The same problem has occurred again today:

W: An error occurred during the signature verification. The repository is not 
updated and the previous index files will be used. OpenPGP signature 
verification 
failed: http://deb.debian.org/debian trixie-backports InRelease: Sub-process 
/usr/
bin/sqv returned an error code (1), error message is: Verifying signature:      
      
Message has been manipulated Verifying signature:            Message has been 
manipulated
E: http://deb.debian.org/debian trixie-backports InRelease is not (yet) 
available (Sub-
process /usr/bin/sqv returned an error code (1), error message is: Verifying 
signature:            Message has been manipulated Verifying signature:         
   Message 
has been manipulated)

The symptoms are the same - the bad InRelease file has changed sha256 hashes, 
and a different signature to the good InRelease file, and the bad
file does not pass the sqv validation.

I have now setup a crontab to save all apt-cacher-ng InRelease files at 
midnight, 
4am and 9am in an attempt to capture the past history of these cached files, so 
I 
can see whether the latter half of the file and signature is the same as the 
previous 
version, which would indicate that a Debian mirror is updating InRelease files 
in-
place, leading to this kind of corruption.

Attachment: bad2.tar.xz
Description: application/xz-compressed-tar

Reply via email to