and subject line Bug#401114: fixed in apt 0.6.46.3-0.1
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: debian-archive-keyring
Version: 2006.11.22
Severity: serious

debian-archive-keyring does not depent on an apt that comes with
apt-key, so in the course of upgrading from sarge to etch one can
end up with a system that has only two keys in apt's keyring,
the signing keys from 2005 and 2006 which are shipped with apt itself.

In the case where I found this I just did an apt-get dist-upgrade from a
quite minimal system, but the issue can easily triggered manually:

| root@simona:/# echo 'deb http://ftp.tu-graz.ac.at/mirror/debian/ etch main' >  /etc/apt/sources.list
| root@simona:/# apt-get update
| Get:1 http://ftp.tu-graz.ac.at etch/main Packages [5600kB]
| Get:2 http://ftp.tu-graz.ac.at etch/main Release [81B]
| Fetched 5600kB in 1s (3851kB/s)
| Reading Package Lists... Done

| root@simona:/# apt-get install debian-archive-keyring
| Reading Package Lists... Done
| Building Dependency Tree... Done
| The following extra packages will be installed:
|   gnupg gpgv libbz2-1.0 libc6 libc6-dev libgcrypt11 libgnutls13 libgpg-error0 libldap2 liblzo1 libncurses5 libopencdk8 libreadline5 libsasl2 libtasn1-3
|   libusb-0.1-4 makedev readline-common tzdata
| Suggested packages:
|   gnupg-doc xloadimage locales glibc-doc manpages-dev rng-tools gnutls-bin hotplug
| Recommended packages:
|   libgpmg1 libsasl2-modules libtasn1-3-bin
| The following NEW packages will be installed:
|   debian-archive-keyring gnupg gpgv libbz2-1.0 libgcrypt11 libgnutls13 libgpg-error0 libldap2 liblzo1 libopencdk8 libreadline5 libsasl2 libtasn1-3
|   libusb-0.1-4 makedev readline-common tzdata
| The following packages will be upgraded:
|   libc6 libc6-dev libncurses5
| 3 upgraded, 17 newly installed, 0 to remove and 62 not upgraded.
| Need to get 810kB/11.5MB of archives.
| After unpacking 11.9MB of additional disk space will be used.
| Do you want to continue? [Y/n] 
[...]
| 
| Setting up gpgv (1.4.5-2) ...
| Setting up makedev (2.3.1-83) ...
| 
| Setting up gnupg (1.4.5-2) ...
| Setting up debian-archive-keyring (2006.11.22) ...
| 
| root@simona:/#


| root@simona:/# apt-get install apt
| Reading Package Lists... Done
| Building Dependency Tree... Done
| The following extra packages will be installed:
|   gcc-4.1-base libgcc1 libstdc++6
| Suggested packages:
|   aptitude synaptic gnome-apt wajig apt-doc bzip2
| The following NEW packages will be installed:
|   gcc-4.1-base libstdc++6
| The following packages will be upgraded:
|   apt libgcc1
| 2 upgraded, 2 newly installed, 0 to remove and 60 not upgraded.
| Need to get 0B/1947kB of archives.
| 
| (Reading database ... 8093 files and directories currently installed.)
| Preparing to replace apt 0.5.28.6 (using .../archives/apt_0.6.46.2_i386.deb) ...
| Unpacking replacement apt ...
| Setting up apt (0.6.46.2) ...
| 
| root@simona:/# apt-key list
| gpg: /etc/apt/trustdb.gpg: trustdb created
| /etc/apt/trusted.gpg
| --------------------
| pub   1024D/4F368D5D 2005-01-31 [expired: 2006-01-31]
| uid                  Debian Archive Automatic Signing Key (2005) <ftpmaster@debian.org>
| 
| pub   1024D/2D230C5F 2006-01-03 [expires: 2007-02-07]
| uid                  Debian Archive Automatic Signing Key (2006) <ftpmaster@debian.org>
| 
| root@simona:/#




Also, when doing it in one go this happens:
[on a fresh sarge again:]

| root@simona:/# echo 'deb http://ftp.tu-graz.ac.at/mirror/debian/ etch main' >  /etc/apt/sources.list
| root@simona:/# apt-get update
| Get:1 http://ftp.tu-graz.ac.at etch/main Packages [5600kB]
| Get:2 http://ftp.tu-graz.ac.at etch/main Release [81B]
| Fetched 5600kB in 1s (3976kB/s)
| Reading Package Lists... Done
| root@simona:/#  apt-get install apt
| Reading Package Lists... Done
| Building Dependency Tree... Done
| The following extra packages will be installed:
|   debian-archive-keyring gcc-4.1-base gnupg gpgv libbz2-1.0 libc6 libc6-dev libgcc1 libgcrypt11 libgnutls13 libgpg-error0 libldap2 liblzo1 libncurses5
|   libopencdk8 libreadline5 libsasl2 libstdc++6 libtasn1-3 libusb-0.1-4 makedev readline-common tzdata
| Suggested packages:
|   aptitude synaptic gnome-apt wajig apt-doc bzip2 gnupg-doc xloadimage locales glibc-doc manpages-dev rng-tools gnutls-bin hotplug
| Recommended packages:
|   libgpmg1 libsasl2-modules libtasn1-3-bin
| The following NEW packages will be installed:
|   debian-archive-keyring gcc-4.1-base gnupg gpgv libbz2-1.0 libgcrypt11 libgnutls13 libgpg-error0 libldap2 liblzo1 libopencdk8 libreadline5 libsasl2
|   libstdc++6 libtasn1-3 libusb-0.1-4 makedev readline-common tzdata
| The following packages will be upgraded:
|   apt libc6 libc6-dev libgcc1 libncurses5
| 5 upgraded, 19 newly installed, 0 to remove and 60 not upgraded.
| Need to get 0B/13.4MB of archives.
| After unpacking 13.6MB of additional disk space will be used.
| Do you want to continue? [Y/n] 
| Selecting previously deselected package tzdata.
| (Reading database ... 7755 files and directories currently installed.)
[...]
| 
| Setting up gnupg (1.4.5-2) ...
| Setting up debian-archive-keyring (2006.11.22) ...
| 
| (Reading database ... 8093 files and directories currently installed.)
| Preparing to replace apt 0.5.28.6 (using .../archives/apt_0.6.46.2_i386.deb) ...
| Unpacking replacement apt ...
| Setting up apt (0.6.46.2) ...
| 
| Setting up libc6-dev (2.3.6.ds1-8) ...
| root@simona:/# apt-key list
| gpg: /etc/apt/trustdb.gpg: trustdb created
| /etc/apt/trusted.gpg
| --------------------
| pub   1024D/4F368D5D 2005-01-31 [expired: 2006-01-31]
| uid                  Debian Archive Automatic Signing Key (2005) <ftpmaster@debian.org>
| 
| pub   1024D/2D230C5F 2006-01-03 [expires: 2007-02-07]
| uid                  Debian Archive Automatic Signing Key (2006) <ftpmaster@debian.org>
| 
| root@simona:/# 


I think this issue warants release critical status, if the RMs think
otherwise please downgrade it.

-- 
Peter


--- End Message ---
--- Begin Message ---
Source: apt
Source-Version: 0.6.46.3-0.1

We believe that the bug you reported is fixed in the latest version of
apt, which is due to be installed in the Debian FTP archive:

apt-doc_0.6.46.3-0.1_all.deb
  to pool/main/a/apt/apt-doc_0.6.46.3-0.1_all.deb
apt_0.6.46.3-0.1.dsc
  to pool/main/a/apt/apt_0.6.46.3-0.1.dsc
apt_0.6.46.3-0.1.tar.gz
  to pool/main/a/apt/apt_0.6.46.3-0.1.tar.gz
libapt-pkg-doc_0.6.46.3-0.1_all.deb
  to pool/main/a/apt/libapt-pkg-doc_0.6.46.3-0.1_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 401114@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andreas Barth <aba@not.so.argh.org> (supplier of updated apt package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Tue,  5 Dec 2006 10:34:56 +0000
Source: apt
Binary: apt-utils libapt-pkg-doc libapt-pkg-dev apt-doc apt
Architecture: source all
Version: 0.6.46.3-0.1
Distribution: unstable
Urgency: high
Maintainer: APT Development Team <deity@lists.debian.org>
Changed-By: Andreas Barth <aba@not.so.argh.org>
Description: 
 apt        - Advanced front-end for dpkg
 apt-doc    - Documentation for APT
 apt-utils  - APT utility programs
 libapt-pkg-dev - Development files for APT's libapt-pkg and libapt-inst
 libapt-pkg-doc - Documentation for APT development
Closes: 400874 401017 401114
Changes: 
 apt (0.6.46.3-0.1) unstable; urgency=high
 .
   * Non-maintainer upload with permission of Michael Vogt.
   * Fix segfault at apt-get source. Closes: #400874
   * Add apt-key update in postinst, so that debian-archive-keyring doesn't
     need to depend on apt >= 0.6. Closes: #401114
   * Don't double-queue pdiff files. Closes: #401017
Files: 
 29db8a90c9c9a579693f5224189239df 796 admin important apt_0.6.46.3-0.1.dsc
 6884258841c3ef4294e441694fc26a2d 1793085 admin important apt_0.6.46.3-0.1.tar.gz
 704ace660caf4bc69adf670b8a9f3f5f 91384 doc optional apt-doc_0.6.46.3-0.1_all.deb
 5b88479ea37cf572fb224f5b4a1f52e4 112860 doc optional libapt-pkg-doc_0.6.46.3-0.1_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFFdVS3mdOZoew2oYURAkvdAKCMaDOQ1Xa7+rZ4d4P1/kn541dCHACdF3d2
Wg9DzIhwvArv8BUuWFOeCYE=
=tt6b
-----END PGP SIGNATURE-----


--- End Message ---

Reply to: