Hi all,
Is there some guidance on how to refresh signed packages?
Attempt 1, there is no keyserver defined:
$ ./pre-inst-env guix refresh -u poppler
Starting download of /tmp/guix-file.rGiKNn
From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz...
Starting download of /tmp/guix-file.LqRvcG
From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz.sig...
gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
gpgv: using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
gpgv: Can't check signature: No public key
Would you like to add this key to keyring
'/home/hugo/.config/guix/upstream/trustedkeys.kbx'?
yes
gpg: Note: Specified keyrings are ignored due to option "use-keyboxd"
gpg: NOTE: THIS IS A DEVELOPMENT VERSION!
gpg: It is only intended for test purposes and should NOT be
gpg: used in a production environment or with production keys!
gpg: keyserver receive failed: No keyserver available
guix refresh: warning: missing public key
CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7 for
'https://poppler.freedesktop.org/poppler-26.08.0.tar.xz'
guix refresh: warning: poppler: version 26.08.0 could not be downloaded
and authenticated; not updating
The manual is not particularly helpful here, because the command-line
argument is `--key-server` instead of `--keyserver`, so I couldn't find
it at first.
Attempt 2:
$ ./pre-inst-env guix refresh -u poppler
--key-server=hkp://keyserver.ubuntu.com:80
Starting download of /tmp/guix-file.YWyfHq
From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz...
Starting download of /tmp/guix-file.5PSDYR
From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz.sig...
gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
gpgv: using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
gpgv: Can't check signature: No public key
Would you like to add this key to keyring
'/home/hugo/.config/guix/upstream/trustedkeys.kbx'?
yes
gpg: Note: Specified keyrings are ignored due to option "use-keyboxd"
gpg: NOTE: THIS IS A DEVELOPMENT VERSION!
gpg: It is only intended for test purposes and should NOT be
gpg: used in a production environment or with production keys!
gpg: key 3A6A4DB839EAA6D7: public key "Albert Astals Cid
<[email protected]>" imported
gpg: Total number processed: 1
gpg: imported: 1
gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
gpgv: using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
gpgv: Can't check signature: No public key
guix refresh: warning: signature verification failed for
'https://poppler.freedesktop.org/poppler-26.08.0.tar.xz' (key:
CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7)
guix refresh: warning: poppler: version 26.08.0 could not be downloaded
and authenticated; not updating
Now I'm at a loss. I tried a third time, but the only difference is
that the key is then 'unchanged' instead of 'imported' (so it did get
the key the second time).
I recall recently refreshing another package that required me to verify
the signature, but I don't recall what it was. That worked fine.
I suppose it is suspicious that the signing key of this very important
and pretty old package has been created just a few weeks ago and I did
not check that yet, but I would expect this to work technically.
Hugo