Fix XBPS repository verification
This commit is contained in:
@@ -117,7 +117,6 @@ xavierk/Fenris-xbps (stable branch)
|
|||||||
fenris-<version>_1.x86_64.xbps # Package archives
|
fenris-<version>_1.x86_64.xbps # Package archives
|
||||||
fenris-<version>_1.x86_64.xbps.sig2 # Package signatures
|
fenris-<version>_1.x86_64.xbps.sig2 # Package signatures
|
||||||
x86_64-repodata # Repository index (zstd-compressed tar)
|
x86_64-repodata # Repository index (zstd-compressed tar)
|
||||||
x86_64-repodata.sig2 # Repository metadata signature
|
|
||||||
keys/
|
keys/
|
||||||
fenris-xbps-signing.pub # Public signing key
|
fenris-xbps-signing.pub # Public signing key
|
||||||
README.md
|
README.md
|
||||||
|
|||||||
@@ -159,7 +159,9 @@ if $PUBLISH; then
|
|||||||
# Compare every served byte with the artifact that was indexed and pushed.
|
# Compare every served byte with the artifact that was indexed and pushed.
|
||||||
# A successful HEAD request alone can still hide a stale or incomplete
|
# A successful HEAD request alone can still hide a stale or incomplete
|
||||||
# publication behind the raw endpoint's cache.
|
# publication behind the raw endpoint's cache.
|
||||||
for artifact in "${XBPS_FILE}" "${XBPS_FILE}.sig2" "x86_64-repodata" "x86_64-repodata.sig2"; do
|
# Repository signatures are embedded in x86_64-repodata by xbps-rindex;
|
||||||
|
# only package signatures are separate .sig2 files.
|
||||||
|
for artifact in "${XBPS_FILE}" "${XBPS_FILE}.sig2" "x86_64-repodata"; do
|
||||||
case "${artifact}" in
|
case "${artifact}" in
|
||||||
"${XBPS_FILE}") local_path="${XBPS_PATH}" ;;
|
"${XBPS_FILE}") local_path="${XBPS_PATH}" ;;
|
||||||
"${XBPS_FILE}.sig2") local_path="${XBPS_PATH}.sig2" ;;
|
"${XBPS_FILE}.sig2") local_path="${XBPS_PATH}.sig2" ;;
|
||||||
@@ -178,9 +180,7 @@ else
|
|||||||
_run "cmp -- ${XBPS_PATH}.sig2 ${WORK_DIR}/.${XBPS_FILE}.sig2.download"
|
_run "cmp -- ${XBPS_PATH}.sig2 ${WORK_DIR}/.${XBPS_FILE}.sig2.download"
|
||||||
_run "curl --fail --silent --show-error --location --output ${WORK_DIR}/.x86_64-repodata.download ${RAW_BASE}/x86_64-repodata"
|
_run "curl --fail --silent --show-error --location --output ${WORK_DIR}/.x86_64-repodata.download ${RAW_BASE}/x86_64-repodata"
|
||||||
_run "cmp -- ${WORK_DIR}/${ARCH}/x86_64-repodata ${WORK_DIR}/.x86_64-repodata.download"
|
_run "cmp -- ${WORK_DIR}/${ARCH}/x86_64-repodata ${WORK_DIR}/.x86_64-repodata.download"
|
||||||
_run "curl --fail --silent --show-error --location --output ${WORK_DIR}/.x86_64-repodata.sig2.download ${RAW_BASE}/x86_64-repodata.sig2"
|
_run "rm -f ${WORK_DIR}/.${XBPS_FILE}.download ${WORK_DIR}/.${XBPS_FILE}.sig2.download ${WORK_DIR}/.x86_64-repodata.download"
|
||||||
_run "cmp -- ${WORK_DIR}/${ARCH}/x86_64-repodata.sig2 ${WORK_DIR}/.x86_64-repodata.sig2.download"
|
|
||||||
_run "rm -f ${WORK_DIR}/.${XBPS_FILE}.download ${WORK_DIR}/.${XBPS_FILE}.sig2.download ${WORK_DIR}/.x86_64-repodata.download ${WORK_DIR}/.x86_64-repodata.sig2.download"
|
|
||||||
fi
|
fi
|
||||||
echo ""
|
echo ""
|
||||||
|
|
||||||
|
|||||||
@@ -111,6 +111,14 @@ def test_runit_logger_uses_accounts_shipped_by_package():
|
|||||||
assert "chpst -u nobody:fenris" in logger
|
assert "chpst -u nobody:fenris" in logger
|
||||||
|
|
||||||
|
|
||||||
|
def test_xbps_publisher_verifies_embedded_repository_signature():
|
||||||
|
"""Publication verification must match XBPS's repository layout."""
|
||||||
|
publisher = (REPO_ROOT / "scripts" / "xbps-publish.sh").read_text()
|
||||||
|
|
||||||
|
assert '"x86_64-repodata"' in publisher
|
||||||
|
assert '"x86_64-repodata.sig2"' not in publisher
|
||||||
|
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# Matrix definitions
|
# Matrix definitions
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|||||||
Reference in New Issue
Block a user