Hi Julian, > On 30. Jul 2020, at 19:52, Julian Reschke <[email protected]> wrote: > > Am 30.07.2020 um 19:35 schrieb Julian Reschke: >> ... >> That would fix the immediate issue (I assume), but is somehow risky >> because then it get's harder to understand what actually is checked. >> >> I get that in this case we have a combined vote for these two releases, >> and that they are only released in tandem or not at all. >> >> But what if one of these had a dependency on something that happens to >> be in the staging repo right now, but which is not part of the vote? >> >> It might be better if check-release actually installed the artefact >> locally. I already tried that by changing the MVN_ARGS in the script, >> but couldn't get that working. >> >> Best regards, Julian > > So I did manually install 3.4.6 and then ran the check for the maven > plugin; log output attached. > > Two problems: > > 1) Tests fail: > >> [INFO] T E S T S >> [INFO] ------------------------------------------------------- >> [INFO] Running >> org.apache.jackrabbit.filevault.maven.packaging.it.AnalyzeClassesMultiModuleIT >> [ERROR] Tests run: 1, Failures: 0, Errors: 1, Skipped: 0, Time elapsed: 0.17 >> s <<< FAILURE! - in >> org.apache.jackrabbit.filevault.maven.packaging.it.AnalyzeClassesMultiModuleIT >> [ERROR] >> org.apache.jackrabbit.filevault.maven.packaging.it.AnalyzeClassesMultiModuleIT.multi_module_build_succeeds >> Time elapsed: 0.085 s <<< ERROR! >> org.apache.maven.it.VerificationException: >> Exit code was non-zero: 1; command line and log = >> bin\mvn -e --batch-mode -Dmaven.repo.local=C:\Users\jre\.m2\repository clean >> test >> Der Befehl "mvn" ist entweder falsch geschrieben oder >> konnte nicht gefunden werden. >> >> at >> org.apache.jackrabbit.filevault.maven.packaging.it.AnalyzeClassesMultiModuleIT.multi_module_build_succeeds(AnalyzeClassesMultiModuleIT.java:33) >> Do you haven Maven (mvn) in your PATH?
> but then also > > 2) there seems to be a problem with the checksum checks (only visible in > the log): > >> [INFO] >> [INFO] 3. Verify checksums and signatures >> [INFO] >> [INFO] Verifying >> filevault-package-maven-plugin-1.1.4-source-release.zip... >> gpg: die unterzeichneten Daten sind wohl in >> './filevault-package-maven-plugin/1.1.4/filevault-package-maven-plugin-1.1.4-source-release.zip' >> gpg: Unterschrift vom Di, 28. Jul 2020 08:43:49 MEZ mittels RSA-Schlüssel ID >> 455ECC7C >> gpg: Korrekte Unterschrift von "Konrad Windszus <[email protected] >> <mailto:[email protected]>>" >> gpg: WARNUNG: Dieser Schlüssel trägt keine vertrauenswürdige Signatur! >> gpg: Es gibt keinen Hinweis, daß die Signatur wirklich dem >> vorgeblichen Besitzer gehört. >> Haupt-Fingerabdruck = B91A B7D2 121D C6B0 A61A A182 D774 2D58 455E CC7C >> [INFO] OK: filevault-package-maven-plugin-1.1.4-source-release.zip.asc >> openssl:Error: '' is an invalid command. >> >> Standard commands >> asn1parse ca ciphers cms >> crl crl2pkcs7 dgst dh >> dhparam dsa dsaparam ec >> ecparam enc engine errstr >> gendh gendsa genpkey genrsa >> nseq ocsp passwd pkcs12 >> pkcs7 pkcs8 pkey pkeyparam >> pkeyutl prime rand req >> rsa rsautl s_client s_server >> s_time sess_id smime speed >> spkac srp ts verify >> version x509 >> >> Message Digest commands (see the `dgst' command for more details) >> md2 md4 md5 mdc2 >> rmd160 sha sha1 >> >> Cipher commands (see the `enc' command for more details) >> aes-128-cbc aes-128-ecb aes-192-cbc aes-192-ecb >> aes-256-cbc aes-256-ecb base64 bf >> bf-cbc bf-cfb bf-ecb bf-ofb >> camellia-128-cbc camellia-128-ecb camellia-192-cbc camellia-192-ecb >> camellia-256-cbc camellia-256-ecb cast cast-cbc >> cast5-cbc cast5-cfb cast5-ecb cast5-ofb >> des des-cbc des-cfb des-ecb >> des-ede des-ede-cbc des-ede-cfb des-ede-ofb >> des-ede3 des-ede3-cbc des-ede3-cfb des-ede3-ofb >> des-ofb des3 desx idea >> idea-cbc idea-cfb idea-ecb idea-ofb >> rc2 rc2-40-cbc rc2-64-cbc rc2-cbc >> rc2-cfb rc2-ecb rc2-ofb rc4 >> rc4-40 rc5 rc5-cbc rc5-cfb >> rc5-ecb rc5-ofb seed seed-cbc >> seed-cfb seed-ecb seed-ofb zlib >> >> [INFO] OK: filevault-package-maven-plugin-1.1.4-source-release.zip.sha512 > My key is in https://dist.apache.org/repos/dist/release/jackrabbit/KEYS <https://dist.apache.org/repos/dist/release/jackrabbit/KEYS> (https:// <https://downloads.apache.org/jackrabbit/KEYS>downloads.apache.org/jackrabbit/KEYS <http://downloads.apache.org/jackrabbit/KEYS>) You have to trust those keys, because they are not (yet) signed by anyone else. According to https://jackrabbit.apache.org/filevault/howto_release.html#Appendix_A:_Create_and_add_your_key_to_the_Jackrabbit_KEYS_file <https://jackrabbit.apache.org/filevault/howto_release.html#Appendix_A:_Create_and_add_your_key_to_the_Jackrabbit_KEYS_file> or https://jackrabbit.apache.org/jcr/creating-releases.html#Appendix_A:_Create_and_add_your_key_to_the_Jackrabbit_KEYS_file <https://jackrabbit.apache.org/jcr/creating-releases.html#Appendix_A:_Create_and_add_your_key_to_the_Jackrabbit_KEYS_file> this is enough. I would suggest to mark all keys being listed in https://dist.apache.org/repos/dist/release/jackrabbit/KEYS <https://dist.apache.org/repos/dist/release/jackrabbit/KEYS> as trusted, as only with ASF credentials someone could upload them there. I am still wondering why these issues never come up with the previous releases..... Konrad > Best regards, Julian > <filevault-package-maven-plugin-1.1.4.log>
