From 9d225254033b9082b15d690a0b13697de58ed149 Mon Sep 17 00:00:00 2001 From: xavierk Date: Tue, 15 Sep 2026 19:48:08 +0530 Subject: [PATCH] Fix XBPS repository verification --- docs/spec/xbps-proof-results.md | 1 - scripts/xbps-publish.sh | 8 ++++---- tests/test_packaging.py | 8 ++++++++ 3 files changed, 12 insertions(+), 5 deletions(-) diff --git a/docs/spec/xbps-proof-results.md b/docs/spec/xbps-proof-results.md index 60128fd..c8267a1 100644 --- a/docs/spec/xbps-proof-results.md +++ b/docs/spec/xbps-proof-results.md @@ -117,7 +117,6 @@ xavierk/Fenris-xbps (stable branch) fenris-_1.x86_64.xbps # Package archives fenris-_1.x86_64.xbps.sig2 # Package signatures x86_64-repodata # Repository index (zstd-compressed tar) - x86_64-repodata.sig2 # Repository metadata signature keys/ fenris-xbps-signing.pub # Public signing key README.md diff --git a/scripts/xbps-publish.sh b/scripts/xbps-publish.sh index d3ae204..f9ebfed 100755 --- a/scripts/xbps-publish.sh +++ b/scripts/xbps-publish.sh @@ -159,7 +159,9 @@ if $PUBLISH; then # Compare every served byte with the artifact that was indexed and pushed. # A successful HEAD request alone can still hide a stale or incomplete # publication behind the raw endpoint's cache. - for artifact in "${XBPS_FILE}" "${XBPS_FILE}.sig2" "x86_64-repodata" "x86_64-repodata.sig2"; do + # Repository signatures are embedded in x86_64-repodata by xbps-rindex; + # only package signatures are separate .sig2 files. + for artifact in "${XBPS_FILE}" "${XBPS_FILE}.sig2" "x86_64-repodata"; do case "${artifact}" in "${XBPS_FILE}") local_path="${XBPS_PATH}" ;; "${XBPS_FILE}.sig2") local_path="${XBPS_PATH}.sig2" ;; @@ -178,9 +180,7 @@ else _run "cmp -- ${XBPS_PATH}.sig2 ${WORK_DIR}/.${XBPS_FILE}.sig2.download" _run "curl --fail --silent --show-error --location --output ${WORK_DIR}/.x86_64-repodata.download ${RAW_BASE}/x86_64-repodata" _run "cmp -- ${WORK_DIR}/${ARCH}/x86_64-repodata ${WORK_DIR}/.x86_64-repodata.download" - _run "curl --fail --silent --show-error --location --output ${WORK_DIR}/.x86_64-repodata.sig2.download ${RAW_BASE}/x86_64-repodata.sig2" - _run "cmp -- ${WORK_DIR}/${ARCH}/x86_64-repodata.sig2 ${WORK_DIR}/.x86_64-repodata.sig2.download" - _run "rm -f ${WORK_DIR}/.${XBPS_FILE}.download ${WORK_DIR}/.${XBPS_FILE}.sig2.download ${WORK_DIR}/.x86_64-repodata.download ${WORK_DIR}/.x86_64-repodata.sig2.download" + _run "rm -f ${WORK_DIR}/.${XBPS_FILE}.download ${WORK_DIR}/.${XBPS_FILE}.sig2.download ${WORK_DIR}/.x86_64-repodata.download" fi echo "" diff --git a/tests/test_packaging.py b/tests/test_packaging.py index 036be45..b0f565e 100644 --- a/tests/test_packaging.py +++ b/tests/test_packaging.py @@ -111,6 +111,14 @@ def test_runit_logger_uses_accounts_shipped_by_package(): assert "chpst -u nobody:fenris" in logger +def test_xbps_publisher_verifies_embedded_repository_signature(): + """Publication verification must match XBPS's repository layout.""" + publisher = (REPO_ROOT / "scripts" / "xbps-publish.sh").read_text() + + assert '"x86_64-repodata"' in publisher + assert '"x86_64-repodata.sig2"' not in publisher + + # --------------------------------------------------------------------------- # Matrix definitions # ---------------------------------------------------------------------------