Skip to content

The GNU keyring is kept with the sources and carried by their cache - #164

Merged
DevomB merged 1 commit into
mainfrom
keyring-cache
Sep 29, 2026
Merged

DevomB merged 1 commit into
mainfrom
keyring-cache

Conversation

@DevomB

@DevomB DevomB commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Twice today the strict gate failed because ftp.gnu.org did not answer a runner's fetch of gnu-keyring.gpg; every other source is served from the sources cache, but the keyring was fetched fresh in every job. Now make sources fetches it into <sources>/.keys/ beside the tarballs (a failure there warns; the gate fetches again), so the cache saved after make sources carries it, and verify-signatures.sh reads it from there. The mark that says "this GNUPGHOME imported the keyring" moves into that GNUPGHOME, since the keyring file now outlives any one checkout's keys. The sources cache key gains a v2 so the next run on main fills a cache that holds the keyring; PR runs restore it by prefix until then. docs/supply-chain.md says the keyring is kept with the sources.

… carried by their cache, so the signature gate needs ftp.gnu.org only when the sources themselves are fetched; the import mark lives in the GNUPGHOME it describes, and the sources cache key is salted so the first run fills it
@DevomB
DevomB merged commit 87d37ae into main Sep 29, 2026
11 of 12 checks passed
@DevomB
DevomB deleted the keyring-cache branch September 30, 2026 04:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant