Received: from mail-lj1-f171.google.com (mail-lj1-f171.google.com [209.85.208.171]) by nld3-dev1.alpinelinux.org (Postfix) with ESMTPS id DA132782C74 for <~alpine/apk-tools@lists.alpinelinux.org>; Thu, 11 Jun 2020 15:58:54 +0000 (UTC) Received: by mail-lj1-f171.google.com with SMTP id q19so7554219lji.2 for <~alpine/apk-tools@lists.alpinelinux.org>; Thu, 11 Jun 2020 08:58:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=3/mtxf5/XUgKvmt4ghmfJQWMW+D2GhOetr/DDALSpl4=; b=lt6iW6Da3NPkrpiJihM1G2GQ8aNrW2IabmwKUBMKipSD0SNhKaABfRNkD+WEOkoqrF d1Utt+iMSYzs9KKvYk5E+ZJ6grwkMkRcVFQhw1LJRnDPQL+FQu6W2PtXzZtF9cQTI2TB kui6In0kTHsY8NLcluRD/shztxYwuKTkiB6HBpuPOXmb0HJrG2au2t7lxUHOMuFyBNu9 pyxwt9U419yTsEJisJX3CMGGgNfQTWCQ4pIF5aF+8IVTHlxUNOFGx5DtytqRDadpMNHL lQS5cMxuAaj/dvd9FjOlR/g35GqVAyKVDkSaB6kwtLXCg96F0mcCblnUHXAjLGoDNhmY VBhw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=3/mtxf5/XUgKvmt4ghmfJQWMW+D2GhOetr/DDALSpl4=; b=bvg6BhLcyCli7gJIytWX2BsY2AYKer36U1WxMNeN2NVZzfNZXycGUgd4HoWt7v3n1A Ts/nJ2uOCxydH36reHQHaLUMjkc7Xbrb2aiitXIw883vhwilGeSQJ1Kapvgcz69qWraL 9CYlza1G+DTF2suUEpWgHezrfPDa3rljbKqOob5srf5/+DeN81ynj3ujdtouHQcypynD KdpPWCb2y46S/JpBNHQSqXDhx62OSPEj4MhVrpP1fljkl8cux6p8mLrCFvId81qOpi1r w4scNJ4472R3tORDKxHGmRlpOt9vPLcvHakWM5/dJFZD6JzKi3GO9L98VMCI8j7bOm4v xw9w== X-Gm-Message-State: AOAM531SIJhFSmzipJnAOOdhjbTQLZ9O0IE8bGV6KWrcACUINR3NsMZO fNXGDEr5ksG1lDvgNjrZaUiWI50ezUyMXER+70w= X-Google-Smtp-Source: ABdhPJz08Fx1QkS7c+/GoDWYIdUH3CzTsA4Owr02CaK7fN2Sm1ZgYG9sjc/u1AGyeUgqJhlUg4Og3Ku/37bSbLq+1nc= X-Received: by 2002:a2e:a495:: with SMTP id h21mr4829151lji.436.1591891133812; Thu, 11 Jun 2020 08:58:53 -0700 (PDT) MIME-Version: 1.0 References: In-Reply-To: From: Reid Rankin Date: Thu, 11 Jun 2020 11:58:42 -0400 Message-ID: Subject: Re: Periodic BAD SIGNATURE issue To: CJ Ess Cc: ~alpine/apk-tools@lists.alpinelinux.org Content-Type: multipart/alternative; boundary="0000000000008d53f805a7d1090c" --0000000000008d53f805a7d1090c Content-Type: text/plain; charset="UTF-8" I've seen this happen before if the connection times out -- a zero-length or truncated package will result in a signature error. While technically accurate, I can imagine a more helpful message for these cases :) --Reid On Thu, Jun 11, 2020 at 11:24 AM CJ Ess wrote: > I am periodically getting BAD SIGNATURE errors from apk when installing > packages. > > I'm not sure what makes the errors start or stop, however I am able to > download and verify the package with curl and apk verify it while still > getting the error from apk add. > > I can also download the index with curl and it looks alright after > unpacking though I don't know how to verify it. > > I do know that neither the index nor package change when the BAD SIGNATURE > errors start or stop. > > Is there any way to get debugging or trace output from APK that might shed > some light? > > This seems to be a common issue just looking at Google results, I see it > reported frequently, but the issues are always closed with no resolution > because it is not possible to reproduce the issue at will. > > --0000000000008d53f805a7d1090c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
I've seen this happen before if the connection t= imes out -- a zero-length or truncated package will result in a signature e= rror. While technically accurate, I can imagine a more helpful message for = these cases :)

--Reid

On Thu, Jun 11, 2020 at 11:24 AM CJ Ess <zxcvbn4038@gmail.com> wrote:
I am periodically getting BAD SIGNATURE errors from ap= k when installing packages.

I'm not sure what makes = the errors start or stop, however I am able to download and verify the pack= age with curl and apk verify it while=C2=A0still getting the error from apk= add.

I can also download the index with curl and = it looks alright after unpacking though I don't know how to verify it.= =C2=A0

I do know that neither the index nor packag= e change when the BAD SIGNATURE errors start or stop.

<= div>Is there any way to get debugging or trace output from APK that might s= hed some light?

This seems to be a common issue ju= st looking at Google results, I see it reported frequently, but the issues = are always closed with no resolution because it is not possible to reproduc= e the issue at will.

--0000000000008d53f805a7d1090c--