The failure is caused by the order of package configuration: - openjdk-17 is unpacked but properties files still have dpkg_new extensions - ca-certificates-java tries to run postinstallation script which requires a working java. - openjdk 17 now requires java.security file present (presently it was silently ignoring it) to intialise Security.
See: - https://bugs.launchpad.net/ubuntu/+source/ca-certificates-java/+bug/2003822 I will discuss today and convert this one or LP: #2003750 to SRU format to deploy the fix. ** Attachment added: "ca-certificates-fail.log" https://bugs.launchpad.net/ubuntu/+source/ca-certificates-java/+bug/2019908/+attachment/5673408/+files/ca-certificates-fail.log ** Tags added: fr-4364 -- You received this bug notification because you are a member of OpenJDK, which is subscribed to ca-certificates-java in Ubuntu. https://bugs.launchpad.net/bugs/2019908 Title: openjdk-17-jre-headless:arm64 Package ca-certificates-java is not configured yet Status in ca-certificates-java package in Ubuntu: New Bug description: From May-16 below is failing: RUN apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install --yes --no-install-recommends \ openjdk-17-jre-headless #7 111.8 head: cannot open '/etc/ssl/certs/java/cacerts' for reading: No such file or directory #7 111.9 Exception in thread "main" java.lang.InternalError: Error loading java.security file #7 111.9 at java.base/java.security.Security.initialize(Security.java:106) #7 111.9 at java.base/java.security.Security$1.run(Security.java:84) #7 111.9 at java.base/java.security.Security$1.run(Security.java:82) #7 111.9 at java.base/java.security.AccessController.doPrivileged(AccessController.java:318) #7 111.9 at java.base/java.security.Security.<clinit>(Security.java:82) #7 111.9 at java.base/sun.security.jca.ProviderList.<init>(ProviderList.java:178) #7 111.9 at java.base/sun.security.jca.ProviderList$2.run(ProviderList.java:96) #7 111.9 at java.base/sun.security.jca.ProviderList$2.run(ProviderList.java:94) #7 111.9 at java.base/java.security.AccessController.doPrivileged(AccessController.java:318) #7 111.9 at java.base/sun.security.jca.ProviderList.fromSecurityProperties(ProviderList.java:93) #7 111.9 at java.base/sun.security.jca.Providers.<clinit>(Providers.java:55) #7 111.9 at java.base/sun.security.jca.GetInstance.getInstance(GetInstance.java:156) #7 111.9 at java.base/java.security.cert.CertificateFactory.getInstance(CertificateFactory.java:193) #7 111.9 at org.debian.security.KeyStoreHandler.<init>(KeyStoreHandler.java:50) #7 111.9 at org.debian.security.UpdateCertificates.<init>(UpdateCertificates.java:65) #7 111.9 at org.debian.security.UpdateCertificates.main(UpdateCertificates.java:51) #7 111.9 dpkg: error processing package ca-certificates-java (--configure): #7 111.9 installed ca-certificates-java package post-installation script subprocess returned error exit status 1 #7 111.9 dpkg: dependency problems prevent configuration of openjdk-17-jre-headless:arm64: #7 111.9 openjdk-17-jre-headless:arm64 depends on ca-certificates-java (>= 20190405~); however: #7 111.9 Package ca-certificates-java is not configured yet. #7 111.9 #7 111.9 dpkg: error processing package openjdk-17-jre-headless:arm64 (--configure): #7 111.9 dependency problems - leaving unconfigured #7 111.9 Processing triggers for libc-bin (2.35-0ubuntu3.1) ... #7 111.9 Processing triggers for ca-certificates (20211016ubuntu0.22.04.1) ... #7 111.9 Updating certificates in /etc/ssl/certs... #7 112.2 0 added, 0 removed; done. #7 112.2 Running hooks in /etc/ca-certificates/update.d... #7 112.2 #7 112.2 Exception in thread "main" java.lang.InternalError: Error loading java.security file #7 112.2 at java.base/java.security.Security.initialize(Security.java:106) #7 112.2 at java.base/java.security.Security$1.run(Security.java:84) #7 112.2 at java.base/java.security.Security$1.run(Security.java:82) #7 112.2 at java.base/java.security.AccessController.doPrivileged(AccessController.java:318) #7 112.2 at java.base/java.security.Security.<clinit>(Security.java:82) #7 112.2 at java.base/sun.security.jca.ProviderList.<init>(ProviderList.java:178) #7 112.2 at java.base/sun.security.jca.ProviderList$2.run(ProviderList.java:96) #7 112.2 at java.base/sun.security.jca.ProviderList$2.run(ProviderList.java:94) #7 112.2 at java.base/java.security.AccessController.doPrivileged(AccessController.java:318) #7 112.2 at java.base/sun.security.jca.ProviderList.fromSecurityProperties(ProviderList.java:93) #7 112.2 at java.base/sun.security.jca.Providers.<clinit>(Providers.java:55) #7 112.2 at java.base/sun.security.jca.GetInstance.getInstance(GetInstance.java:156) #7 112.2 at java.base/java.security.cert.CertificateFactory.getInstance(CertificateFactory.java:193) #7 112.2 at org.debian.security.KeyStoreHandler.<init>(KeyStoreHandler.java:50) #7 112.2 at org.debian.security.UpdateCertificates.<init>(UpdateCertificates.java:65) #7 112.2 at org.debian.security.UpdateCertificates.main(UpdateCertificates.java:51) #7 112.2 E: /etc/ca-certificates/update.d/jks-keystore exited with code 1. #7 112.2 done. #7 112.3 Errors were encountered while processing: #7 112.3 ca-certificates-java #7 112.3 openjdk-17-jre-headless:arm64 #7 112.3 E: Sub-process /usr/bin/dpkg returned an error code (1) ======================== looks like packages are updated on May-16 http://security.ubuntu.com/ubuntu/pool/universe/o/openjdk-17/ and its causing issues To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ca-certificates-java/+bug/2019908/+subscriptions _______________________________________________ Mailing list: https://launchpad.net/~openjdk Post to : openjdk@lists.launchpad.net Unsubscribe : https://launchpad.net/~openjdk More help : https://help.launchpad.net/ListHelp