Skip to content

The signature gate asks a throttling host again, and a note is not stale when its signature could not be fetched - #158

Merged
DevomB merged 1 commit into
mainfrom
siggate-fetch
Sep 29, 2026
Merged

DevomB merged 1 commit into
mainfrom
siggate-fetch

Conversation

@DevomB

@DevomB DevomB commented Sep 29, 2026

Copy link
Copy Markdown
Owner

On #156 the Source manifest job failed with nothing changed under it: freedesktop.org answered HTTP 418 to the runner's fetch of libevdev's .sig, so verify-signatures.sh --strict counted libevdev unverifiable (correct: a signature it could not check) and then also called its no-usable-key note stale, because the note was never tried. Two failures for one throttled request, and a re-run was the only cure.

  • quiet_fetch tries again after a pause on 418, 429 and 503 (three tries, 5 s then 10 s apart); a 404 or a missing file is an answer and is not retried, so sources that publish nothing stay quick.
  • A source that was unverifiable this run has its note left alone: the note is stale only when the key it excuses is held or the source is gone.
  • The fixture suite has the case: a row declaring a .sig that cannot be fetched, with a note, fails --strict as unverifiable and is not called stale.

…ers 418 to a busy runner, others 429 or 503) and a 404 once, and a signature the run could not fetch leaves its no-usable-key note untried, not stale: a transient refusal is one unverifiable source, not two failures
@DevomB
DevomB merged commit 4912e20 into main Sep 29, 2026
11 of 12 checks passed
@DevomB
DevomB deleted the siggate-fetch branch September 30, 2026 04:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant