Skip to content

An incomplete keyring import is fetched again, not marked complete - #160

Merged
DevomB merged 2 commits into
mainfrom
keyring-import
Sep 29, 2026
Merged

DevomB merged 2 commits into
mainfrom
keyring-import

Conversation

@DevomB

@DevomB DevomB commented Sep 29, 2026

Copy link
Copy Markdown
Owner

On main's CI the inventory step fetched the GNU keyring and failed, imported the nine pinned maintainer keys, and wrote the imported mark with that count; the strict gate then reused the partial keyring and reported 31 signed sources unverifiable. Now the mark is written only when the GNU keyring is in the keyring (its own mark, after an import that yielded at least a hundred keys) and every pinned fingerprint is present; otherwise the mark is removed, the warning names what is missing, and the next invocation fetches only what is still missing. --strict on an incomplete keyring fails with that diagnosis instead of a list of unverifiable sources. --refresh also drops the GNU keyring's import mark.

…ring and every pinned key are in it: what a run could not fetch, the next fetches again, instead of nine keys being marked complete and 31 signed sources called unverifiable; --strict then says the keyring is incomplete
…rver does not serve (Torvalds' mainline key, which no pinned source uses) is fetched again next run, and the sources it signs stay unverifiable until then
@DevomB
DevomB merged commit a1fa3c4 into main Sep 29, 2026
15 of 17 checks passed
@DevomB
DevomB deleted the keyring-import branch September 30, 2026 04:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant