Merge lp://staging/~xnox/simplestreams/sensible-default-keyring into lp://staging/simplestreams

Proposed by Dimitri John Ledkov
Status: Rejected
Rejected by: Scott Moser
Proposed branch: lp://staging/~xnox/simplestreams/sensible-default-keyring
Merge into: lp://staging/simplestreams
Diff against target: 55 lines (+8/-4)
4 files modified
bin/sstream-mirror (+2/-1)
bin/sstream-query (+2/-1)
bin/sstream-sync (+2/-1)
tools/sstream-mirror-glance (+2/-1)
To merge this branch: bzr merge lp://staging/~xnox/simplestreams/sensible-default-keyring
Reviewer Review Type Date Requested Status
Scott Moser (community) Needs Fixing
Michał Sawicz (community) Approve
Server Team CI bot continuous-integration Needs Fixing
Review via email: mp+340835@code.staging.launchpad.net

Description of the change

Use sensible default for the cloud image keyring.

Now included in ubuntu-keyring, and available on all systems.

To post a comment you must log in.
Revision history for this message
Michał Sawicz (saviq) wrote :

If doing this, should mirror_url default to http://cloud-images.ubuntu.com/releases?

After all, any mirror other than cloud-images will not sign its streams with the keyring being made default?

review: Needs Information
Revision history for this message
Dimitri John Ledkov (xnox) wrote :

We could default to that too. But an exact rsync mirror of cloud-images.ubuntu.com on the internal network, will still be signed with the same key, as long as it is not modified.

That's how our mirror networks work.... if you mirror it exactly, all signatures remain valid.

Revision history for this message
Server Team CI bot (server-team-bot) wrote :
review: Needs Fixing (continuous-integration)
Revision history for this message
Michał Sawicz (saviq) wrote :

Fine by me, then.

review: Approve
Revision history for this message
Scott Moser (smoser) wrote :

The issue is that your default is very much not always sensible.

While the client (at least for you) might be primarily used to read data
from http://cloud-images.ubuntu.com/ which is signed by a key that is
in the keyring that youv'e given, that is not the only data that it
can read.

The behavior right now is
 a.) default to letting gpg use its default keyring (~/.gnupg or
 $GNUPGHOME)
 b.) allow user to provide a keyring

I do agree that it is annoying to have to provide a keyring path,
but I don't think that your solution is generally correct.

Here are some other signed streams that are not signed by a key
in the cloud-images keyring:
   http://streams.canonical.com/juju/tools/
   http://download.cirros-cloud.net/

If you set the default to the provided keyring, you will actually
break a user that has added the identities to their ~/.gnugp
that signed those streams.

So to fix this right, possibly we could have default keyring
based on the input url?

review: Needs Fixing
Revision history for this message
Scott Moser (smoser) wrote :

Hi.
We've moved simplestreams from bzr on launchpad to git on launchpad.
I'm going to mark this merge proposal as Rejected based only on
the fact that it is a bzr based merge proposal.

Please feel free to re-submit the merge proposal using the launchpad git.
Hopefully the cloud-init doc at
 http://cloudinit.readthedocs.io/en/latest/topics/hacking.html
should give you an idea on how to do that.

Unmerged revisions

460. By Dimitri John Ledkov

Have a sensible default for the simplestreams keyring, now shipped by all ubuntu systems.

Preview Diff

[H/L] Next/Prev Comment, [J/K] Next/Prev File, [N/P] Next/Prev Hunk
The diff is not available at this time. You can reload the page or download it.

Subscribers

People subscribed via source and target branches