Public bug reported:
Using a repository that skips verification with `trusted=yes` in a non-
deb822 format on Noble causes the release upgrade to Resolute to fail
due to an unsigned repository.
I'm reporting this because it causes some Ubuntu Pro client integration
tests to fail. I'm perfectly happy to change these tests if this is not
behavior we actually want to support in a release upgrade.
The following repro was generated with an LLM; I have gone through the
steps myself to verify that they reproduce the bug properly. This repro
uses aptly and LXD to make a fake third-party repo.
---
This procedure reproduces a Noble to Resolute release-upgrade failure caused by
APT source migration. The release upgrader converts a one-line `.list` source
to deb822 and omits the equivalent `Trusted: yes` field. APT then rejects the
unsigned repository.
The reproducer uses two LXC containers and empty aptly repositories. It does
not require Ubuntu Pro infrastructure, packages, or credentials.
## Prerequisites
Install and initialize LXD on the host. The host must be able to launch the
`ubuntu:noble` image and reach the containers over the LXD network.
These commands expect Resolute to be the supported release-upgrade target from
Noble.
Set names for the disposable containers:
```shell
REPO_CONTAINER=release-upgrader-repro-repo
SUT_CONTAINER=release-upgrader-repro-sut
```
## Create the unsigned repositories
Launch a Noble container to host the repositories:
```shell
lxc launch ubuntu:noble "$REPO_CONTAINER"
```
Install aptly, create empty Noble and Resolute repositories, and publish them
without signatures:
```shell
lxc exec "$REPO_CONTAINER" -- sh -eux <<'EOF'
apt-get update
DEBIAN_FRONTEND=noninteractive apt-get install -y aptly
aptly repo create -distribution=noble -component=main fake-noble
aptly repo create -distribution=resolute -component=main fake-resolute
aptly publish repo \
-skip-signing \
-architectures=amd64 \
fake-noble
aptly publish repo \
-skip-signing \
-architectures=amd64 \
fake-resolute
systemd-run \
--unit=aptly-serve \
--property=WorkingDirectory=/root \
/usr/bin/aptly serve -listen=:8080
EOF
```
Aptly needs `-architectures=amd64` because the repositories contain no
packages. The release upgrader only needs valid repository metadata for both
suites.
Get the repository container's address and verify both `Release` files:
```shell
REPO_IP=$(lxc exec "$REPO_CONTAINER" -- hostname -I | awk '{print $1}')
curl --fail "http://${REPO_IP}:8080/dists/noble/Release"
curl --fail "http://${REPO_IP}:8080/dists/resolute/Release"
```
Each response should include its suite and codename. The published directories
contain `Release`, but no `InRelease` or `Release.gpg` signature.
## Prepare the Noble system
Launch and update the system under test:
```shell
lxc launch ubuntu:noble "$SUT_CONTAINER"
lxc exec "$SUT_CONTAINER" -- sh -eux <<'EOF'
apt-get update
DEBIAN_FRONTEND=noninteractive apt-get dist-upgrade -y
DEBIAN_FRONTEND=noninteractive apt-get install -y update-manager-core
cat > /etc/update-manager/release-upgrades.d/repro.cfg <<'CONFIG'
[Sources]
AllowThirdParty=yes
CONFIG
EOF
```
`AllowThirdParty=yes` keeps the arbitrary repository enabled and lets the
release upgrader rewrite its suite. Without this setting, the upgrader disables
the source as an unknown mirror before running APT.
Add the unsigned repository as a trusted one-line source:
```shell
lxc exec "$SUT_CONTAINER" -- sh -c \
"printf '%s\n' \
'deb [trusted=yes] http://${REPO_IP}:8080 noble main' \
> /etc/apt/sources.list.d/release-upgrader-repro.list"
```
Confirm that APT accepts the source before the release upgrade:
```shell
lxc exec "$SUT_CONTAINER" -- apt-get update -o APT::Update::Error-Mode=any
```
This command must exit zero. It fetches the unsigned Noble `Release` file
because the source contains `trusted=yes`.
## Run the release upgrade
Run the Noble to Resolute upgrade:
```shell
if lxc exec "$SUT_CONTAINER" -- sh -c \
"printf 'y\n' | do-release-upgrade \
--frontend DistUpgradeViewNonInteractive"; then
UPGRADE_EXIT=0
else
UPGRADE_EXIT=$?
fi
printf 'do-release-upgrade exit code: %s\n' "$UPGRADE_EXIT"
```
The upgrade exits nonzero. Inspect the relevant events:
```shell
LOG_PATTERN='migrateToDeb822Sources|updateDeb822Sources|examining:|URIs:'
LOG_PATTERN="${LOG_PATTERN}|Suites:|Trusted:|url_downloadable|not signed"
LOG_PATTERN="${LOG_PATTERN}|abort called"
lxc exec "$SUT_CONTAINER" -- \
grep -n -E "$LOG_PATTERN" /var/log/dist-upgrade/main.log
```
The log should show this sequence:
1. `migrateToDeb822Sources()` runs.
2. `updateDeb822Sources()` examines the generated source.
3. The generated local stanza contains `Types`, `URIs`, `Suites`, and
`Components`, with no `Trusted: yes` field.
4. The upgrader changes the suite from Noble to Resolute and confirms that the
Resolute `Release` URL is downloadable.
5. APT reports that the Resolute repository is not signed.
6. The upgrader aborts.
The abort restores the original `.list` source and removes the generated
`.sources` file. Use `main.log` to inspect the generated stanza after the
failure.
** Affects: ubuntu-release-upgrader (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169768
Title:
Third-party sources in non-deb822 format lose trusted=yes on
Noble->Resolute
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ubuntu-release-upgrader/+bug/2169768/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs