On 8/28/26 17:27, Ludovic Courtès wrote:
Hugo Buddelmeijer <[email protected]> skribis:
Apparently I did not have a default key server configured. Should
Guix provide a default? I'm quite certain I did not actively remove a
key server. (I suppose there is value in not providing a default key
server though.)
Yes, picking a default is hard, but maybe we can go with
keyserver.ubuntu.com.
The corollary: if there is no 'default' key server set by Guix itself,
and this is something that needs to be explicitly set by the user, then
the tooling should not mention such a non-existing default.
Perhaps that is something that unreasonably irks me :-).
Weird because the key was apparently imported. Could you check
this:
gpg --no-default-keyring \
--keyring ~/.config/guix/upstream/trustedkeys.kbx --list-keys
Does it show the key that that was imported above?
[...]
Oh! ~/.config/guix/upstream/trustedkeys.kbx is empty (0 bytes)!
"gpg --list-keys" shows exactly the same output. As does `gpg
--no-default-keyring --list-keys`.
Weird. Perhaps that’s because of the empty file?
I figured it out! The problem was that gpg creates
`~/.gnupg/common.conf` that by default contains just "use-keyboxd",
which instructs gpg to ignore all specified keyrings, breaking `guix
refresh`.
Issue to discuss this further: https://codeberg.org/guix/guix/issues/10895 .
Thanks for suggesting to use strace, I'll try to remember that. strace
showed that `~/.gnupg/common.conf` was opened before any of the key
databases, hinting that that file might be the problem.
As a workaround, I simply deleted `~/.gnupg/common.conf`.
Resolved for now, but I don't feel comfortable enough with gpg to
propose an improvement to the documentation / tooling.