Package: apt-cacher-ng Version: 3.7.5-1 Severity: important Dear Maintainer,
Running Discover on a system that uses my apt-cacher-ng instance resulted in the following message: W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. OpenPGP signature verification failed: http://security.debian.org/debian-security trixie-security InRelease: Sub-process /usr/bin/sqv returned an error code (1), error message is: Verifying signature: Message has been manipulated Verifying signature: Message has been manipulated E: http://security.debian.org/debian-security trixie-security InRelease is not (yet) available (Sub-process /usr/bin/sqv returned an error code (1), error message is: Verifying signature: Message has been manipulated Verifying signature: Message has been manipulated) Requesting sqv on the apt-cacher-ng host to validate the file: # sqv --keyring=/etc/apt/trusted.gpg.d/debian-archive-trixie-security-automatic.asc --message /var/cache/apt-cacher-ng/secdeb/dists/trixie-security/InRelease --output /tmp/1 Missing key B0CAB9266E8C3929798B3EEEBDE6D2B9216EC7A8, which is needed to verify signature. Verifying signature: Message has been manipulated Removing the offending InRelease file and requesting Discover to refresh results in an InRelease file that passes SQV validation. The bad file has a filesystem timestamp of August 6th, 14:03. Diffing the bad and good Inrelease files show that the Date: is the same for both files (Thu, 06 Aug 2026 09:33:27 UTC) but various SHA256 hashes and the signature at the end of the file are different. For example: - 9838bcde033a51b3d214a99cc75399f14df0415b79279248ae8866a6b2dd2281 1594893 main/binary-amd64/Packages - 109d397f3295ffcd096cf334105cfbb3a00281ee033041efc5097807b1752fb1 231820 main/binary-amd64/Packages.xz + f66f17e77f4b35f6c04daf302dafa615d80517a247b7f8c3669ee02d25395d74 1596949 main/binary-amd64/Packages + d58ff282c3f5534c3fb906a6e447e892219780feb04d9cde10f5c39552556687 232072 main/binary-amd64/Packages.xz This is not the first instance of this happening. Exactly the same issue occurred with the trixie-backports InRelease file on July 11th. The date field in that file was Fri, 10 Jul 2026 20:06:31 UTC. As far as I can see, apt-cacher-ng does not record where it fetched its files from, so if this is being caused by a bad debian mirror, there seems to be no way to identify which mirror may be at fault. Is there such a way? -- Package-specific info: -- System Information: Debian Release: 13.6 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable') Architecture: armhf (armv7l) Kernel: Linux 7.0.0+ (SMP w/2 CPU threads; PREEMPT) Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB:en Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) Versions of packages apt-cacher-ng depends on: ii adduser 3.152 ii debconf [debconf-2.0] 1.5.91 ii dpkg 1.22.22 ii libbz2-1.0 1.0.8-6 ii libc6 2.41-12+deb13u3 ii libcares2 1.34.5-1+deb13u1 ii libevent-2.1-7t64 2.1.12-stable-10+b1 ii libevent-pthreads-2.1-7t64 2.1.12-stable-10+b1 ii libfuse2t64 2.9.9-9 ii libgcc-s1 14.2.0-19 ii liblzma5 5.8.1-1+deb13u1 ii libssl3t64 3.5.6-1~deb13u2 ii libstdc++6 14.2.0-19 ii libsystemd0 257.13-1~deb13u1 ii libwrap0 7.6.q-36 ii lsb-base 11.6 ii sysvinit-utils [lsb-base] 3.14-4 ii zlib1g 1:1.3.dfsg+really1.3.1-1+b1 Versions of packages apt-cacher-ng recommends: ii ca-certificates 20250419 Versions of packages apt-cacher-ng suggests: pn avahi-daemon <none> pn doc-base <none> -- Configuration Files: /etc/apt-cacher-ng/security.conf [Errno 13] Permission denied: '/etc/apt-cacher-ng/security.conf' -- debconf information: apt-cacher-ng/port: keep apt-cacher-ng/bindaddress: keep apt-cacher-ng/cachedir: keep * apt-cacher-ng/tunnelenable: false apt-cacher-ng/proxy: keep apt-cacher-ng/gentargetmode: No automated setup

