#1061185#5
Date:
2023-12-22 09:54:10 UTC
From:
To:
* Package name    : apt-verify
  Version         : 2.0
  Upstream Contact: Simon Josefsson <simon@josefsson.org>
* URL             : https://gitlab.com/debdistutils/apt-verify
* License         : AGPLv3+
  Programming Lang: Shell script
  Description     : extend apt's gpgv-based verification mechanism

Apt-verify extends apt to call all tools in /etc/verify.d/ instead of
always only calling gpgv, to verify apt archive integrity and
authenticity.  A symbolic link in /etc/verify.d/gpgv is installed by
default to provide full backwards compatibility.

/Simon

#1061185#10
Date:
2023-12-22 17:35:30 UTC
From:
To:
Debian archive, I would very much prefer if we would not encourage it
inside Debian at least…

Especially as this has zero mentions on deity@ and declares itself
a hack that you now want to ship with next stable even through it is
utterly unsupportable for Debian as at least I, as an APT developer,
am unwilling to declare the apt::key::gpgvcommand option a supported
interface & I don't see who else would step up…

I added this completely undocumented option in apt-key in 2015 in the
process of supporting gpgv2, so that our tests could be run against
gpgv, gpgv1 and gpgv2. As we no longer have such a need, that option
could disappear any second.

apt-key itself is heavily deprecated and might disappear in the future.
That it is used by libapt currently is also an implementation detail
(again, of the gpg2 supporting kind) we are unwilling to declare
a supported interface and could be changed any second.

I can't give you an exact time line, but I think Julian even already
wrote some PoC code for libapt, so that the parts from apt-key it
secretly reuses will no longer be needed. Its definitely on the (long)
todo list and has some likelihood of being done before trixie releases.
(And that is ignoring if calling gpgv will even remain the only option).


So, in summary, while no such thing as a VETO formally exists for ITPs,
I intend this mail to be as close to a VETO as possible – by the power
of our dear super cow.


In terms of what this actually does: I haven't looked too closely, but
it seem like you want libapt code not to just call its gpgv-method,
but to also (optionally) call a bunch of other methods before and/or
after it, which all have to approve before we can proceed. Certainly not
the easiest thing in the world to implement, but not that hard either…
after all, we have support for client-merged pdiffs (which isn't used
much nowadays, as Debian moved to server-merged pdiffs years ago) which
are downloaded in parallel and wait on each other before proceeding.
So, not rocket-science. It would also solve a bunch of problems you
already have ("it is currently not known how to find out which apt
repository (apt URL) was used") and the many you will have as soon as
you have actual users (I see e.g. apt-canary downloading files) that
you can solve only by being a proper part of the acquire process, not
by attaching yourself with duck tape and hot glue to its underbelly.
Especially not if you want this to be a security feature…


Best regards

David Kalnischkies

#1061185#15
Date:
2023-12-22 19:41:25 UTC
From:
To:

David already said a lot of good things but let me extend on that:

- apt-key use is slated for removal no later than Feb 29th.
- apt signature verification should not involve shell scripts
  (hence the removal in the first place)
- apt-verify looks like it's an apt tool and is easy to confuse
  with apt-sign, apt's openpgp replacement, and what will likely
  be the name of the method verifying apt-ed25519 signatures,
  'verify'

In closing let me say I consider overriding APT's signature verification
to be RC-buggy and would immediately file an RC bug should that package
be accepted.

#1061185#20
Date:
2024-01-05 19:10:11 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
apt-verify, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1059267@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon Josefsson <simon@josefsson.org> (supplier of updated apt-verify package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 22 Dec 2023 10:02:49 +0100
Source: apt-verify
Binary: apt-verify
Architecture: source all
Version: 2.0-1
Distribution: unstable
Urgency: medium
Maintainer: Simon Josefsson <simon@josefsson.org>
Changed-By: Simon Josefsson <simon@josefsson.org>
Description:
 apt-verify - allow extension of apt's gpgv-based verification mechanism
Closes: 1059267
Changes:
 apt-verify (2.0-1) unstable; urgency=medium
 .
   * Initial packaging.  Closes: #1059267.
Checksums-Sha1:
 8f531b17991e1a1e0218750876471db4bad6a4d5 1283 apt-verify_2.0-1.dsc
 8e2a2c2a4c3c8059660df6bb5915efcbea4880b3 15812 apt-verify_2.0.orig.tar.gz
 5f07a42a3bbe02d988d3f8a103ed8be9b072f613 12440 apt-verify_2.0-1.debian.tar.xz
 949c052aa81b35cbc709dbb9b58fe4129d05a6cd 18352 apt-verify_2.0-1_all.deb
 69c243843102cf23eaa35328c10d3a127e3e10cb 5455 apt-verify_2.0-1_amd64.buildinfo
Checksums-Sha256:
 9ba0b5cc8d0e40aae4ddbd3292b387dbce3de1722a57947123e6242a0f0a4cb6 1283 apt-verify_2.0-1.dsc
 e526726c97e32e4271fb882574d9026b223c90cb4198fe872bd4adced59e3263 15812 apt-verify_2.0.orig.tar.gz
 795374aa028a38da2e1b586b120f1d66bcada39804c7cb5e6a71baa2510a1f8e 12440 apt-verify_2.0-1.debian.tar.xz
 6c431068046e58c60a60ccf9a348e023cff3d6be4fd8505ff0ff37085150530c 18352 apt-verify_2.0-1_all.deb
 b3cad0d5e5d2b4346b279fb48b76f06a0001152c2902e3c59da34d87ac04a63b 5455 apt-verify_2.0-1_amd64.buildinfo
Files:
 22dfdf11b627a147fd55026cbd2266c1 1283 admin optional apt-verify_2.0-1.dsc
 2142f3d5fb05539bd28d5e676a0d79d4 15812 admin optional apt-verify_2.0.orig.tar.gz
 3f2c1e5899b8c6e94e9974f97cfd747e 12440 admin optional apt-verify_2.0-1.debian.tar.xz
 42302aecd517b8615996ec28e0a934f0 18352 admin optional apt-verify_2.0-1_all.deb
 bdd5ab5ec1d2860ba990b0abc6ada1aa 5455 admin optional apt-verify_2.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iIoEARYIADIWIQSjzJyHC50xCrrUzy9RcisI/kdFogUCZYV2cxQcc2ltb25Aam9z
ZWZzc29uLm9yZwAKCRBRcisI/kdFonYeAP0YFZK8Xg25XzK/IfoYNJJGO0CeTdPM
QUghNUmm3vT0nwEAvD2fSLUxmDDbKm/Q05/iG0+4FedOsZ1LM63m+GPBQQA=
=ZxUb
-----END PGP SIGNATURE-----

#1061185#41
Date:
2025-01-22 08:32:17 UTC
From:
To:
Hi!  You re-opened this ITP bug and changed the title to 'apt-verify:
unsupportable' and made it a RC bug.  It is not clear to me what makes
you believe this is a serious bug in this package, since you gave no
justification.  Can you clarify what your actionable concerns are?

/Simon

#1061185#46
Date:
2025-02-17 22:10:18 UTC
From:
To:
severity 1061185 important
thanks

I'm downgrading this due to lack of explanation what is the 'serious'
severity level problem.

/Simon

Simon Josefsson <simon@josefsson.org> writes:

#1061185#53
Date:
2025-02-17 22:15:45 UTC
From:
To:
Control: severity -1 serious

apt-verify has a defacto RC bug or equivalent because apt has
Conflicts: apt-verify.

Notice how it is unable to migrate to Testing because of the piuparts
regression: https://tracker.debian.org/pkg/apt-verify

I am bumping the severity back to serious just so that someone who
visits that tracker page (or the similar excuses pages) has a handy
link to more explanation why this package is unable to migrate to
Testing. There is history in previous comments to this bug. I am not
personally involved in apt maintenance or deciding whether there
should or shouldn't be a Conflicts here.

Thank you,
Jeremy Bícha

#1061185#60
Date:
2025-02-17 22:24:50 UTC
From:
To:
Jeremy Bícha <jeremy.bicha@canonical.com> writes:

I don't understand this -- why is it a RC bug if the apt maintainers
declare a Conflicts with a package?  Where in the debian policies do you
find support for that view?

It would be nice to resolve the Conflicts in apt too, as an orthogonal
but related issue, but I've been equally unable to understand what
actionable change is requested in 'apt-verify'.  Could we try to have a
discussion about this?

/Simon

#1061185#65
Date:
2025-02-17 22:34:49 UTC
From:
To:
apt is Priority: required. It is impossible to install apt-verify on a
standard Debian install. An uninstallable package cannot possibly be
part of Debian.

Perhaps the piuparts section at
https://release.debian.org/testing/rc_policy.txt applies if you need a
reference.

Sorry, I am unable to help with the dispute with the apt maintainers.

Thank you,
Jeremy Bícha

#1061185#70
Date:
2025-12-28 18:47:35 UTC
From:
To:
Just for the record, this is what happen when trying to install
apt-verfiy now:

Solving dependencies... Error!
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:

Unsatisfied dependencies:
 apt : Conflicts: apt-verify but 2.0-1 is to be installed
Error: Unable to satisfy dependencies. Reached two conflicting decisions:
   1. apt-verify:amd64=2.0-1 is selected for install
   2. apt-verify:amd64=2.0-1 is not selected for install because:
      1. apt:amd64 is selected for install
      2. apt:amd64 Conflicts apt-verify

#1061185#75
Date:
2025-12-28 19:20:38 UTC
From:
To:
override apt's default behaviour for Conflicts: handling.

/Simon

Petter Reinholdtsen <pere@hungry.com> writes: