moving to ports@, cc'ing espie On 2026-09-20, Luigi Vianello <[email protected]> wrote: > Hello guys, > There seems to be a problem with the -C option of pkg_info. This > option is supposed to verify the signature of a given package. I > didn't encounter this problem on OpenBSD 7.8, but it appears to be > present in 7.9. > I ran these tests on a virtual machine I had running version 7.8, but > after updating to 7.9, the problem arose. > About the "-C" option the manual says: > -C Show certificate information for signed packages. > To be specific, the problem is the last line, which should indicate > that the package is correctly signed. > Here it is (I removed the white lines); the problem is the final error: > ----- > # pkg_info -C xz > Information for inst:xz-5.8.3 > Comment: > library and tools for XZ and LZMA compressed files > Required by: > python-3.13.14 > tiff-4.7.1p2 > zstd-1.5.7p0 > Description: > XZ Utils provide a general purpose data compression library and > command line tools. The native file format is the .xz format, but > also the legacy .lzma format is supported. The .xz format supports > multiple compression algorithms, of which LZMA2 is currently the > primary algorithm. With typical files, XZ Utils create about 30 % > smaller files than gzip. > Maintainer: Christian Weisgerber <[email protected]> > WWW: https://tukaani.org/xz/ > Can't call method "name" on an undefined value at > /usr/libdata/perl5/OpenBSD/PkgInfo.pm line 433. > ---- > I also tried running a diff between the /usr/libdata/perl5/OpenBSD > directory in OpenBSD 7.8 and 7.9, but they don't seem very different > to me... so I assume the problem stems more generally from the > directory structure higher up.
Seems the @signer tags started getting dropped sometime after 7.8 I have a few old installed packages with them (these have PKG_ARCH=* so don't see updates from _SYSTEM_VERSION hence the older packages stay around) but none with 7.9: <symphytum:/var/db/pkg>$ grep @signer */+CONTENTS cvsutils-0.2.6p0/+CONTENTS:@signer openbsd-74-pkg dtb-6.14/+CONTENTS:@signer openbsd-77-pkg hicolor-icon-theme-0.18/+CONTENTS:@signer openbsd-78-pkg manubulon-snmp-2.1.0p0v0/+CONTENTS:@signer openbsd-74-pkg metaauto-1.0p4/+CONTENTS:@signer openbsd-74-pkg p5-Class-Inspector-1.36p0/+CONTENTS:@signer openbsd-74-pkg p5-Config-Simple-4.59p2/+CONTENTS:@signer openbsd-77-pkg p5-DateTime-Tiny-1.08/+CONTENTS:@signer openbsd-77-pkg p5-Digest-HMAC-1.05/+CONTENTS:@signer openbsd-76-pkg p5-Encode-Locale-1.05p0/+CONTENTS:@signer openbsd-76-pkg p5-File-ShareDir-1.118/+CONTENTS:@signer openbsd-74-pkg p5-File-ShareDir-Install-0.14/+CONTENTS:@signer openbsd-74-pkg p5-File-Slurp-9999.32/+CONTENTS:@signer openbsd-74-pkg p5-FreezeThaw-0.5001p0/+CONTENTS:@signer openbsd-74-pkg p5-HTML-Tagset-3.24/+CONTENTS:@signer openbsd-76-pkg p5-IO-Capture-0.05p3/+CONTENTS:@signer openbsd-74-pkg p5-IO-HTML-1.004/+CONTENTS:@signer openbsd-76-pkg p5-MIME-Base32-1.303p0/+CONTENTS:@signer openbsd-76-pkg p5-MLDBM-2.05p0/+CONTENTS:@signer openbsd-74-pkg p5-Module-Find-0.17/+CONTENTS:@signer openbsd-77-pkg p5-Net-ASN-1.08/+CONTENTS:@signer openbsd-76-pkg p5-Net-Domain-TLD-1.75p0/+CONTENTS:@signer openbsd-74-pkg p5-Net-IP-1.26p1/+CONTENTS:@signer openbsd-76-pkg p5-Readonly-2.05p0/+CONTENTS:@signer openbsd-74-pkg p5-Regexp-IPv6-0.03p0/+CONTENTS:@signer openbsd-74-pkg p5-Tie-Simple-1.04p0/+CONTENTS:@signer openbsd-74-pkg p5-Time-Duration-1.21p0v0/+CONTENTS:@signer openbsd-74-pkg p5-XML-NamespaceSupport-1.12p1/+CONTENTS:@signer openbsd-74-pkg p5-XML-SAX-1.02p0/+CONTENTS:@signer openbsd-74-pkg p5-XML-SAX-Base-1.09p0/+CONTENTS:@signer openbsd-74-pkg raspberrypi-firmware-1.20250430p0/+CONTENTS:@signer openbsd-77-pkg slib-3b4p0/+CONTENTS:@signer openbsd-76-pkg terminus-font-4.49.1p2-centered_tilde/+CONTENTS:@signer openbsd-75-pkg xdg-utils-1.2.1/+CONTENTS:@signer openbsd-78-pkg pkg_info -C could probably be changed to not print the warning message in that situation (and it might help to print more info from the @digital-signature line, at least the timestamp?) but the real question is why they stopped getting included - nothing in cvs log stands out as intentionally doing this - so I'm wondering if maybe if it was something in perl 5.42 instead? anyone have ideas? > I’ll add one more thing that has nothing to do with the problem > mentioned above… I’m just mentioning it out of curiosity… since I > don’t know what to make of it. It could be a problem, or it could be > nothing. > I ran the command > pkg_check -f > and it returned a hash mismatch for node-22.23.2v0... that is, it > seems that node had a different hash than the original package but the > same size. No idea about this. > I think it's a false positive... I also ran a `hexdump -C` on both > binaries and compared them with `diff`... and it produced a 3 MB file. it's not a false positive because the file doesn't match the hash. > Still, we're talking about two huge executables... about 100 MB > each... so a text diff file of just 3 MB seems insignificant to me. 1 bit of difference can be enough to totally break the executable. > In any case, if anyone would like to take a look, I’ve shared both > files along with their hashes here: > https://drive.google.com/drive/folders/1MALmOETPPVJ4YLGbmtcg47kIdRFrWkGn?usp=sharing > > Here are other info: > $ ./node.strange --version > v22.23.2 > $ ./node.original --version > v22.23.2 > $ ls -l node.original node.strange > -rwxr-xr-x 1 myuser myuser 99961784 Sep 17 11:39 node.strange > -rwxr-xr-x 1 myuser myuser 99961784 Sep 20 16:18 node.original > > /var/db/pkg/node-22.23.2v0 $ grep -A 3 bin/node$ +CONTENTS > @bin bin/node > @sha v+O2xvhfcXpVUHHCj4MCBDUzDkkLNRbGJ3w6ZzvygZM= > @size 99961784 > @ts 1787673809 > > $ sha256 -b node.original node.strange > SHA256 (node.original) = v+O2xvhfcXpVUHHCj4MCBDUzDkkLNRbGJ3w6ZzvygZM= > SHA256 (node.strange) = eAo22ce9MLZF3we9e3dh2FhsCw38Xm4Lk2qGH3aGaAY= > > When I discovered the mismatch, I uninstalled the package, but first I > made a copy of the binary, and then I reinstalled it. Then I ran > `pkg_check -f` again, and the mismatch was gone. > Thanks all > Luigi Vianello > > -- Please keep replies on the mailing list.
