Hi,
On 8/28/26 14:32, Ludovic Courtès wrote:
Hello,
Thanks for verifying it does work properly for you!
Hugo Buddelmeijer via "Development of GNU Guix and the GNU System distribution."
<[email protected]> skribis:
Attempt 1, there is no keyserver defined:
In this case it’s using the default key server that happens to be
configured for GnuPG, in your local config file or in GnuPG itself.
Apparently I did not have a default key server configured. Should Guix
provide a default? I'm quite certain I did not actively remove a key
server. (I suppose there is value in not providing a default key server
though.)
The manual is not particularly helpful here, because the command-line
argument is `--key-server` instead of `--keyserver`, so I couldn't
find it at first.
You can run ‘guix refresh --help’ or rely on tab completion, though.
Also, if one types “--keyserver”, the command prints:
guix refresh: error: keyserver: unrecognized option
hint: Did you mean `key-server'?
I think that is what I did yes. So in total, the documentation was
sufficient.
Perhaps this was just a me-behaving-stupid situation; I try to share my
experience unfiltered, because then it is most helpful in figuring out
whether there is something to improve.
Maybe we can update the `--key-server` instructions in the manual with
an explicit copy of the error, so when people search part of the error,
they find the solution. I'll create a P.R.
Attempt 2:
$ ./pre-inst-env guix refresh -u poppler
--key-server=hkp://keyserver.ubuntu.com:80
..
gpg: Total number processed: 1
gpg: imported: 1
gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
gpgv: using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
gpgv: Can't check signature: No public key
Weird because the key was apparently imported. Could you check this:
gpg --no-default-keyring \
--keyring ~/.config/guix/upstream/trustedkeys.kbx --list-keys
Does it show the key that that was imported above?
Yes:
pub rsa4096 2016-09-05 [SC] [expires: 2027-09-07]
CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
uid [ unknown] Albert Astals Cid <[email protected]>
sub rsa4096 2016-09-05 [E] [expires: 2027-09-07]
8692A42FB1A8B666C51053919D17D97FD8224750
Oh! ~/.config/guix/upstream/trustedkeys.kbx is empty (0 bytes)!
"gpg --list-keys" shows exactly the same output. As does `gpg
--no-default-keyring --list-keys`.
I suppose that's what is wrong, gpg just ignores all these options...
And then gpgv does use that empty keyring for the validation.
Maybe this is all fall-out from gnupg thinking it is a development
version, see <https://codeberg.org/guix/guix/pulls/10645>?
I'm tempted to just wait and see whether fixing that would resolve this
problem as well.
At any rate, we should improve diagnostics for the situation above with
something like:
diff --git a/guix/gnupg.scm b/guix/gnupg.scm
index 498f8b34a92..a71cc3cda40 100644
--- a/guix/gnupg.scm
+++ b/guix/gnupg.scm
@@ -253,7 +253,15 @@ (define* (gnupg-verify* sig file
((fingerprint . user)
(values 'valid-signature
(cons fingerprint user))))
- (values 'missing-key missing)))
+ (begin
+ (if server
+ (warning (G_ "failed to download OpenPGP key '~a' \
+from '~a'~%")
+ missing server)
+ (warning (G_ "failed to download OpenPGP key '~a' \
+from default key server~%")
+ missing))
+ (values 'missing-key missing))))
Maybe also include instructions on how to specify a key server. I'll
propose something once I figure out the whole story.
Hugo