Hi all,

Is there some guidance on how to refresh signed packages?

Attempt 1, there is no keyserver defined:

$ ./pre-inst-env guix refresh -u poppler

Starting download of /tmp/guix-file.rGiKNn
From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz...
Starting download of /tmp/guix-file.LqRvcG
From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz.sig...
gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
gpgv:                using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
gpgv: Can't check signature: No public key
Would you like to add this key to keyring '/home/hugo/.config/guix/upstream/trustedkeys.kbx'?
yes
gpg: Note: Specified keyrings are ignored due to option "use-keyboxd"
gpg: NOTE: THIS IS A DEVELOPMENT VERSION!
gpg: It is only intended for test purposes and should NOT be
gpg: used in a production environment or with production keys!
gpg: keyserver receive failed: No keyserver available
guix refresh: warning: missing public key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7 for 'https://poppler.freedesktop.org/poppler-26.08.0.tar.xz' guix refresh: warning: poppler: version 26.08.0 could not be downloaded and authenticated; not updating


The manual is not particularly helpful here, because the command-line argument is `--key-server` instead of `--keyserver`, so I couldn't find it at first.

Attempt 2:

$ ./pre-inst-env guix refresh -u poppler --key-server=hkp://keyserver.ubuntu.com:80

Starting download of /tmp/guix-file.YWyfHq
From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz...
Starting download of /tmp/guix-file.5PSDYR
From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz.sig...
gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
gpgv:                using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
gpgv: Can't check signature: No public key
Would you like to add this key to keyring '/home/hugo/.config/guix/upstream/trustedkeys.kbx'?
yes
gpg: Note: Specified keyrings are ignored due to option "use-keyboxd"
gpg: NOTE: THIS IS A DEVELOPMENT VERSION!
gpg: It is only intended for test purposes and should NOT be
gpg: used in a production environment or with production keys!
gpg: key 3A6A4DB839EAA6D7: public key "Albert Astals Cid <[email protected]>" imported
gpg: Total number processed: 1
gpg:               imported: 1
gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
gpgv:                using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
gpgv: Can't check signature: No public key
guix refresh: warning: signature verification failed for 'https://poppler.freedesktop.org/poppler-26.08.0.tar.xz' (key: CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7) guix refresh: warning: poppler: version 26.08.0 could not be downloaded and authenticated; not updating


Now I'm at a loss. I tried a third time, but the only difference is that the key is then 'unchanged' instead of 'imported' (so it did get the key the second time).

I recall recently refreshing another package that required me to verify the signature, but I don't recall what it was. That worked fine.

I suppose it is suspicious that the signing key of this very important and pretty old package has been created just a few weeks ago and I did not check that yet, but I would expect this to work technically.

Hugo



  • Guidance on how t... Development of GNU Guix and the GNU System distribution.
    • Re: Guidance... Ludovic Courtès
      • Re: Guid... Development of GNU Guix and the GNU System distribution.
        • Re: ... Ludovic Courtès
          • ... Development of GNU Guix and the GNU System distribution.

Reply via email to