libera/#devuan-dev/ Saturday, 2019-12-21

agrisrrq, What is your PGP fingerprint?04:07
rrqE93D7167A4F5FA9E9FED497770285BA5CF280BA404:08
agrisrrq, thanks, what tool are you using to sign the releases with SHA256 sums instead a message? are you doing that manually or with some tool?04:09
rrqI use gpg04:09
rrqhave I messed up now again?04:10
agrisgive me a second please while I verify everything is in order04:11
fsmithredrrq, was there a re-release of any 2.1 installer isos?04:16
agrisI don't think you did a detached signature04:16
agrisgpg --verify SHA256SUMS.asc SHA256SUMS04:16
agrisgpg: not a detached signature04:16
agrislooking at the .asc file it includes a signed message, which is a redundant copy of SHA256SUMS04:17
agrislet me veify to contents by hand04:17
agrisremoving the signed message by hand from the signature results in gpg: BAD signature from "Ralph Ronnquist (rrq) <ralph.ronnquist@gmail.com>" [full]04:18
rrqfor some reason I updated some 2.1 iso I believe.. I would have re-signed, but if it's wrong, it's wrong.04:18
golinuxLooks like from the chat on #devuan04:20
agrisno, the files look good04:20
agrishttps://0x0.st/z0gJ.png04:20
agrisrrq, next time you sign the releases, you really should decide on using a detached signature, or a signed message. Not both04:21
fsmithredchecksum on the amd64 netinstall iso on fdo right now does not match what's in the file04:21
rrqok. are the isos correct?04:22
agrisrrq, use --detach-sign not --sign04:23
fsmithredI'm not sure. I used one I found on my hard drive with Oct. 21 date and different checksum04:23
agrisrrq, hold on, i'm downloading a copy from leaseweb now04:23
rrqagris: thanks. I thought I did. but admittedly gpg is not my friend.04:23
agrisno problem, GPG is a very powerful and simple tool ounce you get the hang of it and read the manual04:24
agrisdevuan_ascii_2.1_i386_netinst.iso OK04:26
agrisdevuan_ascii_2.1_amd64_netinst.iso OK04:28
agrisrrq, ok. file checksums and sigs look ok, but there may be some issues with the newer iso04:32
agrisrrq, from now on when signing releases it would be very helpful if instead of what you did, instead:04:33
agrissha256sum --tag * >SHA256SUMS04:33
agrisgpg --armor --detach-sign SHA256SUMS >SHA256SUMS.sig04:34
rrqta. and also that the isos work :)04:35
agrisThis way GPG can be used to verify the actual checksums file, rather than just the embedded signed message04:35
fsmithredrrq, I'm downloading the newer iso now to see if I can reproduce the problem04:35
fsmithredI tested with the older (Oct 21) iso earlier and didn't find the problem.04:36
fsmithredstovepipe in #devuan had wireless issues with the newer iso04:36
rrqright. I still don't remember why netinst needed and update, but in any case that went wrong apparently.04:38
Jjp137I vaguely remember the ISOs being updated and so I did some searching and the reason seems to be towards the bottom: https://lists.dyne.org/lurker/message/20191124.064426.8724ca37.en.html04:39
fsmithredoh yeah, isolinux was interfering with the checksum04:40
fsmithredJjp137, thanks for finding that04:40
Jjp137np04:40
rrqagris: that gpg command creates a sibling .asc files, and an empty .sig file04:40
rrqfor me04:40
agrismy bad the final output redirection may not be needed for gpg04:41
agrisjust gpg --armor --detach-sign SHA256SUM04:42
agrisas per documentation here https://www.dewinter.com/gnupg_howto/english/GPGMiniHowto-5.html04:42
rrqright. that makes the .asc file with detached signature04:42
agrisrrq, cat it out and see if it's just the detached signature or contains a signed message as well04:43
rrqjust the signature04:43
fsmithredgpg -b -a <file>  (is the shortcut)04:43
agrisrrq, good. that's how it should be04:43
rrqthose files updated.. may need to sack the iso builder though :(04:47
rrqbiab04:52
fsmithred<fsmithred> ok, I don't need to go very far. Like your customer, I got asked to plug in media with firmware.04:53
fsmithred<fsmithred> there's no /firmware directory with links to the packages04:53
rrqok. ta.05:27
rrqsame on all05:32
golinuxSo time for more iso making?05:33
rrqworse: time to go back to the ascii2.1 iso building. beowulf has to wait until next decennium :(05:35
golinuxThat's what I meant actually.05:37
golinuxI can sympathize.  This work is a constant learning experience . . .05:38
onefangIf there was nothing left to learn, everything would be scripted, and we can take a holiday.  B-)05:38
golinuxThat assumes there is nothing to learn on a holiday.05:39
golinuxIt is just a different learning.05:39
golinuxBut I digress . . .05:40
onefangThat's how I'm learning all the little nooks and crannies of the package mirror system, by scripting my mirror checker to poke at them all.05:40
rrqfsmithred: was "exclude isolinux.bin from md5sum.txt" the main reason for updates?05:56
rrqexcluding /firmware was a separate accident05:56
fsmithredyeah, the checksum was failing on isolinux.bin - I think that was when you ran the check from the installer.05:57
rrqand "Fixed order of init selection..." was your thing? it will sneak in to this build06:00
fsmithrednot sure about that last one. I think we did talk about it.06:04
fsmithredsleep now06:05
fsmithredmaybe catch you on the other side06:05
LeePenfsmithred: Do you use the live-build package?13:08
LeePenWe are way behind debian on it:13:09
LeePen 4.0.3-1+devuan2 versus 1:2019031113:09
fsmithredno, I don't use it, but some people do13:10
fsmithredand I think they might be using the debian version13:10
LeePenUseful to know. I will have a look.13:10
fsmithredthere was a maintainer for it early in our history, but that didn't last long13:11
fsmithredand there was a desire to use devuan sdk13:12
fsmithredso that live, virtual and embedded images could all be made with the same tools13:12
LeePenSounds sensible. Does anybody have it working?13:14
fsmithredLeePen, don't burn yourself out trying to do too much13:14
LeePenI am just working through the last few outdated packages.13:14
fsmithredI've been using live-sdk for the live images13:14
fsmithredOziTraveller uses debian's live-build to make Star (devuan derivative)13:15
fsmithredoh!13:15
fsmithredI think he's using live-sdk now13:15
LeePenOK. I will look at merging and up to date version and then if anybody wants to make it work better for devuan they have something to base it on.13:18
fsmithrednice. Thanks.13:19
LeePenHmmm, having merged buster, lots of the quilt patches no longer apply. :(13:39

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!