Hello,

Hugo Buddelmeijer via "Development of GNU Guix and the GNU System 
distribution." <[email protected]> skribis:

> Attempt 1, there is no keyserver defined:

In this case it’s using the default key server that happens to be
configured for GnuPG, in your local config file or in GnuPG itself.

> The manual is not particularly helpful here, because the command-line
> argument is `--key-server` instead of `--keyserver`, so I couldn't
> find it at first.

You can run ‘guix refresh --help’ or rely on tab completion, though.
Also, if one types “--keyserver”, the command prints:

  guix refresh: error: keyserver: unrecognized option
  hint: Did you mean `key-server'?

> Attempt 2:
>
> $ ./pre-inst-env guix refresh -u poppler
> --key-server=hkp://keyserver.ubuntu.com:80
>
> Starting download of /tmp/guix-file.YWyfHq
> From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz...
> Starting download of /tmp/guix-file.5PSDYR
> From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz.sig...
> gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
> gpgv:                using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
> gpgv: Can't check signature: No public key
> Would you like to add this key to keyring
> '/home/hugo/.config/guix/upstream/trustedkeys.kbx'?
> yes
> gpg: Note: Specified keyrings are ignored due to option "use-keyboxd"
> gpg: NOTE: THIS IS A DEVELOPMENT VERSION!
> gpg: It is only intended for test purposes and should NOT be
> gpg: used in a production environment or with production keys!
> gpg: key 3A6A4DB839EAA6D7: public key "Albert Astals Cid
> <[email protected]>" imported
> gpg: Total number processed: 1
> gpg:               imported: 1
> gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
> gpgv:                using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
> gpgv: Can't check signature: No public key
> guix refresh: warning: signature verification failed for
> 'https://poppler.freedesktop.org/poppler-26.08.0.tar.xz' (key:
> CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7)
> guix refresh: warning: poppler: version 26.08.0 could not be
> downloaded and authenticated; not updating

Weird because the key was apparently imported.  Could you check this:

  gpg --no-default-keyring \
    --keyring ~/.config/guix/upstream/trustedkeys.kbx --list-keys

Does it show the key that that was imported above?

I tried this locally:

  ./pre-inst-env guix refresh --key-server=keyserver.ubuntu.com -u poppler

It successfully downloaded the key and then successfully authenticated
the tarball.

At any rate, we should improve diagnostics for the situation above with
something like:

diff --git a/guix/gnupg.scm b/guix/gnupg.scm
index 498f8b34a92..a71cc3cda40 100644
--- a/guix/gnupg.scm
+++ b/guix/gnupg.scm
@@ -253,7 +253,15 @@ (define* (gnupg-verify* sig file
                  ((fingerprint . user)
                   (values 'valid-signature
                           (cons fingerprint user))))
-               (values 'missing-key missing)))
+               (begin
+                 (if server
+                     (warning (G_ "failed to download OpenPGP key '~a' \
+from '~a'~%")
+                              missing server)
+                     (warning (G_ "failed to download OpenPGP key '~a' \
+from default key server~%")
+                              missing))
+                 (values 'missing-key missing))))
 
          (define (receive?)
            (let ((answer
Thanks,
Ludo’.
  • Guidance on how t... Development of GNU Guix and the GNU System distribution.
    • Re: Guidance... Ludovic Courtès
      • Re: Guid... Development of GNU Guix and the GNU System distribution.
        • Re: ... Ludovic Courtès
          • ... Development of GNU Guix and the GNU System distribution.

Reply via email to