- Package:
- src:apt-verify
- Source:
- src:apt-verify
- Submitter:
- Simon Josefsson
- Date:
- 2025-12-28 19:21:02 UTC
- Severity:
- normal
* Package name : apt-verify Version : 2.0 Upstream Contact: Simon Josefsson <simon@josefsson.org> * URL : https://gitlab.com/debdistutils/apt-verify * License : AGPLv3+ Programming Lang: Shell script Description : extend apt's gpgv-based verification mechanism Apt-verify extends apt to call all tools in /etc/verify.d/ instead of always only calling gpgv, to verify apt archive integrity and authenticity. A symbolic link in /etc/verify.d/gpgv is installed by default to provide full backwards compatibility. /Simon
Debian archive, I would very much prefer if we would not encourage it
inside Debian at least…
Especially as this has zero mentions on deity@ and declares itself
a hack that you now want to ship with next stable even through it is
utterly unsupportable for Debian as at least I, as an APT developer,
am unwilling to declare the apt::key::gpgvcommand option a supported
interface & I don't see who else would step up…
I added this completely undocumented option in apt-key in 2015 in the
process of supporting gpgv2, so that our tests could be run against
gpgv, gpgv1 and gpgv2. As we no longer have such a need, that option
could disappear any second.
apt-key itself is heavily deprecated and might disappear in the future.
That it is used by libapt currently is also an implementation detail
(again, of the gpg2 supporting kind) we are unwilling to declare
a supported interface and could be changed any second.
I can't give you an exact time line, but I think Julian even already
wrote some PoC code for libapt, so that the parts from apt-key it
secretly reuses will no longer be needed. Its definitely on the (long)
todo list and has some likelihood of being done before trixie releases.
(And that is ignoring if calling gpgv will even remain the only option).
So, in summary, while no such thing as a VETO formally exists for ITPs,
I intend this mail to be as close to a VETO as possible – by the power
of our dear super cow.
In terms of what this actually does: I haven't looked too closely, but
it seem like you want libapt code not to just call its gpgv-method,
but to also (optionally) call a bunch of other methods before and/or
after it, which all have to approve before we can proceed. Certainly not
the easiest thing in the world to implement, but not that hard either…
after all, we have support for client-merged pdiffs (which isn't used
much nowadays, as Debian moved to server-merged pdiffs years ago) which
are downloaded in parallel and wait on each other before proceeding.
So, not rocket-science. It would also solve a bunch of problems you
already have ("it is currently not known how to find out which apt
repository (apt URL) was used") and the many you will have as soon as
you have actual users (I see e.g. apt-canary downloading files) that
you can solve only by being a proper part of the acquire process, not
by attaching yourself with duck tape and hot glue to its underbelly.
Especially not if you want this to be a security feature…
Best regards
David Kalnischkies
David already said a lot of good things but let me extend on that: - apt-key use is slated for removal no later than Feb 29th. - apt signature verification should not involve shell scripts (hence the removal in the first place) - apt-verify looks like it's an apt tool and is easy to confuse with apt-sign, apt's openpgp replacement, and what will likely be the name of the method verifying apt-ed25519 signatures, 'verify' In closing let me say I consider overriding APT's signature verification to be RC-buggy and would immediately file an RC bug should that package be accepted.
We believe that the bug you reported is fixed in the latest version of apt-verify, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1059267@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Simon Josefsson <simon@josefsson.org> (supplier of updated apt-verify package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Fri, 22 Dec 2023 10:02:49 +0100 Source: apt-verify Binary: apt-verify Architecture: source all Version: 2.0-1 Distribution: unstable Urgency: medium Maintainer: Simon Josefsson <simon@josefsson.org> Changed-By: Simon Josefsson <simon@josefsson.org> Description: apt-verify - allow extension of apt's gpgv-based verification mechanism Closes: 1059267 Changes: apt-verify (2.0-1) unstable; urgency=medium . * Initial packaging. Closes: #1059267. Checksums-Sha1: 8f531b17991e1a1e0218750876471db4bad6a4d5 1283 apt-verify_2.0-1.dsc 8e2a2c2a4c3c8059660df6bb5915efcbea4880b3 15812 apt-verify_2.0.orig.tar.gz 5f07a42a3bbe02d988d3f8a103ed8be9b072f613 12440 apt-verify_2.0-1.debian.tar.xz 949c052aa81b35cbc709dbb9b58fe4129d05a6cd 18352 apt-verify_2.0-1_all.deb 69c243843102cf23eaa35328c10d3a127e3e10cb 5455 apt-verify_2.0-1_amd64.buildinfo Checksums-Sha256: 9ba0b5cc8d0e40aae4ddbd3292b387dbce3de1722a57947123e6242a0f0a4cb6 1283 apt-verify_2.0-1.dsc e526726c97e32e4271fb882574d9026b223c90cb4198fe872bd4adced59e3263 15812 apt-verify_2.0.orig.tar.gz 795374aa028a38da2e1b586b120f1d66bcada39804c7cb5e6a71baa2510a1f8e 12440 apt-verify_2.0-1.debian.tar.xz 6c431068046e58c60a60ccf9a348e023cff3d6be4fd8505ff0ff37085150530c 18352 apt-verify_2.0-1_all.deb b3cad0d5e5d2b4346b279fb48b76f06a0001152c2902e3c59da34d87ac04a63b 5455 apt-verify_2.0-1_amd64.buildinfo Files: 22dfdf11b627a147fd55026cbd2266c1 1283 admin optional apt-verify_2.0-1.dsc 2142f3d5fb05539bd28d5e676a0d79d4 15812 admin optional apt-verify_2.0.orig.tar.gz 3f2c1e5899b8c6e94e9974f97cfd747e 12440 admin optional apt-verify_2.0-1.debian.tar.xz 42302aecd517b8615996ec28e0a934f0 18352 admin optional apt-verify_2.0-1_all.deb bdd5ab5ec1d2860ba990b0abc6ada1aa 5455 admin optional apt-verify_2.0-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iIoEARYIADIWIQSjzJyHC50xCrrUzy9RcisI/kdFogUCZYV2cxQcc2ltb25Aam9z ZWZzc29uLm9yZwAKCRBRcisI/kdFonYeAP0YFZK8Xg25XzK/IfoYNJJGO0CeTdPM QUghNUmm3vT0nwEAvD2fSLUxmDDbKm/Q05/iG0+4FedOsZ1LM63m+GPBQQA= =ZxUb -----END PGP SIGNATURE-----
Hi! You re-opened this ITP bug and changed the title to 'apt-verify: unsupportable' and made it a RC bug. It is not clear to me what makes you believe this is a serious bug in this package, since you gave no justification. Can you clarify what your actionable concerns are? /Simon
severity 1061185 important thanks I'm downgrading this due to lack of explanation what is the 'serious' severity level problem. /Simon Simon Josefsson <simon@josefsson.org> writes:
Control: severity -1 serious apt-verify has a defacto RC bug or equivalent because apt has Conflicts: apt-verify. Notice how it is unable to migrate to Testing because of the piuparts regression: https://tracker.debian.org/pkg/apt-verify I am bumping the severity back to serious just so that someone who visits that tracker page (or the similar excuses pages) has a handy link to more explanation why this package is unable to migrate to Testing. There is history in previous comments to this bug. I am not personally involved in apt maintenance or deciding whether there should or shouldn't be a Conflicts here. Thank you, Jeremy Bícha
Jeremy Bícha <jeremy.bicha@canonical.com> writes: I don't understand this -- why is it a RC bug if the apt maintainers declare a Conflicts with a package? Where in the debian policies do you find support for that view? It would be nice to resolve the Conflicts in apt too, as an orthogonal but related issue, but I've been equally unable to understand what actionable change is requested in 'apt-verify'. Could we try to have a discussion about this? /Simon
apt is Priority: required. It is impossible to install apt-verify on a standard Debian install. An uninstallable package cannot possibly be part of Debian. Perhaps the piuparts section at https://release.debian.org/testing/rc_policy.txt applies if you need a reference. Sorry, I am unable to help with the dispute with the apt maintainers. Thank you, Jeremy Bícha
Just for the record, this is what happen when trying to install
apt-verfiy now:
Solving dependencies... Error!
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:
Unsatisfied dependencies:
apt : Conflicts: apt-verify but 2.0-1 is to be installed
Error: Unable to satisfy dependencies. Reached two conflicting decisions:
1. apt-verify:amd64=2.0-1 is selected for install
2. apt-verify:amd64=2.0-1 is not selected for install because:
1. apt:amd64 is selected for install
2. apt:amd64 Conflicts apt-verify
override apt's default behaviour for Conflicts: handling. /Simon Petter Reinholdtsen <pere@hungry.com> writes: