You are not logged in.

#1 2021-07-15 14:26:53

malacology
Member
Registered: 2021-04-24
Posts: 152

GPG key fail to sign in GitHub Action

Hello, I use this repository to build my local repository via GitHub Action
https://github.com/Aloxaf/aur-build, To easy understand the process of using it, I write an English Guide https://github.com/BioArchLinux/aur-bui … r-build.md for it.
But things always occur on makepkg  by GitHub Action. They always show makepkg --noprogressbar --force --nocolor fail.

==> Leaving fakeroot environment.
==> Signing package(s)...
==> WARNING: Failed to sign package file beast2-2.6.4-1-x86_64.pkg.tar.zst.

Command 'makepkg --noprogressbar --force --nocolor' failed to execute.
:: Removing already installed dependencies for beast2:
=> sudo /tmp/pacman --color=never --remove giflib libpng harfbuzz nspr lcms2 jre-openjdk libnet libtiff java-environment-common openjdk-src freetype2 libjpeg-turbo openjdk-doc nss hicolor-icon-theme graphite jdk-openjdk jre-openjdk-headless java-runtime-common
25lchecking dependencies...
warning: dependency cycle detected:
warning: freetype2 will be removed after its harfbuzz dependency

Packages (19) freetype2-2.10.4-1  giflib-5.2.1-2  graphite-1:1.3.14-1
              harfbuzz-2.8.2-1  hicolor-icon-theme-0.17-2
              java-environment-common-3-3  java-runtime-common-3-3
              jdk-openjdk-16.0.1.u9-1  jre-openjdk-16.0.1.u9-1
              jre-openjdk-headless-16.0.1.u9-1  lcms2-2.12-1
              libjpeg-turbo-2.1.0-1  libnet-1:1.1.6-1  libpng-1.6.37-3
              libtiff-4.3.0-1  nspr-4.32-1  nss-3.68-1  openjdk-doc-16.0.1.u9-1
              openjdk-src-16.0.1.u9-1

Total Removed Size:  611.70 MiB

:: Do you want to remove these packages? [Y/n] 
Y
:: Processing package changes...
removing openjdk-doc...
removing openjdk-src...
removing jdk-openjdk...
removing hicolor-icon-theme...
removing java-environment-common...
removing jre-openjdk...
removing jre-openjdk-headless...
removing java-runtime-common...
removing nss...
removing libnet...
removing lcms2...
removing libtiff...
removing libjpeg-turbo...
removing nspr...
removing harfbuzz...
removing graphite...
removing freetype2...
removing libpng...
removing giflib...
:: Running post-transaction hooks...
(1/1) Arming ConditionNeedsUpdate...

Can't build 'beast2'.

Failed to build following packages:
beast2

So, I am wondering if makepkg --noprogressbar --force --nocolor  need some special condition or running environment, or any other reasons?
I think the GPG key is the main problem.
In GitHub Action, and it shows

gpg: next trustdb check due at 2021-08-02
gpg: key EC035DFB7F9A2A8A: public key "BioArchLinux <BioArchLinux@malacology.net>" imported
gpg: Total number processed: 1
 gpg:               imported: 1
 -> Locally signed 1 keys.
==> Updating trust database...
[LOG] Importing GPG
gpg: directory '/home/aur-build/.gnupg' created
gpg: keybox '/home/aur-build/.gnupg/pubring.kbx' created
gpg: /home/aur-build/.gnupg/trustdb.gpg: trustdb created
gpg: key EC035DFB7F9A2A8A: public key "BioArchLinux <BioArchLinux@malacology.net>" imported
gpg: To migrate 'secring.gpg', with each smartcard, run: gpg --card-status
gpg: key EC035DFB7F9A2A8A: secret key imported
gpg: Total number processed: 1
gpg:               imported: 1
gpg:       secret keys read: 1
gpg:   secret keys imported: 1
OK

So it just shows that this GPG key is imported. but things are strange when run makepkg --noprogressbar --force --nocolor, input the right password and then it shows Failed to sign package.
I use this script to run it

  LOG "Initing GPG"
  rm -fr /etc/pacman.d/gnupg
  pacman-key --init
  pacman-key --populate archlinux
  pacman-key --recv-keys $GPGKEY --keyserver hkp://keyserver.ubuntu.com
  pacman-key --lsign-key $GPGKEY

I can use   pacman-key --recv-keys $GPGKEY --keyserver hkp://keyserver.ubuntu.com and   pacman-key --lsign-key $GPGKEY on my PC well and no error is shown.
All the log is shown here.
https://github.com/BioArchLinux/testing … 40004/logs

Last edited by malacology (2021-07-18 05:42:41)


Don't speak to silly man. Keep Minimalism.

Offline

#2 2021-07-16 13:15:15

Lone_Wolf
Administrator
From: Netherlands, Europe
Registered: 2005-10-04
Posts: 15,268

Re: GPG key fail to sign in GitHub Action

==> WARNING: Failed to sign package file beast2-2.6.4-1-x86_64.pkg.tar.zst.

It's just  a guess, but the signing failure could be the reason why things fail.


Disliking systemd intensely, but not satisfied with alternatives so focusing on taming systemd.

clean chroot building not flexible enough ?
Try clean chroot manager by graysky

Offline

#3 2021-07-18 04:14:06

malacology
Member
Registered: 2021-04-24
Posts: 152

Re: GPG key fail to sign in GitHub Action

=> makepkg --noprogressbar --packagelist

:: Starting the build:
=> makepkg --noprogressbar --force --nocolor
25h==> Making package: arlequin 3.5.2.2-1 (Sun 18 Jul 2021 04:11:09 AM UTC)
==> Checking runtime dependencies...
==> Checking buildtime dependencies...
==> Retrieving sources...
  -> Downloading WinArl35.zip...
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed

  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  5 29.5M    5 1540k    0     0  1291k      0  0:00:23  0:00:01  0:00:22 1290k
 41 29.5M   41 12.1M    0     0  5685k      0  0:00:05  0:00:02  0:00:03 5682k
 79 29.5M   79 23.3M    0     0  7496k      0  0:00:04  0:00:03  0:00:01 7494k
100 29.5M  100 29.5M    0     0  8079k      0  0:00:03  0:00:03 --:--:-- 8077k
  -> Found arlequin.desktop
  -> Found arlequin.png
==> Validating source files with md5sums...
    WinArl35.zip ... Passed
    arlequin.desktop ... Passed
    arlequin.png ... Passed
==> Extracting sources...
  -> Extracting WinArl35.zip with bsdtar
==> Entering fakeroot environment...
==> Starting package()...
==> Tidying install...
  -> Removing libtool files...
  -> Purging unwanted files...
  -> Removing static library files...
  -> Stripping unneeded symbols from binaries and libraries...
  -> Compressing man and info pages...
==> Checking for packaging issues...
==> Creating package "arlequin"...
  -> Generating .PKGINFO file...
  -> Generating .BUILDINFO file...
  -> Generating .MTREE file...
  -> Compressing package...
==> Leaving fakeroot environment.
==> Signing package(s)...
==> WARNING: Failed to sign package file arlequin-3.5.2.2-1-any.pkg.tar.zst.

Command 'makepkg --noprogressbar --force --nocolor' failed to execute.

Right, I also think so.


Don't speak to silly man. Keep Minimalism.

Offline

#4 2022-01-02 21:22:13

malacology
Member
Registered: 2021-04-24
Posts: 152

Re: GPG key fail to sign in GitHub Action

I migrate to archlinuxcn/lilac, so this discussion won't continue


Don't speak to silly man. Keep Minimalism.

Offline

Board footer

Powered by FluxBB