moving to ports@, cc'ing espie

On 2026-09-20, Luigi Vianello <[email protected]> wrote:
> Hello guys,
> There seems to be a problem with the -C option of pkg_info. This
> option is supposed to verify the signature of a given package. I
> didn't encounter this problem on OpenBSD 7.8, but it appears to be
> present in 7.9.
> I ran these tests on a virtual machine I had running version 7.8, but
> after updating to 7.9, the problem arose.
> About the "-C" option the manual says:
> -C      Show certificate information for signed packages.
> To be specific, the problem is the last line, which should indicate
> that the package is correctly signed.
> Here it is (I removed the white lines); the problem is the final error:
> -----
> # pkg_info -C xz
> Information for inst:xz-5.8.3
> Comment:
> library and tools for XZ and LZMA compressed files
> Required by:
> python-3.13.14
> tiff-4.7.1p2
> zstd-1.5.7p0
> Description:
> XZ Utils provide a general purpose data compression library and
> command line tools. The native file format is the .xz format, but
> also the legacy .lzma format is supported. The .xz format supports
> multiple compression algorithms, of which LZMA2 is currently the
> primary algorithm. With typical files, XZ Utils create about 30 %
> smaller files than gzip.
> Maintainer: Christian Weisgerber <[email protected]>
> WWW: https://tukaani.org/xz/
> Can't call method "name" on an undefined value at
> /usr/libdata/perl5/OpenBSD/PkgInfo.pm line 433.
> ----
> I also tried running a diff between the /usr/libdata/perl5/OpenBSD
> directory in OpenBSD 7.8 and 7.9, but they don't seem very different
> to me... so I assume the problem stems more generally from the
> directory structure higher up.

Seems the @signer tags started getting dropped sometime after 7.8
I have a few old installed packages with them (these have PKG_ARCH=*
so don't see updates from _SYSTEM_VERSION hence the older packages
stay around) but none with 7.9:

<symphytum:/var/db/pkg>$ grep @signer */+CONTENTS
cvsutils-0.2.6p0/+CONTENTS:@signer openbsd-74-pkg
dtb-6.14/+CONTENTS:@signer openbsd-77-pkg
hicolor-icon-theme-0.18/+CONTENTS:@signer openbsd-78-pkg
manubulon-snmp-2.1.0p0v0/+CONTENTS:@signer openbsd-74-pkg
metaauto-1.0p4/+CONTENTS:@signer openbsd-74-pkg
p5-Class-Inspector-1.36p0/+CONTENTS:@signer openbsd-74-pkg
p5-Config-Simple-4.59p2/+CONTENTS:@signer openbsd-77-pkg
p5-DateTime-Tiny-1.08/+CONTENTS:@signer openbsd-77-pkg
p5-Digest-HMAC-1.05/+CONTENTS:@signer openbsd-76-pkg
p5-Encode-Locale-1.05p0/+CONTENTS:@signer openbsd-76-pkg
p5-File-ShareDir-1.118/+CONTENTS:@signer openbsd-74-pkg
p5-File-ShareDir-Install-0.14/+CONTENTS:@signer openbsd-74-pkg
p5-File-Slurp-9999.32/+CONTENTS:@signer openbsd-74-pkg
p5-FreezeThaw-0.5001p0/+CONTENTS:@signer openbsd-74-pkg
p5-HTML-Tagset-3.24/+CONTENTS:@signer openbsd-76-pkg
p5-IO-Capture-0.05p3/+CONTENTS:@signer openbsd-74-pkg
p5-IO-HTML-1.004/+CONTENTS:@signer openbsd-76-pkg
p5-MIME-Base32-1.303p0/+CONTENTS:@signer openbsd-76-pkg
p5-MLDBM-2.05p0/+CONTENTS:@signer openbsd-74-pkg
p5-Module-Find-0.17/+CONTENTS:@signer openbsd-77-pkg
p5-Net-ASN-1.08/+CONTENTS:@signer openbsd-76-pkg
p5-Net-Domain-TLD-1.75p0/+CONTENTS:@signer openbsd-74-pkg
p5-Net-IP-1.26p1/+CONTENTS:@signer openbsd-76-pkg
p5-Readonly-2.05p0/+CONTENTS:@signer openbsd-74-pkg
p5-Regexp-IPv6-0.03p0/+CONTENTS:@signer openbsd-74-pkg
p5-Tie-Simple-1.04p0/+CONTENTS:@signer openbsd-74-pkg
p5-Time-Duration-1.21p0v0/+CONTENTS:@signer openbsd-74-pkg
p5-XML-NamespaceSupport-1.12p1/+CONTENTS:@signer openbsd-74-pkg
p5-XML-SAX-1.02p0/+CONTENTS:@signer openbsd-74-pkg
p5-XML-SAX-Base-1.09p0/+CONTENTS:@signer openbsd-74-pkg
raspberrypi-firmware-1.20250430p0/+CONTENTS:@signer openbsd-77-pkg
slib-3b4p0/+CONTENTS:@signer openbsd-76-pkg
terminus-font-4.49.1p2-centered_tilde/+CONTENTS:@signer openbsd-75-pkg
xdg-utils-1.2.1/+CONTENTS:@signer openbsd-78-pkg

pkg_info -C could probably be changed to not print the warning message
in that situation (and it might help to print more info from the
@digital-signature line, at least the timestamp?) but the real question
is why they stopped getting included - nothing in cvs log stands out as
intentionally doing this - so I'm wondering if maybe if it was something
in perl 5.42 instead? anyone have ideas?


> I’ll add one more thing that has nothing to do with the problem
> mentioned above… I’m just mentioning it out of curiosity… since I
> don’t know what to make of it. It could be a problem, or it could be
> nothing.
> I ran the command
> pkg_check -f
> and it returned a hash mismatch for node-22.23.2v0... that is, it
> seems that node had a different hash than the original package but the
> same size.

No idea about this.

> I think it's a false positive... I also ran a `hexdump -C` on both
> binaries and compared them with `diff`... and it produced a 3 MB file.

it's not a false positive because the file doesn't match the hash.

> Still, we're talking about two huge executables... about 100 MB
> each... so a text diff file of just 3 MB seems insignificant to me.

1 bit of difference can be enough to totally break the executable.

> In any case, if anyone would like to take a look, I’ve shared both
> files along with their hashes here:
> https://drive.google.com/drive/folders/1MALmOETPPVJ4YLGbmtcg47kIdRFrWkGn?usp=sharing
>
> Here are other info:
> $ ./node.strange --version
> v22.23.2
> $ ./node.original --version
> v22.23.2
> $ ls -l node.original node.strange
> -rwxr-xr-x  1 myuser  myuser  99961784 Sep 17 11:39 node.strange
> -rwxr-xr-x  1 myuser  myuser  99961784 Sep 20 16:18 node.original
>
> /var/db/pkg/node-22.23.2v0 $ grep -A 3 bin/node$ +CONTENTS
> @bin bin/node
> @sha v+O2xvhfcXpVUHHCj4MCBDUzDkkLNRbGJ3w6ZzvygZM=
> @size 99961784
> @ts 1787673809
>
> $ sha256 -b node.original node.strange
> SHA256 (node.original) = v+O2xvhfcXpVUHHCj4MCBDUzDkkLNRbGJ3w6ZzvygZM=
> SHA256 (node.strange) = eAo22ce9MLZF3we9e3dh2FhsCw38Xm4Lk2qGH3aGaAY=
>
> When I discovered the mismatch, I uninstalled the package, but first I
> made a copy of the binary, and then I reinstalled it. Then I ran
> `pkg_check -f` again, and the mismatch was gone.
> Thanks all
> Luigi Vianello
>
>


-- 
Please keep replies on the mailing list.

Reply via email to