Your message dated Thu, 11 Dec 2014 01:37:34 +0100 with message-id <20141211003734.GB16834@crossbow> and subject line Re: Bug#772676: apt: accesses files not listed in Release file has caused the Debian Bug report #772676, regarding apt: accesses files not listed in Release file to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 772676: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=772676 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
--- Begin Message ---
- To: submit@bugs.debian.org
- Subject: apt: accesses files not listed in Release file
- From: Thorsten Glaser <tg@mirbsd.de>
- Date: Tue, 9 Dec 2014 22:04:23 +0000 (UTC)
- Message-id: <[🔎] Pine.BSM.4.64L.1412092159440.4243@herc.mirbsd.org>
Package: apt Version: 1.0.9.4 Severity: important Justification: at least that, maybe worse if it would actually use these files I just answered someone where to find my own APT repository, when I had a tail -F on the access_log running, and was amazed to see (anonymised): ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/InRelease HTTP/1.1" 404 338 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/Release.gpg HTTP/1.1" 200 473 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/Release HTTP/1.1" 200 13025 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/source/Sources.bz2 HTTP/1.1" 404 351 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-amd64/Packages.bz2 HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-i386/Packages.bz2 HTTP/1.1" 404 357 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.bz2 HTTP/1.1" 404 359 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.bz2 HTTP/1.1" 404 356 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/source/Sources.xz HTTP/1.1" 404 350 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-amd64/Packages.xz HTTP/1.1" 404 357 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-i386/Packages.xz HTTP/1.1" 404 356 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.xz HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:14 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.xz HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:15 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/source/Sources.lzma HTTP/1.1" 404 352 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:15 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-amd64/Packages.lzma HTTP/1.1" 404 359 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:15 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-i386/Packages.lzma HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:15 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.lzma HTTP/1.1" 404 360 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:15 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.lzma HTTP/1.1" 404 357 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:16 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/source/Sources.gz HTTP/1.1" 200 5231 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:16 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-amd64/Packages.gz HTTP/1.1" 200 16902 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:16 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-i386/Packages.gz HTTP/1.1" 200 16896 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:16 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.gz HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:17 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.gz HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:17 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:17 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en HTTP/1.1" 404 352 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:41 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/Pkgs/wtf-debian-keyring/wtf-debian-keyring_20141120_all.deb HTTP/1.1" 200 10232 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:45 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/InRelease HTTP/1.1" 404 338 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:45 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/Release.gpg HTTP/1.1" 200 473 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:45 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/Release HTTP/1.1" 200 13025 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:46 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/source/Sources.gz HTTP/1.1" 200 5231 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:46 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-amd64/Packages.gz HTTP/1.1" 200 16902 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/binary-i386/Packages.gz HTTP/1.1" 200 16896 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.bz2 HTTP/1.1" 404 359 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.bz2 HTTP/1.1" 404 356 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.xz HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.xz HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.lzma HTTP/1.1" 404 360 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.lzma HTTP/1.1" 404 357 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US.gz HTTP/1.1" 404 358 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en.gz HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en_US HTTP/1.1" 404 355 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" ip - - [09/Dec/2014:21:58:47 +0000] -:-:IPv4"www.mirbsd.org" "GET /%7etg/Debs/dists/sid/wtf/i18n/Translation-en HTTP/1.1" 404 352 "-" "Debian APT-HTTP/1.3 (1.0.9.4)" So, *why* is APT accessing files that are not listed in the Release file (*.{bz2,xz,lzma} and Translation*)? The current Release file is: Origin: The MirOS Project Label: wtf Suite: sid Codename: sid Date: Sun Dec 7 15:20:21 UTC 2014 Architectures: all alpha amd64 arm arm64 armel armhf hppa hurd-i386 i386 ia64 kfreebsd-amd64 kfreebsd-i386 m68k mips mipsel powerpc powerpcspe ppc64 s390 s390x sh4 sparc sparc64 x32 source Components: wtf Description: WTF DrSid Repository MD5Sum: 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-all/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-all/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-alpha/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-alpha/Packages.gz 6d552a940fb5fea3428d484f9bee1761 49090 wtf/binary-amd64/Packages bbce142720d3f5933278812e524e1f12 16902 wtf/binary-amd64/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-arm/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-arm/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-arm64/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-arm64/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-armel/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-armel/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-armhf/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-armhf/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-hppa/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-hppa/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-hurd-i386/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-hurd-i386/Packages.gz 80827ddf884683df7b715744120ec4ac 49071 wtf/binary-i386/Packages 6228a7f1a357dd560cbfccf37c2bbd66 16896 wtf/binary-i386/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-ia64/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-ia64/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-kfreebsd-amd64/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-kfreebsd-amd64/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-kfreebsd-i386/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-kfreebsd-i386/Packages.gz be7aa6158214e26f268569e97165b999 44639 wtf/binary-m68k/Packages 280f0a5426a400df5f8bd17323aec936 14687 wtf/binary-m68k/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-mips/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-mips/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-mipsel/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-mipsel/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-powerpc/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-powerpc/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-powerpcspe/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-powerpcspe/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-ppc64/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-ppc64/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-s390/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-s390/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-s390x/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-s390x/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-sh4/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-sh4/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-sparc/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-sparc/Packages.gz 352e0b591d13c1e8b3cb40a81366db22 37487 wtf/binary-sparc64/Packages 13c3b0db47f7cb4c55f8330178f861ef 12242 wtf/binary-sparc64/Packages.gz 576b992b57b0172d51ea86e67700ffe9 46613 wtf/binary-x32/Packages fce56dfb28889ff438ffcb279e3fc76e 15439 wtf/binary-x32/Packages.gz 7192296ab9f9652a3acaf0595c4e3efb 15386 wtf/source/Sources 43adf4e84f0c5c09ef7542d4434b5ba6 5231 wtf/source/Sources.gz SHA1: 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-all/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-all/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-alpha/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-alpha/Packages.gz 342f10ba34519f7a8605930527c227af4badc5d3 49090 wtf/binary-amd64/Packages a68caad86df7ad57ee14150d307a37bdaf5f4bb7 16902 wtf/binary-amd64/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-arm/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-arm/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-arm64/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-arm64/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-armel/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-armel/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-armhf/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-armhf/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-hppa/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-hppa/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-hurd-i386/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-hurd-i386/Packages.gz f176ee42d2067843ff5321ddeab36c43e15e3838 49071 wtf/binary-i386/Packages 74bd7df8238b622d87fc6010ece2f16f27d847a4 16896 wtf/binary-i386/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-ia64/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-ia64/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-kfreebsd-amd64/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-kfreebsd-amd64/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-kfreebsd-i386/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-kfreebsd-i386/Packages.gz 22e3c55233eb7aa8a7bed1da3ca1f515d60b81e3 44639 wtf/binary-m68k/Packages b8e5ada13a569dddbf08e7e8a798a9d0296c6f89 14687 wtf/binary-m68k/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-mips/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-mips/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-mipsel/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-mipsel/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-powerpc/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-powerpc/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-powerpcspe/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-powerpcspe/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-ppc64/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-ppc64/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-s390/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-s390/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-s390x/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-s390x/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-sh4/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-sh4/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-sparc/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-sparc/Packages.gz 683be96a8aa0a49ecbd1d1b0ed5d1c948be2f979 37487 wtf/binary-sparc64/Packages 207b4aa3e8bf05b34055728bb12fbff94b383ad9 12242 wtf/binary-sparc64/Packages.gz 469226c6a6c90cddaf99cd1140d3e0faf61ed03b 46613 wtf/binary-x32/Packages c646f94870f05b9b708502663af0523288ad747a 15439 wtf/binary-x32/Packages.gz c6e4275c1cc0b3cef510c22a9cb913d7e5159318 15386 wtf/source/Sources 3e1b0fe8940d144381ccb03cae529390749a40db 5231 wtf/source/Sources.gz SHA256: affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-all/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-all/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-alpha/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-alpha/Packages.gz 9c892844d9a477be5198587690df4d9a9e2f169d5ecdc014c7185c0c77cd89e4 49090 wtf/binary-amd64/Packages c885e079d495435aeb91978705d519c9c6a287300fb38f165b631811facc472c 16902 wtf/binary-amd64/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-arm/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-arm/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-arm64/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-arm64/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-armel/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-armel/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-armhf/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-armhf/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-hppa/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-hppa/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-hurd-i386/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-hurd-i386/Packages.gz 36ac77737f245aeb54153c1dc2f0207dd00c18483779b885819229dca9f89a0b 49071 wtf/binary-i386/Packages 9bf386f6cb307899db91d31798faaa488e8bc28a1423cc93450fb383154d31cc 16896 wtf/binary-i386/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-ia64/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-ia64/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-kfreebsd-amd64/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-kfreebsd-amd64/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-kfreebsd-i386/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-kfreebsd-i386/Packages.gz a69c1f3bd994b76d01d97b072bed32cb3d678e22ce1b3e0846092cdf0ffb3efb 44639 wtf/binary-m68k/Packages a9ec57770ba7a654dd87f58a15e5fe85ce4093aecd579add6862a9400bc4c973 14687 wtf/binary-m68k/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-mips/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-mips/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-mipsel/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-mipsel/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-powerpc/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-powerpc/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-powerpcspe/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-powerpcspe/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-ppc64/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-ppc64/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-s390/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-s390/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-s390x/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-s390x/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-sh4/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-sh4/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-sparc/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-sparc/Packages.gz affd7f667790606c42d1880e17f0f9ea6f61031cf8bccc1ee168985858e9b7da 37487 wtf/binary-sparc64/Packages 9414c2e5fb501bf4c10b030937d9f4ce3ac33c41f80171adefdc1f23b8c78775 12242 wtf/binary-sparc64/Packages.gz 44cfd3408fb0d76ad66074c61cbf75370124b82a8cb5bfee06dd637e7ddbef64 46613 wtf/binary-x32/Packages f2df12d9fdf3666af618933aaf0d084f953621534c9cec003c010c20220021b8 15439 wtf/binary-x32/Packages.gz c7bd4547a69047498848e6b9c31d1501c5a2a3014e148f822ea8bdbe9fef9240 15386 wtf/source/Sources 09be7ede1eb2adf3e4d0bab8dc46b414e6c1d594ba86211b783c6b159e363739 5231 wtf/source/Sources.gz Worse: what would APT do if there were any such files? But, especially from a server/network load PoV, it has no business accessing them in the first place. That’s what the Release file is for, after all. bye, //mirabilos -- This space for rent.
--- End Message ---
--- Begin Message ---
- To: Thorsten Glaser <tg@mirbsd.de>, 772676-done@bugs.debian.org
- Subject: Re: Bug#772676: apt: accesses files not listed in Release file
- From: David Kalnischkies <david@kalnischkies.de>
- Date: Thu, 11 Dec 2014 01:37:34 +0100
- Message-id: <20141211003734.GB16834@crossbow>
- In-reply-to: <[🔎] Pine.BSM.4.64L.1412092159440.4243@herc.mirbsd.org>
- References: <[🔎] Pine.BSM.4.64L.1412092159440.4243@herc.mirbsd.org>
On Tue, Dec 09, 2014 at 10:04:23PM +0000, Thorsten Glaser wrote: > So, *why* is APT accessing files that are not listed in the Release > file (*.{bz2,xz,lzma} and Translation*)? […] > Worse: what would APT do if there were any such files? > > But, especially from a server/network load PoV, it has no > business accessing them in the first place. That’s what the > Release file is for, after all. That would be nice… we can't really us an unsigned Release file though without endangering us which is why you see Packages.xz and co being requested, which is gone after your ip got the archive signing key. (apt in experimental will actually use the unsigned Release file as the codepaths got sanitised, so we can use it would risking our head, the result is the same though:) The information contained in these files is considered untrusted and you get the beloved unauthenticated question until you got the archive signing key (preferable over a secure channel, which is of course not the unsigned archive, which is actually the only alarming request I can see in this snapshot…). The Translation files are a different matter: They are requested because they weren't in the Release file for years, so we have to guess that they exist. Split long descriptions out (Translation-en) or just create an empty Translation-tlh_DE (for german-based Klingons) which you mention in the Release file (In fact, any file matching Translation-* will work) to hint apt that you mention all the Translation files you got in the Release file, so that it doesn't have to guess. You should be using Translation-en anyhow if you are a good boy… [actually, adding Translation files to the Release file happened in different ways over the years and properly mentioned and not mentioned are the last two remaining cases we are willing to support for the time being. The later might be gone with stretch now that cdrom creation is also fixed to include Translations, last I heard, time will tell]. To remove the last remaining 404, add an InRelease file. Helps a lot in server/network load, too, as it halves the required requests for signing. ;) Having explained both behaviours as non-bug, I hope its clear why I also mark this bugreport as done with this message. Best regards David KalnischkiesAttachment: signature.asc
Description: Digital signature
--- End Message ---