Source: gnupg2
Version: 2.4.9-7
Severity: important
Justification: fails autopkgtest on Debian CI infrastructure
Tags: forky sid
User: [email protected]
Usertags: lxc

Hi,

Debian CI is switching away from lxc containers in favor of incus Containers.
This is motivated by security concerns from us; incus is based on lxc, but
orchestrates containers substantially different: containers are not privileged
(so root in the container is not uid 0 outside of it, and incus imposes a
stricter isolation from the host system.

gnupg2 passes its tests under lxc, but fails under incus.
The relevant part of the failure is (hopefully):

> Setting up libidn2-0:amd64 (2.3.8-5) ...
> Setting up libp11-kit0:amd64 (0.26.4-1) ...
> Setting up libreadline8t64:amd64 (8.3-4) ...
> Setting up gpgconf (2.4.9-7) ...
> Setting up gpg (2.4.9-7) ...
> Created symlink '/etc/systemd/user/sockets.target.wants/keyboxd.socket' → 
> '/usr/lib/systemd/user/keyboxd.socket'.
> Setting up libgnutls30t64:amd64 (3.8.13-1) ...
> Setting up gpg-agent (2.4.9-7) ...
> Created symlink 
> '/etc/systemd/user/sockets.target.wants/gpg-agent-browser.socket' → 
> '/usr/lib/systemd/user/gpg-agent-browser.socket'.
> Created symlink 
> '/etc/systemd/user/sockets.target.wants/gpg-agent-extra.socket' → 
> '/usr/lib/systemd/user/gpg-agent-extra.socket'.
> Created symlink '/etc/systemd/user/sockets.target.wants/gpg-agent-ssh.socket' 
> → '/usr/lib/systemd/user/gpg-agent-ssh.socket'.
> Created symlink '/etc/systemd/user/sockets.target.wants/gpg-agent.socket' → 
> '/usr/lib/systemd/user/gpg-agent.socket'.
> Setting up gpgsm (2.4.9-7) ...
> Setting up dirmngr (2.4.9-7) ...
> Created symlink '/etc/systemd/user/sockets.target.wants/dirmngr.socket' → 
> '/usr/lib/systemd/user/dirmngr.socket'.
> Setting up gnupg (2.4.9-7) ...
> Processing triggers for libc-bin (2.42-17) ...
> autopkgtest [20:49:02]: test verify-openpgp: [-----------------------
> gpg: Cannot create Ed448 or Curve448 key without --compliance=gnupg.
> gpg: Key generation failed: Invalid public key algorithm
> gpg: Cannot create a v5 key without --compliance=gnupg
> gpg: Key generation failed: Unknown version in packet
> gpg: Cannot create a v5 key without --compliance=gnupg
> gpg: Key generation failed: Unknown version in packet
> gpg: error running '/usr/bin/gpg-agent': exit status 2
> gpg: failed to start gpg-agent '/usr/bin/gpg-agent': General error
> gpg: can't connect to the gpg-agent: General error
> gpg: agent_genkey failed: No agent running
> gpg: key generation failed: No agent running
> FAILURE: Failed to generate --compliance=gnupg ed25519/v5+cv25519/v5
> /tmp/autopkgtest.fzoC0Z/build.kNH/src/debian/tests/verify-openpgp: line 150: 
> /tmp/autopkgtest.fzoC0Z/verify-openpgp-artifacts/workdir/certs/librepgp-ed25519/v5+cv25519/v5.cert:
>  No such file or directory
> gpg: librepgp-ed25519/v5+cv25519/v5: skipped: No public key
> gpg: [stdin]: encryption failed: No public key
> === Errors ====
> Failed to generate --compliance=gnupg ed25519/v5+cv25519/v5
> autopkgtest [20:49:06]: test verify-openpgp: -----------------------]
> autopkgtest [20:49:06]: test verify-openpgp:  - - - - - - - - - - results - - 
> - - - - - - - -
> verify-openpgp       FAIL non-zero exit status 1
> autopkgtest [20:49:06]: @@@@@@@@@@@@@@@@@@@@ summary
> gpgv-win32           SKIP Test lists explicitly supported architectures, but 
> the current architecture amd64 isn't listed.
> gpgv-win32           SKIP Test lists explicitly supported architectures, but 
> the current architecture amd64 isn't listed.
> simple-tests         PASS
> migration            PASS
> emacs-epg-message-mode PASS
> verify-openpgp       FAIL non-zero exit status 1


The full autokpgtest logs are available at:
https://ci.debian.net/experiments/8/regressions/
(please beware of pagination)

Common types of failure and suggested fixes are being documented at:
https://wiki.debian.org/ContinuousIntegration/LxcToIncus

Note that for the time being, gnupg2 is still being tested under lxc to
avoid disturbing its testing migration test results.

If you decide to add the `isolation-machine` restriction to get this package
tested under qemu, please mention that explicitly when closing this bug (it's
fine to do that only in the package changelog entry that closes the bug) so
that we can configure your package for qemu on ci.debian.net.

Attachment: signature.asc
Description: PGP signature

Reply via email to