Diff of the two buildlogs: -- --- b1/build.log 2025-03-17 19:19:38.611479812 +0000 +++ b2/build.log 2025-03-17 19:46:33.487303193 +0000 @@ -1,6 +1,6 @@ I: pbuilder: network access will be disabled during build -I: Current time: Mon Mar 17 07:19:00 -12 2025 -I: pbuilder-time-stamp: 1742239140 +I: Current time: Mon Apr 20 15:43:34 +14 2026 +I: pbuilder-time-stamp: 1776649414 I: Building the build Environment I: extracting base tarball [/var/cache/pbuilder/unstable-reproducible-base.tgz] I: copying local configuration @@ -21,54 +21,86 @@ dpkg-source: info: unpacking debsig-verify_0.33.tar.xz I: Not using root during the build. I: Installing the build-deps -I: user script /srv/workspace/pbuilder/39465/tmp/hooks/D02_print_environment starting +I: user script /srv/workspace/pbuilder/121220/tmp/hooks/D01_modify_environment starting +debug: Running on ionos16-i386. +I: Changing host+domainname to test build reproducibility +I: Adding a custom variable just for the fun of it... +I: Changing /bin/sh to bash +'/bin/sh' -> '/bin/bash' +lrwxrwxrwx 1 root root 9 Apr 20 01:51 /bin/sh -> /bin/bash +I: Setting pbuilder2's login shell to /bin/bash +I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other +I: user script /srv/workspace/pbuilder/121220/tmp/hooks/D01_modify_environment finished +I: user script /srv/workspace/pbuilder/121220/tmp/hooks/D02_print_environment starting I: set - BUILDDIR='/build/reproducible-path' - BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other' - BUILDUSERNAME='pbuilder1' - BUILD_ARCH='i386' - DEBIAN_FRONTEND='noninteractive' - DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=11 ' - DISTRIBUTION='unstable' - HOME='/root' - HOST_ARCH='i386' + BASH=/bin/sh + BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath + BASH_ALIASES=() + BASH_ARGC=() + BASH_ARGV=() + BASH_CMDS=() + BASH_LINENO=([0]="12" [1]="0") + BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:. + BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment") + BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="i686-pc-linux-gnu") + BASH_VERSION='5.2.37(1)-release' + BUILDDIR=/build/reproducible-path + BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other' + BUILDUSERNAME=pbuilder2 + BUILD_ARCH=i386 + DEBIAN_FRONTEND=noninteractive + DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=21 ' + DIRSTACK=() + DISTRIBUTION=unstable + EUID=0 + FUNCNAME=([0]="Echo" [1]="main") + GROUPS=() + HOME=/root + HOSTNAME=i-capture-the-hostname + HOSTTYPE=i686 + HOST_ARCH=i386 IFS=' ' - INVOCATION_ID='e4afa1d37a62412e81c04a8e1e086d18' - LANG='C' - LANGUAGE='en_US:en' - LC_ALL='C' - LD_LIBRARY_PATH='/usr/lib/libeatmydata' - LD_PRELOAD='libeatmydata.so' - MAIL='/var/mail/root' - OPTIND='1' - PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games' - PBCURRENTCOMMANDLINEOPERATION='build' - PBUILDER_OPERATION='build' - PBUILDER_PKGDATADIR='/usr/share/pbuilder' - PBUILDER_PKGLIBDIR='/usr/lib/pbuilder' - PBUILDER_SYSCONFDIR='/etc' - PPID='39465' - PS1='# ' - PS2='> ' + INVOCATION_ID=e041c7b3c1444ea091002b26f38b3c2f + LANG=C + LANGUAGE=de_CH:de + LC_ALL=C + LD_LIBRARY_PATH=/usr/lib/libeatmydata + LD_PRELOAD=libeatmydata.so + MACHTYPE=i686-pc-linux-gnu + MAIL=/var/mail/root + OPTERR=1 + OPTIND=1 + OSTYPE=linux-gnu + PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path + PBCURRENTCOMMANDLINEOPERATION=build + PBUILDER_OPERATION=build + PBUILDER_PKGDATADIR=/usr/share/pbuilder + PBUILDER_PKGLIBDIR=/usr/lib/pbuilder + PBUILDER_SYSCONFDIR=/etc + PIPESTATUS=([0]="0") + POSIXLY_CORRECT=y + PPID=121220 PS4='+ ' - PWD='/' - SHELL='/bin/bash' - SHLVL='2' - SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.BYU6J6pv/pbuilderrc_RlEf --distribution unstable --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.BYU6J6pv/b1 --logfile b1/build.log debsig-verify_0.33.dsc' - SUDO_GID='112' - SUDO_UID='107' - SUDO_USER='jenkins' - TERM='unknown' - TZ='/usr/share/zoneinfo/Etc/GMT+12' - USER='root' - _='/usr/bin/systemd-run' - http_proxy='http://46.16.76.132:3128' + PWD=/ + SHELL=/bin/bash + SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix + SHLVL=3 + SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.BYU6J6pv/pbuilderrc_CKAI --distribution unstable --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.BYU6J6pv/b2 --logfile b2/build.log debsig-verify_0.33.dsc' + SUDO_GID=112 + SUDO_UID=107 + SUDO_USER=jenkins + TERM=unknown + TZ=/usr/share/zoneinfo/Etc/GMT-14 + UID=0 + USER=root + _='I: set' + http_proxy=http://213.165.73.152:3128 I: uname -a - Linux ionos2-i386 6.1.0-32-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.129-1 (2025-03-06) x86_64 GNU/Linux + Linux i-capture-the-hostname 6.1.0-32-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.129-1 (2025-03-06) x86_64 GNU/Linux I: ls -l /bin - lrwxrwxrwx 1 root root 7 Mar 4 11:20 /bin -> usr/bin -I: user script /srv/workspace/pbuilder/39465/tmp/hooks/D02_print_environment finished + lrwxrwxrwx 1 root root 7 Mar 4 2025 /bin -> usr/bin +I: user script /srv/workspace/pbuilder/121220/tmp/hooks/D02_print_environment finished -> Attempting to satisfy build-dependencies -> Creating pbuilder-satisfydepends-dummy package Package: pbuilder-satisfydepends-dummy @@ -181,7 +213,7 @@ Get: 49 http://deb.debian.org/debian unstable/main i386 libpkgconf3 i386 1.8.1-4 [38.4 kB] Get: 50 http://deb.debian.org/debian unstable/main i386 pkgconf-bin i386 1.8.1-4 [30.6 kB] Get: 51 http://deb.debian.org/debian unstable/main i386 pkgconf i386 1.8.1-4 [26.2 kB] -Fetched 25.9 MB in 0s (84.5 MB/s) +Fetched 25.9 MB in 12s (2189 kB/s) Preconfiguring packages ... Selecting previously unselected package readline-common. (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 19770 files and directories currently installed.) @@ -404,7 +436,11 @@ Building tag database... -> Finished parsing the build-deps I: Building the package -I: Running cd /build/reproducible-path/debsig-verify-0.33/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S > ../debsig-verify_0.33_source.changes +I: user script /srv/workspace/pbuilder/121220/tmp/hooks/A99_set_merged_usr starting +Not re-configuring usrmerge for unstable +I: user script /srv/workspace/pbuilder/121220/tmp/hooks/A99_set_merged_usr finished +hostname: Name or service not known +I: Running cd /build/reproducible-path/debsig-verify-0.33/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S > ../debsig-verify_0.33_source.changes dpkg-buildpackage: info: source package debsig-verify dpkg-buildpackage: info: source version 0.33 dpkg-buildpackage: info: source distribution unstable @@ -457,8 +493,8 @@ checking whether make supports the include directive... yes (GNU style) checking whether make supports nested variables... yes checking xargs -n works... yes -checking whether UID '1111' is supported by ustar format... yes -checking whether GID '1111' is supported by ustar format... yes +checking whether UID '2222' is supported by ustar format... yes +checking whether GID '2222' is supported by ustar format... yes checking how to create a ustar tar archive... gnutar checking dependency style of gcc... none checking for gcc... (cached) gcc @@ -511,12 +547,15 @@ config.status: executing test/atconfig commands config.status: executing depfiles commands dh_auto_build -O--builddir=build-tree - cd build-tree && make -j11 + cd build-tree && make -j21 make[1]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree' +make[1]: Warning: File 'Makefile' has modification time 34410175 s in the future make all-recursive make[2]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree' +make[2]: Warning: File 'Makefile' has modification time 34410174 s in the future Making all in . make[3]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree' +make[3]: Warning: File 'Makefile' has modification time 34410174 s in the future /usr/bin/mkdir -p doc sed -e 's,@POLICIES_DIR@,/etc/debsig/policies,g' -e 's,@KEYRINGS_DIR@,/usr/share/debsig/keyrings,g' -e 's,%RELEASE_DATE%,,g' -e 's,%PACKAGE_VERSION%,0.33,g' < ../doc/debsig-verify.1.in > doc/debsig-verify.1 gcc -DHAVE_CONFIG_H -I. -DLIBDPKG_VOLATILE_API=1 -DDEBSIG_POLICIES_DIR=\"/etc/debsig/policies\" -DDEBSIG_KEYRINGS_DIR=\"/usr/share/debsig/keyrings\" -Wdate-time -D_FORTIFY_SOURCE=2 -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.33=. -fstack-protector-strong -Wformat -Werror=format-security -c -o src/ar-parse.o ../src/ar-parse.c @@ -526,941 +565,59 @@ gcc -DHAVE_CONFIG_H -I. -DLIBDPKG_VOLATILE_API=1 -DDEBSIG_POLICIES_DIR=\"/etc/debsig/policies\" -DDEBSIG_KEYRINGS_DIR=\"/usr/share/debsig/keyrings\" -Wdate-time -D_FORTIFY_SOURCE=2 -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.33=. -fstack-protector-strong -Wformat -Werror=format-security -c -o src/openpgp-gpg.o ../src/openpgp-gpg.c gcc -DHAVE_CONFIG_H -I. -DLIBDPKG_VOLATILE_API=1 -DDEBSIG_POLICIES_DIR=\"/etc/debsig/policies\" -DDEBSIG_KEYRINGS_DIR=\"/usr/share/debsig/keyrings\" -Wdate-time -D_FORTIFY_SOURCE=2 -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.33=. -fstack-protector-strong -Wformat -Werror=format-security -c -o src/policy-xml.o ../src/policy-xml.c gcc -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.33=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro -Wl,-z,now -o src/debsig-verify src/ar-parse.o src/debsig-verify.o src/debug.o src/openpgp.o src/openpgp-gpg.o src/policy-xml.o -ldpkg -lmd -lz -llzma -lzstd -lbz2 -lexpat -lexpat +make[3]: warning: Clock skew detected. Your build may be incomplete. make[3]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree' Making all in test make[3]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree/test' +make[3]: Warning: File 'Makefile' has modification time 34410171 s in the future make[3]: Nothing to be done for 'all'. +make[3]: warning: Clock skew detected. Your build may be incomplete. make[3]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree/test' +make[2]: warning: Clock skew detected. Your build may be incomplete. make[2]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree' +make[1]: warning: Clock skew detected. Your build may be incomplete. make[1]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree' dh_auto_test -O--builddir=build-tree - cd build-tree && make -j11 check "TESTSUITEFLAGS=-j11 --verbose" VERBOSE=1 + cd build-tree && make -j21 test "TESTSUITEFLAGS=-j21 --verbose" VERBOSE=1 make[1]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree' -Making check in . -make[2]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree' -make[2]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree' -Making check in test -make[2]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree/test' -make check-local -make[3]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree/test' -/bin/bash ../../test/testsuite -j11 --verbose -## ------------------------------ ## -## debsig-verify 0.33 test suite. ## -## ------------------------------ ## - - - - - - - - - - - -1. debsig-cmd.at:3: testing debsig-verify --version ... -../../test/debsig-cmd.at:5: debsig-verify --version -3. debsig-sig.at:3: testing deb no validates, no sig ... -4. debsig-sig.at:9: testing deb no validates, bad sig ... -2. debsig-cmd.at:8: testing debsig-verify --help ... -../../test/debsig-cmd.at:10: debsig-verify --help -stdout: -6. debsig-sig.at:23: testing deb no validates, good sig, no policy (fprid) ... -Debsig Program Version - 0.33 - Signature Version - 1.0 - Signature Namespace - https://www.debian.org/debsig/1.0/ - Policies Directory - /etc/debsig/policies - Keyrings Directory - /usr/share/debsig/keyrings -stdout: -5. debsig-sig.at:16: testing deb no validates, good sig, no policy dir ... -7. debsig-sig.at:31: testing deb no validates, good sig, no policy (keyid) ... -Usage: debsig-verify [<option>...] <deb> - -Options: - -q, --quiet Quiet, only output fatal errors. - -v, --verbose Verbose output (mainly debug). - -d, --debug Debug output as well. - --list-policies Only list policies that can be used to validate - this sig. Only runs through 'Selection' block. - --use-policy <name> Specify the short policy name to use. - --policies-dir <dir> Use an alternative policies directory. - --keyrings-dir <dir> Use an alternative keyrings directory. - --root <dir> Use an alternative root directory for policy lookup. - --help Output usage info, and exit. - --version Output version info, and exit. -1. debsig-cmd.at:3: 8. debsig-sig.at:39: testing deb validates with fprid, fprid db ... - ok -2. debsig-cmd.at:8: ok -9. debsig-sig.at:46: testing deb validates with keyid, fprid db ... -11. debsig-sig.at:60: testing deb validates with fprid, keyid db ... -10. debsig-sig.at:53: testing deb validates with nameid, fprid db ... -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -dpkg-deb: building package 'debraw' in 'debraw_1.0.deb'. -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. - -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. - -12. debsig-sig.at:69: testing deb validates with keyid, keyid db ... -13. debsig-sig.at:78: testing deb validates with nameid, keyid db ... -../../test/debsig-sig.at:6: $DEBSIG debraw_1.0.deb -stdout: -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -debsig: Starting verification for: debraw_1.0.deb -debsig: Origin Signature check failed. This deb might not be signed. - -3. debsig-sig.at:3: ok -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.14X0wGmVzq/pubring.kbx' created -gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.gEqNjVV0Lf/pubring.kbx' created -gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: enabled compatibility flags: -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.BvT0p2iUl9/pubring.kbx' created -gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: keybox '/tmp/debsig-test-tmp.p8mjkl1x7g/pubring.kbx' created -gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: enabled compatibility flags: -gpg: Total number processed: 1 -gpg: imported: 1 - -gpg: keybox '/tmp/debsig-test-tmp.B9pVRmO9y4/pubring.kbx' created -gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.6NM48fRZha/pubring.kbx' created -gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: enabled compatibility flags: -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: keybox '/tmp/debsig-test-tmp.rQXX9bSfVt/pubring.kbx' created -gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.SMMRnRieou/pubring.kbx' created -gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: enabled compatibility flags:gpg: enabled compatibility flags: -gpg: enabled compatibility flags: -gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: Total number processed: 1 -gpg: imported: 1 -14. debsig-sig.at:87: testing deb validates with subkey, fprid, fprid db ... - -gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: enabled compatibility flags: -gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: enabled compatibility flags: -gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported -gpg: key E9F3837DB59CDACD: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: enabled compatibility flags: -gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported -gpg: key E9F3837DB59CDACD: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported -gpg: key E9F3837DB59CDACD: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported -gpg: key E9F3837DB59CDACD: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: enabled compatibility flags: -gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported -gpg: key E9F3837DB59CDACD: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: enabled compatibility flags: -gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported -gpg: key E9F3837DB59CDACD: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported -gpg: key E9F3837DB59CDACD: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported -gpg: key E9F3837DB59CDACD: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -gpg: enabled compatibility flags: -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.1ZGDXxpcq3/pubring.kbx' created -gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: keybox '/tmp/debsig-test-tmp.62rvCSDw0N/pubring.kbx' created -gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: enabled compatibility flags: -gpg: enabled compatibility flags: -gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> -gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported -gpg: key E9F3837DB59CDACD: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported -gpg: key E9F3837DB59CDACD: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.faowuiKGrz/pubring.kbx' created -gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: enabled compatibility flags: -gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported -gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported -gpg: key 4832DEA0A066232B: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -../../test/debsig-sig.at:64: mkdir -p policies/$TESTKEYID -cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID -$DEBSIG --policies-dir policies debsig_1.0.deb -../../test/debsig-sig.at:13: $DEBSIG debsig_1.0.deb -../../test/debsig-sig.at:50: $DEBSIG --use-policy keyid.pol debsig_1.0.deb -../../test/debsig-sig.at:27: mkdir -p policies/$TESTFPRID -$DEBSIG --policies-dir "policies" debsig_1.0.deb -../../test/debsig-sig.at:20: $DEBSIG --policies-dir "nonexistent" debsig_1.0.deb -stdout: -../../test/debsig-sig.at:57: $DEBSIG --use-policy nameid.pol debsig_1.0.deb -../../test/debsig-sig.at:35: mkdir -p policies/$TESTKEYID -$DEBSIG --policies-dir "policies" debsig_1.0.deb -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Could not find Origin directory for B2551A215CE5C74584C6AE0DE9F3837DB59CDACD - -stdout: -../../test/debsig-sig.at:43: $DEBSIG debsig_1.0.deb -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: getDbPathname: using policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD keyring -debsig: Using policy directory: policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: No applicable policy found. -5. debsig-sig.at:16: ok -stdout: -6. debsig-sig.at:23: ok -../../test/debsig-sig.at:82: mkdir -p policies/$TESTKEYID -cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID -$DEBSIG --policies-dir policies --use-policy nameid.pol debsig_1.0.deb -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: getDbPathname: using policies/E9F3837DB59CDACD keyring -debsig: Using policy directory: policies/E9F3837DB59CDACD -debsig: No applicable policy found. -stderr: -../../test/debsig-sig.at:73: mkdir -p policies/$TESTKEYID -cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID -$DEBSIG --policies-dir policies --use-policy keyid.pol debsig_1.0.deb -7. debsig-sig.at:31: ok -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD -stdout: -stderr: -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -gpg: BAD signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -stdout: -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: getDbPathname: using policies/E9F3837DB59CDACD keyring -debsig: Using policy directory: policies/E9F3837DB59CDACD -debsig: Parsing policy file: policies/E9F3837DB59CDACD/keyid.pol -debsig: parsePolicyFile: parsing 'policies/E9F3837DB59CDACD/keyid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: policies/E9F3837DB59CDACD/keyid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD keyring -debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol -debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: sigVerify: gpg exited abnormally or with non-zero exit status -debsig: verifyGroupRules: failed for origin -debsig: Verification group failed checks. -debsig: Failed verification for debsig_1.0.deb. -stderr: -4. debsig-sig.at:9: ok -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD -stdout: -11. debsig-sig.at:60: ok -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD keyring -debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol -debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) - -9. debsig-sig.at:46: ok - - -15. debsig-sig.at:95: testing deb validates with subkey, keyid, fprid db ... - -16. debsig-sig.at:103: testing deb validates with subkey, subid, fprid db ... - -17. debsig-sig.at:111: testing deb validates with subkey, nameid, fprid db ... - -18. debsig-sig.at:119: testing deb validates with subkey, fprid, keyid db ... -19. debsig-sig.at:129: testing deb validates with subkey, keyid, keyid db ... -stderr: -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -stdout: -stderr: -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD keyring -debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/nameid.pol -debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/nameid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped Debsig Origin Test Key <debsig-test@example.com> -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/nameid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -20. debsig-sig.at:139: testing deb validates with subkey, subid, keyid db ... -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD -stdout: -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD keyring -debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol -debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -10. debsig-sig.at:53: ok -8. debsig-sig.at:39: ok -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -stderr: -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD -stdout: -stderr: -../../test/debsig-sig.at:92: $DEBSIG debsig_1.0.deb -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD -stdout: -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: getDbPathname: using policies/E9F3837DB59CDACD keyring -debsig: Using policy directory: policies/E9F3837DB59CDACD -debsig: Parsing policy file: policies/E9F3837DB59CDACD/nameid.pol -debsig: parsePolicyFile: parsing 'policies/E9F3837DB59CDACD/nameid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped Debsig Origin Test Key <debsig-test@example.com> -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: policies/E9F3837DB59CDACD/nameid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: getDbPathname: using policies/E9F3837DB59CDACD keyring -debsig: Using policy directory: policies/E9F3837DB59CDACD -debsig: Parsing policy file: policies/E9F3837DB59CDACD/keyid.pol -debsig: parsePolicyFile: parsing 'policies/E9F3837DB59CDACD/keyid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: policies/E9F3837DB59CDACD/keyid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring -debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) - -12. debsig-sig.at:69: 13. debsig-sig.at:78: ok - ok -21. debsig-sig.at:149: testing deb validates with subkey, nameid, keyid db ... -dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.p2YX3rjZem/pubring.kbx' created -gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.jAX6emdl97/pubring.kbx' created -gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.fuT74sDwOk/pubring.kbx' created -gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.pliYNxtAI5/pubring.kbx' created -gpg: enabled compatibility flags: -gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: keybox '/tmp/debsig-test-tmp.RQHXMhDA7S/pubring.kbx' created -gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.SEh41rHtXH/pubring.kbx' created -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: enabled compatibility flags: -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: enabled compatibility flags: -gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: enabled compatibility flags: -gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: enabled compatibility flags: -gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: enabled compatibility flags: -gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: enabled compatibility flags: -gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported -gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported -gpg: key 4832DEA0A066232B: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported -gpg: enabled compatibility flags: -gpg: keybox '/tmp/debsig-test-tmp.UlblUOf9Tc/pubring.kbx' created -gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported -gpg: key 4832DEA0A066232B: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported -stderr: -gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported -gpg: key 4832DEA0A066232B: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B - Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 -stdout: -gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 keyring -debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/keyid.pol -debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/keyid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/keyid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported -gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported -gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported -gpg: key 4832DEA0A066232B: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported -gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported -gpg: key 4832DEA0A066232B: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -14. debsig-sig.at:87: ok -gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported -gpg: key 4832DEA0A066232B: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -gpg: Total number processed: 1 -gpg: imported: 1 -gpg: enabled compatibility flags: -gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> -gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed -gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported -gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported -gpg: key 4832DEA0A066232B: secret key imported -gpg: Total number processed: 1 -gpg: unchanged: 1 -gpg: secret keys read: 1 -gpg: secret keys imported: 1 -../../test/debsig-sig.at:108: $DEBSIG --use-policy subid.pol debsig_1.0.deb -../../test/debsig-sig.at:134: mkdir -p policies/$TESTKEYID -cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID -$DEBSIG --policies-dir policies --use-policy keyid.pol debsig_1.0.deb -../../test/debsig-sig.at:100: $DEBSIG --use-policy keyid.pol debsig_1.0.deb -../../test/debsig-sig.at:154: mkdir -p policies/$TESTKEYID -cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID -$DEBSIG --policies-dir policies --use-policy nameid.pol debsig_1.0.deb -../../test/debsig-sig.at:144: mkdir -p policies/$TESTKEYID -cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID -$DEBSIG --policies-dir policies --use-policy subid.pol debsig_1.0.deb -../../test/debsig-sig.at:116: $DEBSIG --use-policy nameid.pol debsig_1.0.deb -../../test/debsig-sig.at:124: mkdir -p policies/$TESTKEYID -cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID -$DEBSIG --policies-dir policies debsig_1.0.deb -stderr: -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B - Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 -stdout: -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 keyring -debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/subid.pol -debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/subid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/subid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -16. debsig-sig.at:103: ok -stderr: -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B - Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 -stdout: -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: getDbPathname: using policies/4C2E30ED5C790356 keyring -debsig: Using policy directory: policies/4C2E30ED5C790356 -debsig: Parsing policy file: policies/4C2E30ED5C790356/keyid.pol -debsig: parsePolicyFile: parsing 'policies/4C2E30ED5C790356/keyid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: policies/4C2E30ED5C790356/keyid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -stderr: -19. debsig-sig.at:129: gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B - Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 - ok -stdout: -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 keyring -debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/keyid.pol -debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/keyid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/keyid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -15. debsig-sig.at:95: ok -stderr: -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B - Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 -stdout: -stderr: -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 keyring -debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/nameid.pol -debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/nameid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped Debsig Origin Test Key <debsig-test@example.com> -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: /build/reproducible-path/debsig-verify-0.33/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/nameid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B - Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 -stdout: -17. debsig-sig.at:111: debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: getDbPathname: using policies/4C2E30ED5C790356 keyring -debsig: Using policy directory: policies/4C2E30ED5C790356 -debsig: Parsing policy file: policies/4C2E30ED5C790356/nameid.pol -debsig: parsePolicyFile: parsing 'policies/4C2E30ED5C790356/nameid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped Debsig Origin Test Key <debsig-test@example.com> -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: policies/4C2E30ED5C790356/nameid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) - ok -stderr: -21. debsig-sig.at:149: ok -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B - Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 -stdout: -stderr: -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: getDbPathname: using policies/4C2E30ED5C790356 keyring -debsig: Using policy directory: policies/4C2E30ED5C790356 -debsig: Parsing policy file: policies/4C2E30ED5C790356/subid.pol -debsig: parsePolicyFile: parsing 'policies/4C2E30ED5C790356/subid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: policies/4C2E30ED5C790356/subid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -gpg: Signature made Mon Mar 17 19:19:32 2025 UTC -gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] -gpg: WARNING: This key is not certified with a trusted signature! -gpg: There is no indication that the signature belongs to the owner. -Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B - Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 -stdout: -20. debsig-sig.at:139: ok -debsig: Starting verification for: debsig_1.0.deb -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: getDbPathname: using policies/4C2E30ED5C790356 keyring -debsig: Using policy directory: policies/4C2E30ED5C790356 -debsig: Parsing policy file: policies/4C2E30ED5C790356/keyid.pol -debsig: parsePolicyFile: parsing 'policies/4C2E30ED5C790356/keyid.pol' -debsig: parsePolicyFile: completed -debsig: Checking Selection group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Selection group(s) passed, policy is usable. -debsig: Using policy file: policies/4C2E30ED5C790356/keyid.pol -debsig: Checking Verification group(s). -debsig: Processing 'origin' key... -debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.33/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring -debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key -debsig: Verification group(s) passed, deb is validated. -debsig: Verified package from 'Debsig testing' (Debsig) -18. debsig-sig.at:119: ok - -## ------------- ## -## Test results. ## -## ------------- ## - -All 21 tests were successful. -make[3]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree/test' -make[2]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree/test' +make[1]: Warning: File 'Makefile' has modification time 34410171 s in the future +make[1]: Nothing to be done for 'test'. +make[1]: warning: Clock skew detected. Your build may be incomplete. make[1]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree' create-stamp debian/debhelper-build-stamp dh_testroot -O--builddir=build-tree dh_prep -O--builddir=build-tree dh_auto_install --destdir=debian/debsig-verify/ -O--builddir=build-tree - cd build-tree && make -j11 install DESTDIR=/build/reproducible-path/debsig-verify-0.33/debian/debsig-verify AM_UPDATE_INFO_DIR=no + cd build-tree && make -j21 install DESTDIR=/build/reproducible-path/debsig-verify-0.33/debian/debsig-verify AM_UPDATE_INFO_DIR=no make[1]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree' +make[1]: Warning: File 'Makefile' has modification time 34410171 s in the future Making install in . make[2]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree' +make[2]: Warning: File 'Makefile' has modification time 34410171 s in the future make[3]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree' +make[3]: Warning: File 'Makefile' has modification time 34410171 s in the future /usr/bin/mkdir -p /build/reproducible-path/debsig-verify-0.33/debian/debsig-verify/etc/debsig/policies /usr/bin/mkdir -p '/build/reproducible-path/debsig-verify-0.33/debian/debsig-verify/usr/bin' /usr/bin/mkdir -p '/build/reproducible-path/debsig-verify-0.33/debian/debsig-verify/usr/share/man/man1' /usr/bin/mkdir -p /build/reproducible-path/debsig-verify-0.33/debian/debsig-verify/usr/share/debsig/keyrings - /usr/bin/install -c src/debsig-verify '/build/reproducible-path/debsig-verify-0.33/debian/debsig-verify/usr/bin' /usr/bin/install -c -m 644 doc/debsig-verify.1 '/build/reproducible-path/debsig-verify-0.33/debian/debsig-verify/usr/share/man/man1' + /usr/bin/install -c src/debsig-verify '/build/reproducible-path/debsig-verify-0.33/debian/debsig-verify/usr/bin' +make[3]: warning: Clock skew detected. Your build may be incomplete. make[3]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree' +make[2]: warning: Clock skew detected. Your build may be incomplete. make[2]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree' Making install in test make[2]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree/test' +make[2]: Warning: File 'Makefile' has modification time 34410168 s in the future make[3]: Entering directory '/build/reproducible-path/debsig-verify-0.33/build-tree/test' +make[3]: Warning: File 'Makefile' has modification time 34410168 s in the future make[3]: Nothing to be done for 'install-exec-am'. make[3]: Nothing to be done for 'install-data-am'. +make[3]: warning: Clock skew detected. Your build may be incomplete. make[3]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree/test' +make[2]: warning: Clock skew detected. Your build may be incomplete. make[2]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree/test' +make[1]: warning: Clock skew detected. Your build may be incomplete. make[1]: Leaving directory '/build/reproducible-path/debsig-verify-0.33/build-tree' dh_installdocs -O--builddir=build-tree debian/rules override_dh_installchangelogs @@ -1488,8 +645,8 @@ make[1]: Leaving directory '/build/reproducible-path/debsig-verify-0.33' dh_md5sums -O--builddir=build-tree dh_builddeb -O--builddir=build-tree -dpkg-deb: building package 'debsig-verify' in '../debsig-verify_0.33_i386.deb'. dpkg-deb: building package 'debsig-verify-dbgsym' in '../debsig-verify-dbgsym_0.33_i386.deb'. +dpkg-deb: building package 'debsig-verify' in '../debsig-verify_0.33_i386.deb'. dpkg-genbuildinfo --build=binary -O../debsig-verify_0.33_i386.buildinfo dpkg-genchanges --build=binary -O../debsig-verify_0.33_i386.changes dpkg-genchanges: info: binary-only upload (no source code included) @@ -1497,12 +654,14 @@ dpkg-buildpackage: info: binary-only upload (no source included) dpkg-genchanges: info: including full source code in upload I: copying local configuration +I: user script /srv/workspace/pbuilder/121220/tmp/hooks/B01_cleanup starting +I: user script /srv/workspace/pbuilder/121220/tmp/hooks/B01_cleanup finished I: unmounting dev/ptmx filesystem I: unmounting dev/pts filesystem I: unmounting dev/shm filesystem I: unmounting proc filesystem I: unmounting sys filesystem I: cleaning the build env -I: removing directory /srv/workspace/pbuilder/39465 and its subdirectories -I: Current time: Mon Mar 17 07:19:37 -12 2025 -I: pbuilder-time-stamp: 1742239177 +I: removing directory /srv/workspace/pbuilder/121220 and its subdirectories +I: Current time: Mon Apr 20 16:09:24 +14 2026 +I: pbuilder-time-stamp: 1776650964