Bug#872543: apt does not honor trusted=yes from sources.list
Package: apt
Version: 1.8.0
Followup-For: Bug #872543
Hello!
I can reproduce this particular bug. I just tried building debian-installer on
ia64 using snapshot.debian.org and neither passing "trusted=yes" nor "check-
valid-until=no" has any impact on APT checking the signatures.
It still tries to check the validity of the InRelease file, then fails:
$ glaubitz@titanium:/srv/tmp/debian-installer$ export DEB_BUILD_OPTIONS="nocheck nobench" ; SBUILD_CONFIG=~/sbuild2.conf sbuild -d sid -c sid-ia64-sbuild --arch=ia64 --no-arch-all --apt-update --extra-repository="deb http://incoming.debian.org/debian-buildd buildd-unstable main" --extra-repository="deb [trusted=yes] http://snapshot.debian.org/archive/debian/20130507T220417Z/ unstable main"
dh_testdir
dh_testroot
dh_clean
(...)
+------------------------------------------------------------------------------+
| Update chroot |
+------------------------------------------------------------------------------+
Get:1 http://ftp.ports.debian.org/debian-ports unstable InRelease [47.1 kB]
Get:2 http://ftp.debian.org/debian unstable InRelease [242 kB]
Get:3 http://snapshot.debian.org/archive/debian/20130507T220417Z unstable InRelease [204 kB]
Get:4 http://incoming.ports.debian.org/buildd unstable InRelease [49.1 kB]
Get:5 http://ftp.ports.debian.org/debian-ports unreleased InRelease [52.4 kB]
Get:6 http://incoming.debian.org/debian-buildd buildd-unstable InRelease [54.5 kB]
Get:7 http://ftp.ports.debian.org/debian-ports unstable/main ia64 Packages [18.6 MB]
Get:8 http://ftp.debian.org/debian unstable/main Sources [8735 kB]
Ign:3 http://snapshot.debian.org/archive/debian/20130507T220417Z unstable InRelease
Get:9 http://ftp.ports.debian.org/debian-ports unstable/main all Packages [8758 kB]
Get:10 http://incoming.ports.debian.org/buildd unstable/main ia64 Packages [112 kB]
Get:11 http://ftp.ports.debian.org/debian-ports unreleased/main ia64 Packages [2816 B]
Get:12 http://incoming.debian.org/debian-buildd buildd-unstable/main Sources [35.0 kB]
Reading package lists...
W: GPG error: http://snapshot.debian.org/archive/debian/20130507T220417Z unstable InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY AED4B06F473041FA
E: Release file for http://snapshot.debian.org/archive/debian/20130507T220417Z/dists/unstable/InRelease is expired (invalid since 2152d 17h 4min 35s). Updates for this repository will not be applied.
(...)
Reading package lists...
Get:1 http://snapshot.debian.org/archive/debian/20130507T220417Z unstable InRelease [204 kB]
Ign:1 http://snapshot.debian.org/archive/debian/20130507T220417Z unstable InRelease
Hit:2 http://incoming.debian.org/debian-buildd buildd-unstable InRelease
Reading package lists...
W: GPG error: http://snapshot.debian.org/archive/debian/20130507T220417Z unstable InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY AED4B06F473041FA
E: Release file for http://snapshot.debian.org/archive/debian/20130507T220417Z/dists/unstable/InRelease is expired (invalid since 2152d 17h 4min 57s). Updates for this repository will not be applied.
E: Updating apt archive failed
(...)
+------------------------------------------------------------------------------+
| Summary |
+------------------------------------------------------------------------------+
Build Architecture: ia64
Build Type: any
Build-Space: n/a
Build-Time: 0
Distribution: sid
Fail-Stage: explain-bd-uninstallable
Host Architecture: ia64
Install-Time: 0
Job: /srv/tmp/debian-installer_20190119.dsc
Machine Architecture: ia64
Package: debian-installer
Package-Time: 0
Source-Version: 20190119
Space: n/a
Status: given-back
Version: 20190119
--------------------------------------------------------------------------------
Finished at 2019-04-06T13:30:51Z
Build needed 00:00:00, no disk space
E: Failed to explain bd-uninstallable
glaubitz@titanium:/srv/tmp/debian-installer$
Thanks,
Adrian
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer - glaubitz@debian.org
`. `' Freie Universitaet Berlin - glaubitz@physik.fu-berlin.de
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
Reply to: