The same problem has occurred again today: W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. OpenPGP signature verification failed: http://deb.debian.org/debian trixie-backports InRelease: Sub-process /usr/ bin/sqv returned an error code (1), error message is: Verifying signature: Message has been manipulated Verifying signature: Message has been manipulated E: http://deb.debian.org/debian trixie-backports InRelease is not (yet) available (Sub- process /usr/bin/sqv returned an error code (1), error message is: Verifying signature: Message has been manipulated Verifying signature: Message has been manipulated)
The symptoms are the same - the bad InRelease file has changed sha256 hashes, and a different signature to the good InRelease file, and the bad file does not pass the sqv validation. I have now setup a crontab to save all apt-cacher-ng InRelease files at midnight, 4am and 9am in an attempt to capture the past history of these cached files, so I can see whether the latter half of the file and signature is the same as the previous version, which would indicate that a Debian mirror is updating InRelease files in- place, leading to this kind of corruption.
bad2.tar.xz
Description: application/xz-compressed-tar

