| Summary: | rpmsign does not update file | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Bill C. Riemers <briemers> | ||||||
| Component: | rpm | Assignee: | Panu Matilainen <pmatilai> | ||||||
| Status: | CLOSED DUPLICATE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||||
| Severity: | unspecified | Docs Contact: | |||||||
| Priority: | unspecified | ||||||||
| Version: | 15 | CC: | ffesti, jnovy, pmatilai | ||||||
| Target Milestone: | --- | ||||||||
| Target Release: | --- | ||||||||
| Hardware: | Unspecified | ||||||||
| OS: | Unspecified | ||||||||
| Whiteboard: | |||||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2011-10-23 11:43:41 UTC | Type: | --- | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Attachments: |
|
||||||||
|
Description
Bill C. Riemers
2011-10-22 06:07:14 UTC
It looks like the problem is that pgpPrtPkts returns a non-zero value. In that case, rpm-sign silently fails. It looks like pgpPrtPkts does not provide any sort of diagnostic information to indicate what the problem is with the gpg signature. I generated a new key, and that one seems to work. The differences in keys is the first one was a 2048 bit DSA key with a expiration of 5 years. The second was a 1024 bit DSA key with no expiration. Don't know if the part that causes problems is the number of bits, or the expiration. At minimum, an error message needs to be added to rpm-sign there is some indication that a failure occurred and why it occurred. I actually wasted a huge amount of bandwidth uploading rpm's to my repo, that I thought were signed... Multiple times... Created attachment 529623 [details]
patch to add an error message
Created attachment 529624 [details]
spec file to apply patch
Thanks for looking up the place with missing error message. It can't go making assumptions about DSA (there are any number of reasons why it could fail), but it should issue an error anyway. A rather vague message added upstream (the caller has little clue of what failed) but better than silently failing... *** This bug has been marked as a duplicate of bug 719154 *** Definitely, even a very vague message is better than no message at all. At least this way at least the user knows something has failed. Once they have an error message they can google, or try something different instead of just left assuming the command succeeded. |