[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#772676: marked as done (apt: accesses files not listed in Release file)



Your message dated Thu, 11 Dec 2014 01:37:34 +0100
with message-id <20141211003734.GB16834@crossbow>
and subject line Re: Bug#772676: apt: accesses files not listed in Release file
has caused the Debian Bug report #772676,
regarding apt: accesses files not listed in Release file
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
772676: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=772676
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: apt
Version: 1.0.9.4
Severity: important
Justification: at least that, maybe worse if it would actually use these files

I just answered someone where to find my own APT repository, when I had
a tail -F on the access_log running, and was amazed to see (anonymised):

ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/InRelease HTTP/1.1" 404 338 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/Release.gpg HTTP/1.1" 200 473 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/Release HTTP/1.1" 200 13025 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/source/Sources.bz2 HTTP/1.1" 404 351 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-amd64/Packages.bz2 HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-i386/Packages.bz2 HTTP/1.1" 404 357 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.bz2 HTTP/1.1" 404 359 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.bz2 HTTP/1.1" 404 356 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/source/Sources.xz HTTP/1.1" 404 350 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-amd64/Packages.xz HTTP/1.1" 404 357 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-i386/Packages.xz HTTP/1.1" 404 356 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.xz HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.xz HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:15 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/source/Sources.lzma HTTP/1.1" 404 352 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:15 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-amd64/Packages.lzma HTTP/1.1" 404 359 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:15 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-i386/Packages.lzma HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:15 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.lzma HTTP/1.1" 404 360 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:15 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.lzma HTTP/1.1" 404 357 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:16 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/source/Sources.gz HTTP/1.1" 200 5231 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:16 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-amd64/Packages.gz HTTP/1.1" 200 16902 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:16 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-i386/Packages.gz HTTP/1.1" 200 16896 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:16 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.gz HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:17 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.gz HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:17 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:17 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en HTTP/1.1" 404 352 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:41 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/Pkgs/wtf-debian-keyring/wtf-debian-keyring_20141120_all.deb HTTP/1.1" 200 10232 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:45 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/InRelease HTTP/1.1" 404 338 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:45 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/Release.gpg HTTP/1.1" 200 473 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:45 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/Release HTTP/1.1" 200 13025 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:46 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/source/Sources.gz HTTP/1.1" 200 5231 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:46 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-amd64/Packages.gz HTTP/1.1" 200 16902 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-i386/Packages.gz HTTP/1.1" 200 16896 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.bz2 HTTP/1.1" 404 359 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.bz2 HTTP/1.1" 404 356 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.xz HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.xz HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.lzma HTTP/1.1" 404 360 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.lzma HTTP/1.1" 404 357 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.gz HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.gz HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"
ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en HTTP/1.1" 404 352 "-" "Debian APT-HTTP/1.3 (1.0.9.4)"

So, *why* is APT accessing files that are not listed in the Release
file (*.{bz2,xz,lzma} and Translation*)?

The current Release file is:

Origin: The MirOS Project
Label: wtf
Suite: sid
Codename: sid
Date: Sun Dec  7 15:20:21 UTC 2014
Architectures: all alpha amd64 arm arm64 armel armhf hppa hurd-i386 i386 ia64 kfreebsd-amd64 kfreebsd-i386 m68k mips mipsel powerpc powerpcspe ppc64 s390 s390x sh4 sparc sparc64 x32 source
Components: wtf
Description: WTF DrSid Repository
MD5Sum:
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-all/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-all/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-alpha/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-alpha/Packages.gz
 6d552a940fb5fea3428d484f9bee1761 49090 wtf/binary-amd64/Packages
 bbce142720d3f5933278812e524e1f12 16902 wtf/binary-amd64/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-arm/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-arm/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-arm64/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-arm64/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-armel/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-armel/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-armhf/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-armhf/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-hppa/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-hppa/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-hurd-i386/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-hurd-i386/Packages.gz
 80827ddf884683df7b715744120ec4ac 49071 wtf/binary-i386/Packages
 6228a7f1a357dd560cbfccf37c2bbd66 16896 wtf/binary-i386/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-ia64/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-ia64/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-kfreebsd-amd64/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-kfreebsd-amd64/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-kfreebsd-i386/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-kfreebsd-i386/Packages.gz
 be7aa6158214e26f268569e97165b999 44639 wtf/binary-m68k/Packages
 280f0a5426a400df5f8bd17323aec936 14687 wtf/binary-m68k/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-mips/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-mips/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-mipsel/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-mipsel/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-powerpc/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-powerpc/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-powerpcspe/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-powerpcspe/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-ppc64/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-ppc64/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-s390/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-s390/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-s390x/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-s390x/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-sh4/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-sh4/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-sparc/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-sparc/Packages.gz
 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-sparc64/Packages
 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-sparc64/Packages.gz
 576b992b57b0172d51ea86e67700ffe9 46613 wtf/binary-x32/Packages
 fce56dfb28889ff438ffcb279e3fc76e 15439 wtf/binary-x32/Packages.gz
 7192296ab9f9652a3acaf0595c4e3efb 15386 wtf/source/Sources
 43adf4e84f0c5c09ef7542d4434b5ba6 5231 wtf/source/Sources.gz
SHA1:
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-all/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-all/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-alpha/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-alpha/Packages.gz
 342f10ba34519f7a8605930527c227af4badc5d3 49090 wtf/binary-amd64/Packages
 a68caad86df7ad57ee14150d307a37bdaf5f4bb7 16902 wtf/binary-amd64/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-arm/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-arm/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-arm64/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-arm64/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-armel/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-armel/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-armhf/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-armhf/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-hppa/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-hppa/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-hurd-i386/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-hurd-i386/Packages.gz
 f176ee42d2067843ff5321ddeab36c43e15e3838 49071 wtf/binary-i386/Packages
 74bd7df8238b622d87fc6010ece2f16f27d847a4 16896 wtf/binary-i386/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-ia64/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-ia64/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-kfreebsd-amd64/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-kfreebsd-amd64/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-kfreebsd-i386/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-kfreebsd-i386/Packages.gz
 22e3c55233eb7aa8a7bed1da3ca1f515d60b81e3 44639 wtf/binary-m68k/Packages
 b8e5ada13a569dddbf08e7e8a798a9d0296c6f89 14687 wtf/binary-m68k/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-mips/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-mips/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-mipsel/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-mipsel/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-powerpc/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-powerpc/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-powerpcspe/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-powerpcspe/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-ppc64/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-ppc64/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-s390/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-s390/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-s390x/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-s390x/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-sh4/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-sh4/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-sparc/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-sparc/Packages.gz
 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-sparc64/Packages
 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-sparc64/Packages.gz
 469226c6a6c90cddaf99cd1140d3e0faf61ed03b 46613 wtf/binary-x32/Packages
 c646f94870f05b9b708502663af0523288ad747a 15439 wtf/binary-x32/Packages.gz
 c6e4275c1cc0b3cef510c22a9cb913d7e5159318 15386 wtf/source/Sources
 3e1b0fe8940d144381ccb03cae529390749a40db 5231 wtf/source/Sources.gz
SHA256:
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-all/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-all/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-alpha/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-alpha/Packages.gz
 9c892844d9a477be5198587690df4d9a9e2f169d5ecdc014c7185c0c77cd89e4 49090 wtf/binary-amd64/Packages
 c885e079d495435aeb91978705d519c9c6a287300fb38f165b631811facc472c 16902 wtf/binary-amd64/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-arm/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-arm/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-arm64/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-arm64/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-armel/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-armel/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-armhf/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-armhf/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-hppa/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-hppa/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-hurd-i386/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-hurd-i386/Packages.gz
 36ac77737f245aeb54153c1dc2f0207dd00c18483779b885819229dca9f89a0b 49071 wtf/binary-i386/Packages
 9bf386f6cb307899db91d31798faaa488e8bc28a1423cc93450fb383154d31cc 16896 wtf/binary-i386/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-ia64/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-ia64/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-kfreebsd-amd64/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-kfreebsd-amd64/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-kfreebsd-i386/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-kfreebsd-i386/Packages.gz
 a69c1f3bd994b76d01d97b072bed32cb3d678e22ce1b3e0846092cdf0ffb3efb 44639 wtf/binary-m68k/Packages
 a9ec57770ba7a654dd87f58a15e5fe85ce4093aecd579add6862a9400bc4c973 14687 wtf/binary-m68k/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-mips/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-mips/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-mipsel/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-mipsel/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-powerpc/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-powerpc/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-powerpcspe/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-powerpcspe/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-ppc64/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-ppc64/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-s390/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-s390/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-s390x/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-s390x/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-sh4/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-sh4/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-sparc/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-sparc/Packages.gz
 affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-sparc64/Packages
 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-sparc64/Packages.gz
 44cfd3408fb0d76ad66074c61cbf75370124b82a8cb5bfee06dd637e7ddbef64 46613 wtf/binary-x32/Packages
 f2df12d9fdf3666af618933aaf0d084f953621534c9cec003c010c20220021b8 15439 wtf/binary-x32/Packages.gz
 c7bd4547a69047498848e6b9c31d1501c5a2a3014e148f822ea8bdbe9fef9240 15386 wtf/source/Sources
 09be7ede1eb2adf3e4d0bab8dc46b414e6c1d594ba86211b783c6b159e363739 5231 wtf/source/Sources.gz

Worse: what would APT do if there were any such files?

But, especially from a server/network load PoV, it has no
business accessing them in the first place. That’s what the
Release file is for, after all.

bye,
//mirabilos
-- 
This space for rent.

--- End Message ---
--- Begin Message ---
On Tue, Dec 09, 2014 at 10:04:23PM +0000, Thorsten Glaser wrote:
> So, *why* is APT accessing files that are not listed in the Release
> file (*.{bz2,xz,lzma} and Translation*)?
[…]
> Worse: what would APT do if there were any such files?
> 
> But, especially from a server/network load PoV, it has no
> business accessing them in the first place. That’s what the
> Release file is for, after all.

That would be nice… we can't really us an unsigned Release file though
without endangering us which is why you see Packages.xz and co being
requested, which is gone after your ip got the archive signing key.
(apt in experimental will actually use the unsigned Release file as the
codepaths got sanitised, so we can use it would risking our head, the
result is the same though:) The information contained in these files is
considered untrusted and you get the beloved unauthenticated question
until you got the archive signing key (preferable over a secure channel,
which is of course not the unsigned archive, which is actually the
only alarming request I can see in this snapshot…).


The Translation files are a different matter: They are requested because
they weren't in the Release file for years, so we have to guess that
they exist. Split long descriptions out (Translation-en) or just create
an empty Translation-tlh_DE (for german-based Klingons) which you
mention in the Release file (In fact, any file matching Translation-*
will work) to hint apt that you mention all the Translation files you
got in the Release file, so that it doesn't have to guess. You should be
using Translation-en anyhow if you are a good boy…
[actually, adding Translation files to the Release file happened in
different ways over the years and properly mentioned and not mentioned
are the last two remaining cases we are willing to support for the time
being. The later might be gone with stretch now that cdrom creation is
also fixed to include Translations, last I heard, time will tell].

To remove the last remaining 404, add an InRelease file. Helps a lot in
server/network load, too, as it halves the required requests for signing.
;)


Having explained both behaviours as non-bug, I hope its clear why I also
mark this bugreport as done with this message.


Best regards

David Kalnischkies

Attachment: signature.asc
Description: Digital signature


--- End Message ---

Reply to: