Hi,

On 8/28/26 14:32, Ludovic Courtès wrote:
Hello,

Thanks for verifying it does work properly for you!

Hugo Buddelmeijer via "Development of GNU Guix and the GNU System distribution." 
<[email protected]> skribis:

Attempt 1, there is no keyserver defined:

In this case it’s using the default key server that happens to be
configured for GnuPG, in your local config file or in GnuPG itself.

Apparently I did not have a default key server configured. Should Guix provide a default? I'm quite certain I did not actively remove a key server. (I suppose there is value in not providing a default key server though.)

The manual is not particularly helpful here, because the command-line
argument is `--key-server` instead of `--keyserver`, so I couldn't
find it at first.

You can run ‘guix refresh --help’ or rely on tab completion, though.
Also, if one types “--keyserver”, the command prints:

   guix refresh: error: keyserver: unrecognized option
   hint: Did you mean `key-server'?

I think that is what I did yes. So in total, the documentation was sufficient.

Perhaps this was just a me-behaving-stupid situation; I try to share my experience unfiltered, because then it is most helpful in figuring out whether there is something to improve.

Maybe we can update the `--key-server` instructions in the manual with an explicit copy of the error, so when people search part of the error, they find the solution. I'll create a P.R.


Attempt 2:

$ ./pre-inst-env guix refresh -u poppler
--key-server=hkp://keyserver.ubuntu.com:80
..
gpg: Total number processed: 1
gpg:               imported: 1
gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
gpgv:                using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
gpgv: Can't check signature: No public key

Weird because the key was apparently imported.  Could you check this:

   gpg --no-default-keyring \
     --keyring ~/.config/guix/upstream/trustedkeys.kbx --list-keys

Does it show the key that that was imported above?

Yes:

pub   rsa4096 2016-09-05 [SC] [expires: 2027-09-07]
      CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
uid           [ unknown] Albert Astals Cid <[email protected]>
sub   rsa4096 2016-09-05 [E] [expires: 2027-09-07]
      8692A42FB1A8B666C51053919D17D97FD8224750


Oh!  ~/.config/guix/upstream/trustedkeys.kbx is empty (0 bytes)!

"gpg --list-keys" shows exactly the same output. As does `gpg --no-default-keyring --list-keys`.

I suppose that's what is wrong, gpg just ignores all these options... And then gpgv does use that empty keyring for the validation.

Maybe this is all fall-out from gnupg thinking it is a development version, see <https://codeberg.org/guix/guix/pulls/10645>?

I'm tempted to just wait and see whether fixing that would resolve this problem as well.


At any rate, we should improve diagnostics for the situation above with
something like:


diff --git a/guix/gnupg.scm b/guix/gnupg.scm
index 498f8b34a92..a71cc3cda40 100644
--- a/guix/gnupg.scm
+++ b/guix/gnupg.scm
@@ -253,7 +253,15 @@ (define* (gnupg-verify* sig file
                   ((fingerprint . user)
                    (values 'valid-signature
                            (cons fingerprint user))))
-               (values 'missing-key missing)))
+               (begin
+                 (if server
+                     (warning (G_ "failed to download OpenPGP key '~a' \
+from '~a'~%")
+                              missing server)
+                     (warning (G_ "failed to download OpenPGP key '~a' \
+from default key server~%")
+                              missing))
+                 (values 'missing-key missing))))


Maybe also include instructions on how to specify a key server. I'll propose something once I figure out the whole story.

Hugo



  • Guidance on how t... Development of GNU Guix and the GNU System distribution.
    • Re: Guidance... Ludovic Courtès
      • Re: Guid... Development of GNU Guix and the GNU System distribution.
        • Re: ... Ludovic Courtès
          • ... Development of GNU Guix and the GNU System distribution.

Reply via email to