Fix XBPS repository verification

This commit is contained in:
xavierk
2026-09-15 19:48:08 +05:30
parent a3e6cc3b3c
commit 9d22525403
3 changed files with 12 additions and 5 deletions
+4 -4
View File
@@ -159,7 +159,9 @@ if $PUBLISH; then
# Compare every served byte with the artifact that was indexed and pushed.
# A successful HEAD request alone can still hide a stale or incomplete
# publication behind the raw endpoint's cache.
for artifact in "${XBPS_FILE}" "${XBPS_FILE}.sig2" "x86_64-repodata" "x86_64-repodata.sig2"; do
# Repository signatures are embedded in x86_64-repodata by xbps-rindex;
# only package signatures are separate .sig2 files.
for artifact in "${XBPS_FILE}" "${XBPS_FILE}.sig2" "x86_64-repodata"; do
case "${artifact}" in
"${XBPS_FILE}") local_path="${XBPS_PATH}" ;;
"${XBPS_FILE}.sig2") local_path="${XBPS_PATH}.sig2" ;;
@@ -178,9 +180,7 @@ else
_run "cmp -- ${XBPS_PATH}.sig2 ${WORK_DIR}/.${XBPS_FILE}.sig2.download"
_run "curl --fail --silent --show-error --location --output ${WORK_DIR}/.x86_64-repodata.download ${RAW_BASE}/x86_64-repodata"
_run "cmp -- ${WORK_DIR}/${ARCH}/x86_64-repodata ${WORK_DIR}/.x86_64-repodata.download"
_run "curl --fail --silent --show-error --location --output ${WORK_DIR}/.x86_64-repodata.sig2.download ${RAW_BASE}/x86_64-repodata.sig2"
_run "cmp -- ${WORK_DIR}/${ARCH}/x86_64-repodata.sig2 ${WORK_DIR}/.x86_64-repodata.sig2.download"
_run "rm -f ${WORK_DIR}/.${XBPS_FILE}.download ${WORK_DIR}/.${XBPS_FILE}.sig2.download ${WORK_DIR}/.x86_64-repodata.download ${WORK_DIR}/.x86_64-repodata.sig2.download"
_run "rm -f ${WORK_DIR}/.${XBPS_FILE}.download ${WORK_DIR}/.${XBPS_FILE}.sig2.download ${WORK_DIR}/.x86_64-repodata.download"
fi
echo ""