Package: apt-cacher-ng
Version: 3.7.5-1
Severity: important

Dear Maintainer,

Running Discover on a system that uses my apt-cacher-ng instance
resulted in the following message:

W: An error occurred during the signature verification. The repository is not 
updated and the previous index files will be used. OpenPGP signature 
verification failed: http://security.debian.org/debian-security trixie-security 
InRelease: Sub-process /usr/bin/sqv returned an error code (1), error message 
is: Verifying signature:            Message has been manipulated Verifying 
signature:            Message has been manipulated
E: http://security.debian.org/debian-security trixie-security InRelease is not 
(yet) available (Sub-process /usr/bin/sqv returned an error code (1), error 
message is: Verifying signature:            Message has been manipulated 
Verifying signature:            Message has been manipulated)

Requesting sqv on the apt-cacher-ng host to validate the file:

# sqv 
--keyring=/etc/apt/trusted.gpg.d/debian-archive-trixie-security-automatic.asc 
--message /var/cache/apt-cacher-ng/secdeb/dists/trixie-security/InRelease 
--output /tmp/1
Missing key B0CAB9266E8C3929798B3EEEBDE6D2B9216EC7A8, which is needed to verify 
signature.
Verifying signature:
           Message has been manipulated

Removing the offending InRelease file and requesting Discover to refresh
results in an InRelease file that passes SQV validation.

The bad file has a filesystem timestamp of August 6th, 14:03.

Diffing the bad and good Inrelease files show that the Date: is the same
for both files (Thu, 06 Aug 2026 09:33:27 UTC) but various SHA256 hashes
and the signature at the end of the file are different. For example:

- 9838bcde033a51b3d214a99cc75399f14df0415b79279248ae8866a6b2dd2281  1594893 
main/binary-amd64/Packages
- 109d397f3295ffcd096cf334105cfbb3a00281ee033041efc5097807b1752fb1   231820 
main/binary-amd64/Packages.xz
+ f66f17e77f4b35f6c04daf302dafa615d80517a247b7f8c3669ee02d25395d74  1596949 
main/binary-amd64/Packages
+ d58ff282c3f5534c3fb906a6e447e892219780feb04d9cde10f5c39552556687   232072 
main/binary-amd64/Packages.xz

This is not the first instance of this happening. Exactly the same issue
occurred with the trixie-backports InRelease file on July 11th. The
date field in that file was Fri, 10 Jul 2026 20:06:31 UTC.

As far as I can see, apt-cacher-ng does not record where it fetched its
files from, so if this is being caused by a bad debian mirror, there
seems to be no way to identify which mirror may be at fault. Is there
such a way?

-- Package-specific info:

-- System Information:
Debian Release: 13.6
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: armhf (armv7l)

Kernel: Linux 7.0.0+ (SMP w/2 CPU threads; PREEMPT)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_GB:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages apt-cacher-ng depends on:
ii  adduser                     3.152
ii  debconf [debconf-2.0]       1.5.91
ii  dpkg                        1.22.22
ii  libbz2-1.0                  1.0.8-6
ii  libc6                       2.41-12+deb13u3
ii  libcares2                   1.34.5-1+deb13u1
ii  libevent-2.1-7t64           2.1.12-stable-10+b1
ii  libevent-pthreads-2.1-7t64  2.1.12-stable-10+b1
ii  libfuse2t64                 2.9.9-9
ii  libgcc-s1                   14.2.0-19
ii  liblzma5                    5.8.1-1+deb13u1
ii  libssl3t64                  3.5.6-1~deb13u2
ii  libstdc++6                  14.2.0-19
ii  libsystemd0                 257.13-1~deb13u1
ii  libwrap0                    7.6.q-36
ii  lsb-base                    11.6
ii  sysvinit-utils [lsb-base]   3.14-4
ii  zlib1g                      1:1.3.dfsg+really1.3.1-1+b1

Versions of packages apt-cacher-ng recommends:
ii  ca-certificates  20250419

Versions of packages apt-cacher-ng suggests:
pn  avahi-daemon  <none>
pn  doc-base      <none>

-- Configuration Files:
/etc/apt-cacher-ng/security.conf [Errno 13] Permission denied: 
'/etc/apt-cacher-ng/security.conf'

-- debconf information:
  apt-cacher-ng/port: keep
  apt-cacher-ng/bindaddress: keep
  apt-cacher-ng/cachedir: keep
* apt-cacher-ng/tunnelenable: false
  apt-cacher-ng/proxy: keep
  apt-cacher-ng/gentargetmode: No automated setup

Reply via email to