You are not logged in.
Pages: 1
For some reason I can't seem to get my own package signing to work. When I try to install a package from my custom repo (for example I built yay to test), I get the error:
error: yay: missing required signature
error: failed to commit transaction (package missing required signature)I am using the default SigLevel in pacman.conf (SigLevel = Required DatabaseOptional) and my custom repo is fairly basic (I just commented out the repo-specific SigLevel trust options as you can see):
[custom]
#SigLevel = Optional TrustAll
Server = file:///srv/http/arch/repo/x86_64Note: That folder structure is becuase I hope to share my packages on my lan eventually, but it's all local files for this specific computer.
My public key is imported and lsign'ed in my user's keyring, the pacman keyring, and root's keyring, and I have verified it by listing keys. This is from pacman-key --list-keys (obfuscated keyid, name and email):
pub ed25519 2020-01-18 [SC]
KEYID
uid [ full ] My Name <myemail@example.com>
sub ed25519 2020-01-18 [A] [expires: 2021-01-17]
sub rsa4096 2020-01-18 [A] [expires: 2021-01-17]
sub rsa4096 2020-01-18 [S] [expires: 2021-01-17]
sub rsa4096 2020-01-18 [E] [expires: 2021-01-17]I first tried generated the signature by using makepkg (makepkg --sign -s) and copying both my .pkg.zst and .pkg.zst.sig files to my repo's directory. Then I just did repo-add custom.db.tar.xz yay-9.4.4-1-x86_64.pkg.tar.zst. I get no errors:
% repo-add custom.db.tar.xz yay-9.4.4-1-x86_64.pkg.tar.zst
==> Extracting custom.db.tar.xz to a temporary location...
==> Extracting custom.files.tar.xz to a temporary location...
==> Adding package 'yay-9.4.4-1-x86_64.pkg.tar.zst'
==> WARNING: An entry for 'yay-9.4.4-1' already existed
-> Adding package signature...
-> Computing checksums...
-> Removing existing entry 'yay-9.4.4-1'...
-> Creating 'desc' db entry...
-> Creating 'files' db entry...
==> Creating updated database file 'custom.db.tar.xz'I also have tried generating my signatures myself using gpg --detach-sign yay-9.4.4-1-x86_64.pkg.tar.zst
I am getting prompted for my private key password each time, whether I use makepkg --sign or gpg --detach-sign so I know the correct key is being used. Is there an additional step needed for packing signing?
Last edited by dtjohnst (2020-01-19 23:11:30)
Offline
Are you sure the signature is in /var/lib/pacman/sync/custom.db ? It won't be automatically synced if you update the .db with repo-add but don't use pacman -Syu after. You could inspect the contents of /var/lib/pacman/sync/custom.db using "bsdtar -xOf /var/lib/pacman/sync/custom.db yay-9.4.4-1/desc" to see if it has the %PGPSIG% field in it.
Managing AUR repos The Right Way -- aurpublish (now a standalone tool)
Offline
I am mortified to admit that you are correct.
Had I been asked, "Did you sync the databases after you added the signatures?" I would have said, "Absolutely." There was no doubt in my mind I had done it. I even verified the rules before posting and read that part about always do an -Syu before asking, and thought, "Yup, done." When you mentioned it, I immediately thought, "Yup, I sure did sync my database." But when I checked with bsdtar there was no signature, and for the sake of thoroughness I updated the database and checked again and sure enough it appeared.
I am indeed a foolish boy and I apologise for wasting everyone's time.
Offline
Pages: 1