Skip to content

The signatures are kept in the sources cache - #169

Merged
DevomB merged 1 commit into
mainfrom
signature-cache
Sep 30, 2026
Merged

DevomB merged 1 commit into
mainfrom
signature-cache

Conversation

@DevomB

@DevomB DevomB commented Sep 30, 2026

Copy link
Copy Markdown
Owner

The signature gate fetched each source's detached signature from its upstream on every run, because the sources cache is saved before the gate runs and so never held them. Six times in two days one host or another answered a runner with a 418, a 500 or a page in place of the file (lynx's mirror twice), and the gate went red with nothing changed. Now the step that fills the cache also runs the verifier once, output discarded, so the signatures land in /.signatures before the save, in CI and in the Distro jobs' prepare action alike; the gate then reads them from disk. The cache key goes to v3 so the next run on main fills a cache that holds them. verify_detached also asks once more when what came back is not an OpenPGP signature, before calling the source unverifiable.

…so the gate reads them from disk instead of asking every host on every run; a signature file that comes back as something else is asked for once more
@DevomB
DevomB merged commit 91c3238 into main Sep 30, 2026
11 of 12 checks passed
@DevomB
DevomB deleted the signature-cache branch September 30, 2026 10:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant