Sun Feb 23 04:59:38 UTC 2025 I: starting to build debsig-verify/unstable/i386 on jenkins on '2025-02-23 04:59' Sun Feb 23 04:59:38 UTC 2025 I: The jenkins build log is/was available at https://jenkins.debian.net/userContent/reproducible/debian/build_service/i386_10/44892/console.log Sun Feb 23 04:59:38 UTC 2025 I: Downloading source for unstable/debsig-verify=0.32 --2025-02-23 04:59:38-- http://deb.debian.org/debian/pool/main/d/debsig-verify/debsig-verify_0.32.dsc Connecting to 46.16.76.132:3128... connected. Proxy request sent, awaiting response... 200 OK Length: 2257 (2.2K) [text/prs.lines.tag] Saving to: ‘debsig-verify_0.32.dsc’ 0K .. 100% 342M=0s 2025-02-23 04:59:38 (342 MB/s) - ‘debsig-verify_0.32.dsc’ saved [2257/2257] Sun Feb 23 04:59:38 UTC 2025 I: debsig-verify_0.32.dsc -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 3.0 (native) Source: debsig-verify Binary: debsig-verify Architecture: any Version: 0.32 Maintainer: Dpkg Developers <debian-dpkg@lists.debian.org> Uploaders: Guillem Jover <guillem@debian.org> Standards-Version: 4.7.1 Vcs-Browser: https://git.dpkg.org/cgit/dpkg/debsig-verify.git Vcs-Git: https://git.dpkg.org/git/dpkg/debsig-verify.git Testsuite: autopkgtest Testsuite-Triggers: @builddeps@ Build-Depends: debhelper-compat (= 13), debhelper (>= 13.10), pkgconf, libdpkg-dev (>= 1.22.0), libexpat1-dev, gpg <!nocheck> | gpg-from-sq <!nocheck>, gpg <!nocheck> | sqop <!nocheck> | rsop <!nocheck> | gosop <!nocheck> | pgpainless-cli <!nocheck> | sq <!nocheck>, gpg-agent <!nocheck> | sqop <!nocheck> | rsop <!nocheck> | gosop <!nocheck> | pgpainless-cli <!nocheck> | sq <!nocheck> Build-Conflicts: gosop (<< 1.1.0~), libsop-java-java (<< 4.0.7~), pgpainless-cli (<< 1.3.13~), rsop (<< 0.4.0~), sq (<< 0.40.0~), sqop (<< 0.27.2~) Package-List: debsig-verify deb admin optional arch=any Checksums-Sha1: 914c3d3698212331cef3d85c5ecfb035343f9dbf 151176 debsig-verify_0.32.tar.xz Checksums-Sha256: e6ffa4a9a5d95e6c98f706cebbeef89fc8535d2a92845f302399b8cc1f6c9169 151176 debsig-verify_0.32.tar.xz Files: 8d917f367af4f69d040134ee92e4e839 151176 debsig-verify_0.32.tar.xz -----BEGIN PGP SIGNATURE----- wsG7BAEBCgBvBYJnuhwsCRC5cr8+pK5Xo0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmfu8cczEN9DFJxfdhN+B+FO11awE8CvMI7K6TtEQzrq 3xYhBE8+dPQ2BQwQ9WlldLlyvz6krlejAAB07BAAjkJdSHHlsy7TUHOE62wnP36/ 0RmWCh+DcEZ7w9syAs64xJycE2omCJzhzJdfWDhRoSs7ZaKWhHhRzEEckWkx9KZ5 TZEq42PG59YAT3clRFqfmuJ2dSYGHGLPigbKYqmsSNQhwAybxZeWQBfm3SfmRcrD eMTJ17PTI33PkM344gHuYiNQffaEGLaPOrxECq0iQq7qmJ7PH9R0vJff+AYTm92B vCazmGMzl0gsAIv5jahqyjhvRxvgF52tgkG/EcEMtTAjfgv2ByO88ZF9r4BnQqT8 gDt4ndSLlzzHRatz98VeWy7nz57EQCI1ZV4bEX2yu12749eOh5rfZx4Jvmogre82 +88YGQRhHKdIZL/k4xQJEwqaNWqY4uEgdGD/JYAmCaEQH9YJS+sRWb3oq0+CzWzM AymDqkLa1luko/5AK0QbVY7g+Nqd42oibeRy52LSl+QbxyKTa0DzuTjrnvDOERlU iKkG9IYtK/SWRyAljmv7CYmHdvIPk65A8NSOH3I+1Gf8SBqEl1I7bTkJnCmy/EmN orwyJBBE9elGm3Y2P9R0X/F0t6d8HkH9EQJQqYJ0TwDY3jrntNQyOIy3mArobp6A jOUlh5XBN8Dj2Jep4lJfrL98eQyHTNGNxOhnXR0X21lkZH3QA05C9LnFg+D1NXyK 3fhlWx1M3IQ4pAUBHnI= =zqyH -----END PGP SIGNATURE----- Sun Feb 23 04:59:38 UTC 2025 I: Checking whether the package is not for us Sun Feb 23 04:59:39 UTC 2025 I: Starting 1st build on remote node ionos16-i386.debian.net. Sun Feb 23 04:59:39 UTC 2025 I: Preparing to do remote build '1' on ionos16-i386.debian.net. Sun Feb 23 05:00:10 UTC 2025 I: Deleting $TMPDIR on ionos16-i386.debian.net. I: pbuilder: network access will be disabled during build I: Current time: Fri Mar 27 23:22:39 -12 2026 I: pbuilder-time-stamp: 1774696959 I: Building the build Environment I: extracting base tarball [/var/cache/pbuilder/unstable-reproducible-base.tgz] I: copying local configuration W: --override-config is not set; not updating apt.conf Read the manpage for details. I: mounting /proc filesystem I: mounting /sys filesystem I: creating /{dev,run}/shm I: mounting /dev/pts filesystem I: redirecting /dev/ptmx to /dev/pts/ptmx I: policy-rc.d already exists I: using eatmydata during job I: Copying source file I: copying [debsig-verify_0.32.dsc] I: copying [./debsig-verify_0.32.tar.xz] I: Extracting source dpkg-source: warning: cannot verify inline signature for ./debsig-verify_0.32.dsc: unsupported subcommand dpkg-source: info: extracting debsig-verify in debsig-verify-0.32 dpkg-source: info: unpacking debsig-verify_0.32.tar.xz I: Not using root during the build. I: Installing the build-deps I: user script /srv/workspace/pbuilder/70588/tmp/hooks/D02_print_environment starting I: set BUILDDIR='/build/reproducible-path' BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other' BUILDUSERNAME='pbuilder1' BUILD_ARCH='i386' DEBIAN_FRONTEND='noninteractive' DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=22 ' DISTRIBUTION='unstable' HOME='/root' HOST_ARCH='i386' IFS=' ' INVOCATION_ID='6d1b54358929424b9ebb44584b0f18bc' LANG='C' LANGUAGE='en_US:en' LC_ALL='C' LD_LIBRARY_PATH='/usr/lib/libeatmydata' LD_PRELOAD='libeatmydata.so' MAIL='/var/mail/root' OPTIND='1' PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games' PBCURRENTCOMMANDLINEOPERATION='build' PBUILDER_OPERATION='build' PBUILDER_PKGDATADIR='/usr/share/pbuilder' PBUILDER_PKGLIBDIR='/usr/lib/pbuilder' PBUILDER_SYSCONFDIR='/etc' PPID='70588' PS1='# ' PS2='> ' PS4='+ ' PWD='/' SHELL='/bin/bash' SHLVL='2' SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.UjJP7fXV/pbuilderrc_NgB5 --distribution unstable --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.UjJP7fXV/b1 --logfile b1/build.log debsig-verify_0.32.dsc' SUDO_GID='112' SUDO_UID='107' SUDO_USER='jenkins' TERM='unknown' TZ='/usr/share/zoneinfo/Etc/GMT+12' USER='root' _='/usr/bin/systemd-run' http_proxy='http://213.165.73.152:3128' I: uname -a Linux ionos16-i386 6.1.0-31-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.128-1 (2025-02-07) x86_64 GNU/Linux I: ls -l /bin lrwxrwxrwx 1 root root 7 Nov 22 2024 /bin -> usr/bin I: user script /srv/workspace/pbuilder/70588/tmp/hooks/D02_print_environment finished -> Attempting to satisfy build-dependencies -> Creating pbuilder-satisfydepends-dummy package Package: pbuilder-satisfydepends-dummy Version: 0.invalid.0 Architecture: i386 Maintainer: Debian Pbuilder Team <pbuilder-maint@lists.alioth.debian.org> Description: Dummy package to satisfy dependencies with aptitude - created by pbuilder This package was created automatically by pbuilder to satisfy the build-dependencies of the package being currently built. Depends: debhelper-compat (= 13), debhelper (>= 13.10), pkgconf, libdpkg-dev (>= 1.22.0), libexpat1-dev, gpg | gpg-from-sq, gpg | sqop | rsop | gosop | pgpainless-cli | sq, gpg-agent | sqop | rsop | gosop | pgpainless-cli | sq Conflicts: gosop (<< 1.1.0~), libsop-java-java (<< 4.0.7~), pgpainless-cli (<< 1.3.13~), rsop (<< 0.4.0~), sq (<< 0.40.0~), sqop (<< 0.27.2~) dpkg-deb: building package 'pbuilder-satisfydepends-dummy' in '/tmp/satisfydepends-aptitude/pbuilder-satisfydepends-dummy.deb'. Selecting previously unselected package pbuilder-satisfydepends-dummy. (Reading database ... 19761 files and directories currently installed.) Preparing to unpack .../pbuilder-satisfydepends-dummy.deb ... Unpacking pbuilder-satisfydepends-dummy (0.invalid.0) ... dpkg: pbuilder-satisfydepends-dummy: dependency problems, but configuring anyway as you requested: pbuilder-satisfydepends-dummy depends on debhelper-compat (= 13); however: Package debhelper-compat is not installed. pbuilder-satisfydepends-dummy depends on debhelper (>= 13.10); however: Package debhelper is not installed. pbuilder-satisfydepends-dummy depends on pkgconf; however: Package pkgconf is not installed. pbuilder-satisfydepends-dummy depends on libdpkg-dev (>= 1.22.0); however: Package libdpkg-dev is not installed. pbuilder-satisfydepends-dummy depends on libexpat1-dev; however: Package libexpat1-dev is not installed. pbuilder-satisfydepends-dummy depends on gpg | gpg-from-sq; however: Package gpg is not installed. Package gpg-from-sq is not installed. pbuilder-satisfydepends-dummy depends on gpg | sqop | rsop | gosop | pgpainless-cli | sq; however: Package gpg is not installed. Package sqop is not installed. Package rsop is not installed. Package gosop is not installed. Package pgpainless-cli is not installed. Package sq is not installed. pbuilder-satisfydepends-dummy depends on gpg-agent | sqop | rsop | gosop | pgpainless-cli | sq; however: Package gpg-agent is not installed. Package sqop is not installed. Package rsop is not installed. Package gosop is not installed. Package pgpainless-cli is not installed. Package sq is not installed. Setting up pbuilder-satisfydepends-dummy (0.invalid.0) ... Reading package lists... Building dependency tree... Reading state information... Initializing package states... Writing extended state information... Building tag database... pbuilder-satisfydepends-dummy is already installed at the requested version (0.invalid.0) pbuilder-satisfydepends-dummy is already installed at the requested version (0.invalid.0) The following NEW packages will be installed: autoconf{a} automake{a} autopoint{a} autotools-dev{a} bsdextrautils{a} debhelper{a} dh-autoreconf{a} dh-strip-nondeterminism{a} dwz{a} file{a} gettext{a} gettext-base{a} gpg{a} gpg-agent{a} gpgconf{a} groff-base{a} intltool-debian{a} libarchive-zip-perl{a} libassuan9{a} libbz2-dev{a} libdebhelper-perl{a} libdpkg-dev{a} libelf1t64{a} libexpat1{a} libexpat1-dev{a} libfile-stripnondeterminism-perl{a} libgcrypt20{a} libgpg-error0{a} libicu72{a} liblzma-dev{a} libmagic-mgc{a} libmagic1t64{a} libmd-dev{a} libnpth0t64{a} libpipeline1{a} libpkgconf3{a} libreadline8t64{a} libtool{a} libuchardet0{a} libunistring5{a} libxml2{a} libzstd-dev{a} m4{a} man-db{a} pinentry-curses{a} pkgconf{a} pkgconf-bin{a} po-debconf{a} readline-common{a} sensible-utils{a} zlib1g-dev{a} The following packages are RECOMMENDED but will NOT be installed: bzip2-doc curl gnupg libarchive-cpio-perl libgpg-error-l10n libltdl-dev libmail-sendmail-perl lynx wget 0 packages upgraded, 51 newly installed, 0 to remove and 0 not upgraded. Need to get 25.5 MB of archives. After unpacking 89.8 MB will be used. Writing extended state information... Get: 1 http://deb.debian.org/debian unstable/main i386 readline-common all 8.2-6 [69.4 kB] Get: 2 http://deb.debian.org/debian unstable/main i386 sensible-utils all 0.0.24 [24.8 kB] Get: 3 http://deb.debian.org/debian unstable/main i386 libmagic-mgc i386 1:5.45-3+b1 [314 kB] Get: 4 http://deb.debian.org/debian unstable/main i386 libmagic1t64 i386 1:5.45-3+b1 [115 kB] Get: 5 http://deb.debian.org/debian unstable/main i386 file i386 1:5.45-3+b1 [43.2 kB] Get: 6 http://deb.debian.org/debian unstable/main i386 gettext-base i386 0.23.1-1 [245 kB] Get: 7 http://deb.debian.org/debian unstable/main i386 libuchardet0 i386 0.0.8-1+b2 [69.2 kB] Get: 8 http://deb.debian.org/debian unstable/main i386 groff-base i386 1.23.0-7 [1199 kB] Get: 9 http://deb.debian.org/debian unstable/main i386 bsdextrautils i386 2.40.4-4 [96.4 kB] Get: 10 http://deb.debian.org/debian unstable/main i386 libpipeline1 i386 1.5.8-1 [41.2 kB] Get: 11 http://deb.debian.org/debian unstable/main i386 man-db i386 2.13.0-1 [1428 kB] Get: 12 http://deb.debian.org/debian unstable/main i386 m4 i386 1.4.19-5 [301 kB] Get: 13 http://deb.debian.org/debian unstable/main i386 autoconf all 2.72-3 [493 kB] Get: 14 http://deb.debian.org/debian unstable/main i386 autotools-dev all 20220109.1 [51.6 kB] Get: 15 http://deb.debian.org/debian unstable/main i386 automake all 1:1.17-3 [862 kB] Get: 16 http://deb.debian.org/debian unstable/main i386 autopoint all 0.23.1-1 [770 kB] Get: 17 http://deb.debian.org/debian unstable/main i386 libdebhelper-perl all 13.24.1 [90.9 kB] Get: 18 http://deb.debian.org/debian unstable/main i386 libtool all 2.5.4-3 [539 kB] Get: 19 http://deb.debian.org/debian unstable/main i386 dh-autoreconf all 20 [17.1 kB] Get: 20 http://deb.debian.org/debian unstable/main i386 libarchive-zip-perl all 1.68-1 [104 kB] Get: 21 http://deb.debian.org/debian unstable/main i386 libfile-stripnondeterminism-perl all 1.14.1-2 [19.7 kB] Get: 22 http://deb.debian.org/debian unstable/main i386 dh-strip-nondeterminism all 1.14.1-2 [8620 B] Get: 23 http://deb.debian.org/debian unstable/main i386 libelf1t64 i386 0.192-4 [195 kB] Get: 24 http://deb.debian.org/debian unstable/main i386 dwz i386 0.15-1+b1 [116 kB] Get: 25 http://deb.debian.org/debian unstable/main i386 libunistring5 i386 1.3-1 [458 kB] Get: 26 http://deb.debian.org/debian unstable/main i386 libicu72 i386 72.1-6 [9582 kB] Get: 27 http://deb.debian.org/debian unstable/main i386 libxml2 i386 2.12.7+dfsg+really2.9.14-0.2+b1 [734 kB] Get: 28 http://deb.debian.org/debian unstable/main i386 gettext i386 0.23.1-1 [1714 kB] Get: 29 http://deb.debian.org/debian unstable/main i386 intltool-debian all 0.35.0+20060710.6 [22.9 kB] Get: 30 http://deb.debian.org/debian unstable/main i386 po-debconf all 1.0.21+nmu1 [248 kB] Get: 31 http://deb.debian.org/debian unstable/main i386 debhelper all 13.24.1 [920 kB] Get: 32 http://deb.debian.org/debian unstable/main i386 libgpg-error0 i386 1.51-3 [87.3 kB] Get: 33 http://deb.debian.org/debian unstable/main i386 libassuan9 i386 3.0.1-2 [62.4 kB] Get: 34 http://deb.debian.org/debian unstable/main i386 libgcrypt20 i386 1.11.0-7 [799 kB] Get: 35 http://deb.debian.org/debian unstable/main i386 libreadline8t64 i386 8.2-6 [173 kB] Get: 36 http://deb.debian.org/debian unstable/main i386 gpgconf i386 2.2.46-1+b1 [128 kB] Get: 37 http://deb.debian.org/debian unstable/main i386 gpg i386 2.2.46-1+b1 [574 kB] Get: 38 http://deb.debian.org/debian unstable/main i386 pinentry-curses i386 1.3.1-2 [88.0 kB] Get: 39 http://deb.debian.org/debian unstable/main i386 libnpth0t64 i386 1.8-2 [23.0 kB] Get: 40 http://deb.debian.org/debian unstable/main i386 gpg-agent i386 2.2.46-1+b1 [270 kB] Get: 41 http://deb.debian.org/debian unstable/main i386 libbz2-dev i386 1.0.8-6 [32.1 kB] Get: 42 http://deb.debian.org/debian unstable/main i386 libmd-dev i386 1.1.0-2+b1 [57.4 kB] Get: 43 http://deb.debian.org/debian unstable/main i386 zlib1g-dev i386 1:1.3.dfsg+really1.3.1-1+b1 [916 kB] Get: 44 http://deb.debian.org/debian unstable/main i386 liblzma-dev i386 5.6.3-1+b1 [328 kB] Get: 45 http://deb.debian.org/debian unstable/main i386 libzstd-dev i386 1.5.6+dfsg-2 [354 kB] Get: 46 http://deb.debian.org/debian unstable/main i386 libdpkg-dev i386 1.22.15 [386 kB] Get: 47 http://deb.debian.org/debian unstable/main i386 libexpat1 i386 2.6.4-1 [107 kB] Get: 48 http://deb.debian.org/debian unstable/main i386 libexpat1-dev i386 2.6.4-1 [165 kB] Get: 49 http://deb.debian.org/debian unstable/main i386 libpkgconf3 i386 1.8.1-4 [38.4 kB] Get: 50 http://deb.debian.org/debian unstable/main i386 pkgconf-bin i386 1.8.1-4 [30.6 kB] Get: 51 http://deb.debian.org/debian unstable/main i386 pkgconf i386 1.8.1-4 [26.2 kB] Fetched 25.5 MB in 0s (102 MB/s) Preconfiguring packages ... Selecting previously unselected package readline-common. (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 19761 files and directories currently installed.) Preparing to unpack .../00-readline-common_8.2-6_all.deb ... Unpacking readline-common (8.2-6) ... Selecting previously unselected package sensible-utils. Preparing to unpack .../01-sensible-utils_0.0.24_all.deb ... Unpacking sensible-utils (0.0.24) ... Selecting previously unselected package libmagic-mgc. Preparing to unpack .../02-libmagic-mgc_1%3a5.45-3+b1_i386.deb ... Unpacking libmagic-mgc (1:5.45-3+b1) ... Selecting previously unselected package libmagic1t64:i386. Preparing to unpack .../03-libmagic1t64_1%3a5.45-3+b1_i386.deb ... Unpacking libmagic1t64:i386 (1:5.45-3+b1) ... Selecting previously unselected package file. Preparing to unpack .../04-file_1%3a5.45-3+b1_i386.deb ... Unpacking file (1:5.45-3+b1) ... Selecting previously unselected package gettext-base. Preparing to unpack .../05-gettext-base_0.23.1-1_i386.deb ... Unpacking gettext-base (0.23.1-1) ... Selecting previously unselected package libuchardet0:i386. Preparing to unpack .../06-libuchardet0_0.0.8-1+b2_i386.deb ... Unpacking libuchardet0:i386 (0.0.8-1+b2) ... Selecting previously unselected package groff-base. Preparing to unpack .../07-groff-base_1.23.0-7_i386.deb ... Unpacking groff-base (1.23.0-7) ... Selecting previously unselected package bsdextrautils. Preparing to unpack .../08-bsdextrautils_2.40.4-4_i386.deb ... Unpacking bsdextrautils (2.40.4-4) ... Selecting previously unselected package libpipeline1:i386. Preparing to unpack .../09-libpipeline1_1.5.8-1_i386.deb ... Unpacking libpipeline1:i386 (1.5.8-1) ... Selecting previously unselected package man-db. Preparing to unpack .../10-man-db_2.13.0-1_i386.deb ... Unpacking man-db (2.13.0-1) ... Selecting previously unselected package m4. Preparing to unpack .../11-m4_1.4.19-5_i386.deb ... Unpacking m4 (1.4.19-5) ... Selecting previously unselected package autoconf. Preparing to unpack .../12-autoconf_2.72-3_all.deb ... Unpacking autoconf (2.72-3) ... Selecting previously unselected package autotools-dev. Preparing to unpack .../13-autotools-dev_20220109.1_all.deb ... Unpacking autotools-dev (20220109.1) ... Selecting previously unselected package automake. Preparing to unpack .../14-automake_1%3a1.17-3_all.deb ... Unpacking automake (1:1.17-3) ... Selecting previously unselected package autopoint. Preparing to unpack .../15-autopoint_0.23.1-1_all.deb ... Unpacking autopoint (0.23.1-1) ... Selecting previously unselected package libdebhelper-perl. Preparing to unpack .../16-libdebhelper-perl_13.24.1_all.deb ... Unpacking libdebhelper-perl (13.24.1) ... Selecting previously unselected package libtool. Preparing to unpack .../17-libtool_2.5.4-3_all.deb ... Unpacking libtool (2.5.4-3) ... Selecting previously unselected package dh-autoreconf. Preparing to unpack .../18-dh-autoreconf_20_all.deb ... Unpacking dh-autoreconf (20) ... Selecting previously unselected package libarchive-zip-perl. Preparing to unpack .../19-libarchive-zip-perl_1.68-1_all.deb ... Unpacking libarchive-zip-perl (1.68-1) ... Selecting previously unselected package libfile-stripnondeterminism-perl. Preparing to unpack .../20-libfile-stripnondeterminism-perl_1.14.1-2_all.deb ... Unpacking libfile-stripnondeterminism-perl (1.14.1-2) ... Selecting previously unselected package dh-strip-nondeterminism. Preparing to unpack .../21-dh-strip-nondeterminism_1.14.1-2_all.deb ... Unpacking dh-strip-nondeterminism (1.14.1-2) ... Selecting previously unselected package libelf1t64:i386. Preparing to unpack .../22-libelf1t64_0.192-4_i386.deb ... Unpacking libelf1t64:i386 (0.192-4) ... Selecting previously unselected package dwz. Preparing to unpack .../23-dwz_0.15-1+b1_i386.deb ... Unpacking dwz (0.15-1+b1) ... Selecting previously unselected package libunistring5:i386. Preparing to unpack .../24-libunistring5_1.3-1_i386.deb ... Unpacking libunistring5:i386 (1.3-1) ... Selecting previously unselected package libicu72:i386. Preparing to unpack .../25-libicu72_72.1-6_i386.deb ... Unpacking libicu72:i386 (72.1-6) ... Selecting previously unselected package libxml2:i386. Preparing to unpack .../26-libxml2_2.12.7+dfsg+really2.9.14-0.2+b1_i386.deb ... Unpacking libxml2:i386 (2.12.7+dfsg+really2.9.14-0.2+b1) ... Selecting previously unselected package gettext. Preparing to unpack .../27-gettext_0.23.1-1_i386.deb ... Unpacking gettext (0.23.1-1) ... Selecting previously unselected package intltool-debian. Preparing to unpack .../28-intltool-debian_0.35.0+20060710.6_all.deb ... Unpacking intltool-debian (0.35.0+20060710.6) ... Selecting previously unselected package po-debconf. Preparing to unpack .../29-po-debconf_1.0.21+nmu1_all.deb ... Unpacking po-debconf (1.0.21+nmu1) ... Selecting previously unselected package debhelper. Preparing to unpack .../30-debhelper_13.24.1_all.deb ... Unpacking debhelper (13.24.1) ... Selecting previously unselected package libgpg-error0:i386. Preparing to unpack .../31-libgpg-error0_1.51-3_i386.deb ... Unpacking libgpg-error0:i386 (1.51-3) ... Selecting previously unselected package libassuan9:i386. Preparing to unpack .../32-libassuan9_3.0.1-2_i386.deb ... Unpacking libassuan9:i386 (3.0.1-2) ... Selecting previously unselected package libgcrypt20:i386. Preparing to unpack .../33-libgcrypt20_1.11.0-7_i386.deb ... Unpacking libgcrypt20:i386 (1.11.0-7) ... Selecting previously unselected package libreadline8t64:i386. Preparing to unpack .../34-libreadline8t64_8.2-6_i386.deb ... Adding 'diversion of /lib/i386-linux-gnu/libhistory.so.8 to /lib/i386-linux-gnu/libhistory.so.8.usr-is-merged by libreadline8t64' Adding 'diversion of /lib/i386-linux-gnu/libhistory.so.8.2 to /lib/i386-linux-gnu/libhistory.so.8.2.usr-is-merged by libreadline8t64' Adding 'diversion of /lib/i386-linux-gnu/libreadline.so.8 to /lib/i386-linux-gnu/libreadline.so.8.usr-is-merged by libreadline8t64' Adding 'diversion of /lib/i386-linux-gnu/libreadline.so.8.2 to /lib/i386-linux-gnu/libreadline.so.8.2.usr-is-merged by libreadline8t64' Unpacking libreadline8t64:i386 (8.2-6) ... Selecting previously unselected package gpgconf. Preparing to unpack .../35-gpgconf_2.2.46-1+b1_i386.deb ... Unpacking gpgconf (2.2.46-1+b1) ... Selecting previously unselected package gpg. Preparing to unpack .../36-gpg_2.2.46-1+b1_i386.deb ... Unpacking gpg (2.2.46-1+b1) ... Selecting previously unselected package pinentry-curses. Preparing to unpack .../37-pinentry-curses_1.3.1-2_i386.deb ... Unpacking pinentry-curses (1.3.1-2) ... Selecting previously unselected package libnpth0t64:i386. Preparing to unpack .../38-libnpth0t64_1.8-2_i386.deb ... Unpacking libnpth0t64:i386 (1.8-2) ... Selecting previously unselected package gpg-agent. Preparing to unpack .../39-gpg-agent_2.2.46-1+b1_i386.deb ... Unpacking gpg-agent (2.2.46-1+b1) ... Selecting previously unselected package libbz2-dev:i386. Preparing to unpack .../40-libbz2-dev_1.0.8-6_i386.deb ... Unpacking libbz2-dev:i386 (1.0.8-6) ... Selecting previously unselected package libmd-dev:i386. Preparing to unpack .../41-libmd-dev_1.1.0-2+b1_i386.deb ... Unpacking libmd-dev:i386 (1.1.0-2+b1) ... Selecting previously unselected package zlib1g-dev:i386. Preparing to unpack .../42-zlib1g-dev_1%3a1.3.dfsg+really1.3.1-1+b1_i386.deb ... Unpacking zlib1g-dev:i386 (1:1.3.dfsg+really1.3.1-1+b1) ... Selecting previously unselected package liblzma-dev:i386. Preparing to unpack .../43-liblzma-dev_5.6.3-1+b1_i386.deb ... Unpacking liblzma-dev:i386 (5.6.3-1+b1) ... Selecting previously unselected package libzstd-dev:i386. Preparing to unpack .../44-libzstd-dev_1.5.6+dfsg-2_i386.deb ... Unpacking libzstd-dev:i386 (1.5.6+dfsg-2) ... Selecting previously unselected package libdpkg-dev:i386. Preparing to unpack .../45-libdpkg-dev_1.22.15_i386.deb ... Unpacking libdpkg-dev:i386 (1.22.15) ... Selecting previously unselected package libexpat1:i386. Preparing to unpack .../46-libexpat1_2.6.4-1_i386.deb ... Unpacking libexpat1:i386 (2.6.4-1) ... Selecting previously unselected package libexpat1-dev:i386. Preparing to unpack .../47-libexpat1-dev_2.6.4-1_i386.deb ... Unpacking libexpat1-dev:i386 (2.6.4-1) ... Selecting previously unselected package libpkgconf3:i386. Preparing to unpack .../48-libpkgconf3_1.8.1-4_i386.deb ... Unpacking libpkgconf3:i386 (1.8.1-4) ... Selecting previously unselected package pkgconf-bin. Preparing to unpack .../49-pkgconf-bin_1.8.1-4_i386.deb ... Unpacking pkgconf-bin (1.8.1-4) ... Selecting previously unselected package pkgconf:i386. Preparing to unpack .../50-pkgconf_1.8.1-4_i386.deb ... Unpacking pkgconf:i386 (1.8.1-4) ... Setting up libexpat1:i386 (2.6.4-1) ... Setting up libpipeline1:i386 (1.5.8-1) ... Setting up libnpth0t64:i386 (1.8-2) ... Setting up libicu72:i386 (72.1-6) ... Setting up libzstd-dev:i386 (1.5.6+dfsg-2) ... Setting up bsdextrautils (2.40.4-4) ... Setting up libgpg-error0:i386 (1.51-3) ... Setting up libmagic-mgc (1:5.45-3+b1) ... Setting up libarchive-zip-perl (1.68-1) ... Setting up libdebhelper-perl (13.24.1) ... Setting up libmagic1t64:i386 (1:5.45-3+b1) ... Setting up gettext-base (0.23.1-1) ... Setting up m4 (1.4.19-5) ... Setting up libgcrypt20:i386 (1.11.0-7) ... Setting up file (1:5.45-3+b1) ... Setting up libelf1t64:i386 (0.192-4) ... Setting up autotools-dev (20220109.1) ... Setting up libpkgconf3:i386 (1.8.1-4) ... Setting up libexpat1-dev:i386 (2.6.4-1) ... Setting up libunistring5:i386 (1.3-1) ... Setting up autopoint (0.23.1-1) ... Setting up pkgconf-bin (1.8.1-4) ... Setting up autoconf (2.72-3) ... Setting up liblzma-dev:i386 (5.6.3-1+b1) ... Setting up zlib1g-dev:i386 (1:1.3.dfsg+really1.3.1-1+b1) ... Setting up dwz (0.15-1+b1) ... Setting up sensible-utils (0.0.24) ... Setting up libuchardet0:i386 (0.0.8-1+b2) ... Setting up libassuan9:i386 (3.0.1-2) ... Setting up libmd-dev:i386 (1.1.0-2+b1) ... Setting up readline-common (8.2-6) ... Setting up libxml2:i386 (2.12.7+dfsg+really2.9.14-0.2+b1) ... Setting up libbz2-dev:i386 (1.0.8-6) ... Setting up automake (1:1.17-3) ... update-alternatives: using /usr/bin/automake-1.17 to provide /usr/bin/automake (automake) in auto mode Setting up pinentry-curses (1.3.1-2) ... Setting up libfile-stripnondeterminism-perl (1.14.1-2) ... Setting up gettext (0.23.1-1) ... Setting up libtool (2.5.4-3) ... Setting up pkgconf:i386 (1.8.1-4) ... Setting up intltool-debian (0.35.0+20060710.6) ... Setting up dh-autoreconf (20) ... Setting up libreadline8t64:i386 (8.2-6) ... Setting up dh-strip-nondeterminism (1.14.1-2) ... Setting up groff-base (1.23.0-7) ... Setting up gpgconf (2.2.46-1+b1) ... Setting up gpg (2.2.46-1+b1) ... Setting up libdpkg-dev:i386 (1.22.15) ... Setting up gpg-agent (2.2.46-1+b1) ... Setting up po-debconf (1.0.21+nmu1) ... Setting up man-db (2.13.0-1) ... Not building database; man-db/auto-update is not 'true'. Setting up debhelper (13.24.1) ... Processing triggers for libc-bin (2.40-7) ... Reading package lists... Building dependency tree... Reading state information... Reading extended state information... Initializing package states... Writing extended state information... Building tag database... -> Finished parsing the build-deps I: Building the package I: Running cd /build/reproducible-path/debsig-verify-0.32/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S > ../debsig-verify_0.32_source.changes dpkg-buildpackage: info: source package debsig-verify dpkg-buildpackage: info: source version 0.32 dpkg-buildpackage: info: source distribution unstable dpkg-buildpackage: info: source changed by Guillem Jover <guillem@debian.org> dpkg-source --before-build . dpkg-buildpackage: info: host architecture i386 debian/rules clean dh clean --builddir=build-tree dh_auto_clean -O--builddir=build-tree dh_autoreconf_clean -O--builddir=build-tree dh_clean -O--builddir=build-tree debian/rules binary dh binary --builddir=build-tree dh_update_autotools_config -O--builddir=build-tree dh_autoreconf -O--builddir=build-tree dh_auto_configure -O--builddir=build-tree cd build-tree && ../configure --build=i686-linux-gnu --prefix=/usr --includedir=\${prefix}/include --mandir=\${prefix}/share/man --infodir=\${prefix}/share/info --sysconfdir=/etc --localstatedir=/var --disable-option-checking --disable-silent-rules --libdir=\${prefix}/lib/i386-linux-gnu --runstatedir=/run --disable-maintainer-mode --disable-dependency-tracking checking for gcc... gcc checking whether the C compiler works... yes checking for C compiler default output file name... a.out checking for suffix of executables... checking whether we are cross compiling... no checking for suffix of object files... o checking whether the compiler supports GNU C... yes checking whether gcc accepts -g... yes checking for gcc option to enable C11 features... none needed checking whether gcc understands -c and -o together... yes checking for stdio.h... yes checking for stdlib.h... yes checking for string.h... yes checking for inttypes.h... yes checking for stdint.h... yes checking for strings.h... yes checking for sys/stat.h... yes checking for sys/types.h... yes checking for unistd.h... yes checking for wchar.h... yes checking for minix/config.h... no checking whether it is safe to define __EXTENSIONS__... yes checking whether _XOPEN_SOURCE should be defined... no checking for gcc option to enable large file support... -D_FILE_OFFSET_BITS=64 checking for a BSD-compatible install... /usr/bin/install -c checking whether sleep supports fractional seconds... yes checking filesystem timestamp resolution... 0.01 checking whether build environment is sane... yes checking for a race-free mkdir -p... /usr/bin/mkdir -p checking for gawk... no checking for mawk... mawk checking whether make sets $(MAKE)... yes checking whether make supports the include directive... yes (GNU style) checking whether make supports nested variables... yes checking xargs -n works... yes checking whether UID '1111' is supported by ustar format... yes checking whether GID '1111' is supported by ustar format... yes checking how to create a ustar tar archive... gnutar checking dependency style of gcc... none checking for gcc... (cached) gcc checking whether the compiler supports GNU C... (cached) yes checking whether gcc accepts -g... (cached) yes checking for gcc option to enable C11 features... (cached) none needed checking whether gcc understands -c and -o together... (cached) yes checking for XML_ParserCreate in -lexpat... yes checking for pkg-config... /usr/bin/pkg-config checking pkg-config is at least version 0.9.0... yes checking for libdpkg >= 1.22.0... yes checking for off_t... yes checking for pid_t... yes checking for size_t... yes checking build system type... i686-pc-linux-gnu checking host system type... i686-pc-linux-gnu checking for working strnlen... yes checking for obstacks... yes checking whether gcc accepts -Wall... yes checking whether gcc accepts -Wextra... yes checking whether gcc accepts -Wno-unused-parameter... yes checking whether gcc accepts -Wno-missing-field-initializers... yes checking whether gcc accepts -Wmissing-declarations... yes checking whether gcc accepts -Wmissing-format-attribute... yes checking whether gcc accepts -Wformat -Wformat-security... yes checking whether gcc accepts -Wsizeof-array-argument... yes checking whether gcc accepts -Wpointer-arith... yes checking whether gcc accepts -Wlogical-op... yes checking whether gcc accepts -Wlogical-not-parentheses... yes checking whether gcc accepts -Wswitch-bool... yes checking whether gcc accepts -Wvla... yes checking whether gcc accepts -Winit-self... yes checking whether gcc accepts -Wwrite-strings... yes checking whether gcc accepts -Wcast-align... yes checking whether gcc accepts -Wshadow... yes checking whether gcc accepts -Wduplicated-cond... yes checking whether gcc accepts -Wnull-dereference... yes checking whether gcc accepts -Wdeclaration-after-statement... yes checking whether gcc accepts -Wnested-externs... yes checking whether gcc accepts -Wbad-function-cast... yes checking whether gcc accepts -Wstrict-prototypes... yes checking whether gcc accepts -Wmissing-prototypes... yes checking whether gcc accepts -Wold-style-definition... yes checking that generated files are newer than configure... done configure: creating ./config.status config.status: creating Makefile config.status: creating test/Makefile config.status: creating test/atlocal config.status: creating config.h config.status: executing test/atconfig commands config.status: executing depfiles commands dh_auto_build -O--builddir=build-tree cd build-tree && make -j22 make[1]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree' make all-recursive make[2]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree' Making all in . make[3]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree' /usr/bin/mkdir -p doc sed -e 's,@POLICIES_DIR@,/etc/debsig/policies,g' -e 's,@KEYRINGS_DIR@,/usr/share/debsig/keyrings,g' -e 's,%RELEASE_DATE%,,g' -e 's,%PACKAGE_VERSION%,0.32,g' < ../doc/debsig-verify.1.in > doc/debsig-verify.1 gcc -DHAVE_CONFIG_H -I. -DLIBDPKG_VOLATILE_API=1 -DDEBSIG_POLICIES_DIR=\"/etc/debsig/policies\" -DDEBSIG_KEYRINGS_DIR=\"/usr/share/debsig/keyrings\" -Wdate-time -D_FORTIFY_SOURCE=2 -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.32=. -fstack-protector-strong -Wformat -Werror=format-security -c -o src/ar-parse.o ../src/ar-parse.c gcc -DHAVE_CONFIG_H -I. -DLIBDPKG_VOLATILE_API=1 -DDEBSIG_POLICIES_DIR=\"/etc/debsig/policies\" -DDEBSIG_KEYRINGS_DIR=\"/usr/share/debsig/keyrings\" -Wdate-time -D_FORTIFY_SOURCE=2 -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.32=. -fstack-protector-strong -Wformat -Werror=format-security -c -o src/debsig-verify.o ../src/debsig-verify.c gcc -DHAVE_CONFIG_H -I. -DLIBDPKG_VOLATILE_API=1 -DDEBSIG_POLICIES_DIR=\"/etc/debsig/policies\" -DDEBSIG_KEYRINGS_DIR=\"/usr/share/debsig/keyrings\" -Wdate-time -D_FORTIFY_SOURCE=2 -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.32=. -fstack-protector-strong -Wformat -Werror=format-security -c -o src/debug.o ../src/debug.c gcc -DHAVE_CONFIG_H -I. -DLIBDPKG_VOLATILE_API=1 -DDEBSIG_POLICIES_DIR=\"/etc/debsig/policies\" -DDEBSIG_KEYRINGS_DIR=\"/usr/share/debsig/keyrings\" -Wdate-time -D_FORTIFY_SOURCE=2 -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.32=. -fstack-protector-strong -Wformat -Werror=format-security -c -o src/openpgp.o ../src/openpgp.c gcc -DHAVE_CONFIG_H -I. -DLIBDPKG_VOLATILE_API=1 -DDEBSIG_POLICIES_DIR=\"/etc/debsig/policies\" -DDEBSIG_KEYRINGS_DIR=\"/usr/share/debsig/keyrings\" -Wdate-time -D_FORTIFY_SOURCE=2 -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.32=. -fstack-protector-strong -Wformat -Werror=format-security -c -o src/openpgp-gpg.o ../src/openpgp-gpg.c gcc -DHAVE_CONFIG_H -I. -DLIBDPKG_VOLATILE_API=1 -DDEBSIG_POLICIES_DIR=\"/etc/debsig/policies\" -DDEBSIG_KEYRINGS_DIR=\"/usr/share/debsig/keyrings\" -Wdate-time -D_FORTIFY_SOURCE=2 -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.32=. -fstack-protector-strong -Wformat -Werror=format-security -c -o src/policy-xml.o ../src/policy-xml.c gcc -Wall -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/debsig-verify-0.32=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro -Wl,-z,now -o src/debsig-verify src/ar-parse.o src/debsig-verify.o src/debug.o src/openpgp.o src/openpgp-gpg.o src/policy-xml.o -ldpkg -lmd -lz -llzma -lzstd -lbz2 -lexpat -lexpat make[3]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree' Making all in test make[3]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree/test' make[3]: Nothing to be done for 'all'. make[3]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree/test' make[2]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree' make[1]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree' dh_auto_test -O--builddir=build-tree cd build-tree && make -j22 check "TESTSUITEFLAGS=-j22 --verbose" VERBOSE=1 make[1]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree' Making check in . make[2]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree' make[2]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree' Making check in test make[2]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree/test' make check-local make[3]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree/test' /bin/bash ../../test/testsuite -j22 --verbose ## ------------------------------ ## ## debsig-verify 0.32 test suite. ## ## ------------------------------ ## 1. debsig-cmd.at:3: testing debsig-verify --version ... ../../test/debsig-cmd.at:5: debsig-verify --version 2. debsig-cmd.at:8: testing debsig-verify --help ... ../../test/debsig-cmd.at:10: debsig-verify --help 3. debsig-sig.at:3: testing deb no validates, no sig ... 4. debsig-sig.at:9: testing deb no validates, bad sig ... 5. debsig-sig.at:16: testing deb no validates, good sig, no policy dir ... stdout: stdout: 6. debsig-sig.at:23: testing deb no validates, good sig, no policy (fprid) ... Debsig Program Version - 0.32 Signature Version - 1.0 Signature Namespace - https://www.debian.org/debsig/1.0/ Policies Directory - /etc/debsig/policies Keyrings Directory - /usr/share/debsig/keyrings Usage: debsig-verify [<option>...] <deb> Options: -q, --quiet Quiet, only output fatal errors. -v, --verbose Verbose output (mainly debug). -d, --debug Debug output as well. --list-policies Only list policies that can be used to validate this sig. Only runs through 'Selection' block. --use-policy <name> Specify the short policy name to use. --policies-dir <dir> Use an alternative policies directory. --keyrings-dir <dir> Use an alternative keyrings directory. --root <dir> Use an alternative root directory for policy lookup. --help Output usage info, and exit. --version Output version info, and exit. 8. debsig-sig.at:39: testing deb validates with fprid, fprid db ... 7. debsig-sig.at:31: testing deb no validates, good sig, no policy (keyid) ... 1. debsig-cmd.at:3: 2. debsig-cmd.at:8: ok ok 9. debsig-sig.at:46: testing deb validates with keyid, fprid db ... 11. debsig-sig.at:60: testing deb validates with fprid, keyid db ... 10. debsig-sig.at:53: testing deb validates with nameid, fprid db ... 14. debsig-sig.at:87: testing deb validates with subkey, fprid, fprid db ... 13. debsig-sig.at:78: testing deb validates with nameid, keyid db ... 12. debsig-sig.at:69: testing deb validates with keyid, keyid db ... 15. debsig-sig.at:95: testing deb validates with subkey, keyid, fprid db ... dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. 17. debsig-sig.at:111: testing deb validates with subkey, nameid, fprid db ... 18. debsig-sig.at:119: testing deb validates with subkey, fprid, keyid db ... dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. 16. debsig-sig.at:103: testing deb validates with subkey, subid, fprid db ... dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. 21. debsig-sig.at:149: testing deb validates with subkey, nameid, keyid db ... 19. debsig-sig.at:129: testing deb validates with subkey, keyid, keyid db ... dpkg-deb: building package 'debraw' in 'debraw_1.0.deb'. 20. debsig-sig.at:139: testing deb validates with subkey, subid, keyid db ... dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. dpkg-deb: building package 'debsig' in 'debsig_1.0.deb'. gpg: enabled compatibility flags: gpg: keybox '/tmp/debsig-test-tmp.hu3ebSSKaF/pubring.kbx' created gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: keybox '/tmp/debsig-test-tmp.HxWFkIsGkl/pubring.kbx' created gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: keybox '/tmp/debsig-test-tmp.JidlU8Vu9S/pubring.kbx' created gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: enabled compatibility flags: gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: enabled compatibility flags: gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported gpg: key E9F3837DB59CDACD: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported gpg: key E9F3837DB59CDACD: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported gpg: key E9F3837DB59CDACD: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 ../../test/debsig-sig.at:6: $DEBSIG debraw_1.0.deb stdout: debsig: Starting verification for: debraw_1.0.deb debsig: Origin Signature check failed. This deb might not be signed. 3. debsig-sig.at:3: ok gpg: enabled compatibility flags: gpg: keybox '/tmp/debsig-test-tmp.SkqCH6IzTY/pubring.kbx' created gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: keybox '/tmp/debsig-test-tmp.jxG1sgIfGv/pubring.kbx' created gpg: enabled compatibility flags: gpg: enabled compatibility flags: gpg: enabled compatibility flags: gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: keybox '/tmp/debsig-test-tmp.9IsuDz7Bf5/pubring.kbx' created gpg: keybox '/tmp/debsig-test-tmp.beZrzSPnbt/pubring.kbx' created gpg: enabled compatibility flags: gpg: keybox '/tmp/debsig-test-tmp.biM978xn56/pubring.kbx' created gpg: enabled compatibility flags: gpg: enabled compatibility flags: gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: enabled compatibility flags: gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: keybox '/tmp/debsig-test-tmp.8A1a5n3S31/pubring.kbx' created gpg: keybox '/tmp/debsig-test-tmp.x1C4AqxMRP/pubring.kbx' created gpg: keybox '/tmp/debsig-test-tmp.3tEMXW7Hke/pubring.kbx' created gpg: keybox '/tmp/debsig-test-tmp.kj1m2lM7CZ/pubring.kbx' created gpg: keybox '/tmp/debsig-test-tmp.YXy5ib3I3b/pubring.kbx' created gpg: enabled compatibility flags: gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: keybox '/tmp/debsig-test-tmp.HVzTs8C6gK/pubring.kbx' created gpg: keybox '/tmp/debsig-test-tmp.voAOBKgspY/pubring.kbx' created gpg: keybox '/tmp/debsig-test-tmp.vkzdW1CarT/pubring.kbx' created gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: keybox '/tmp/debsig-test-tmp.E9mEzhGYAD/pubring.kbx' created gpg: keybox '/tmp/debsig-test-tmp.yp7WpEV4iW/pubring.kbx' created gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: pub rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: pub rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: key E9F3837DB59CDACD: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: Total number processed: 1 gpg: imported: 1 gpg: Total number processed: 1 gpg: imported: 1 gpg: enabled compatibility flags: gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: enabled compatibility flags: gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: Total number processed: 1 gpg: imported: 1 gpg: enabled compatibility flags: gpg: enabled compatibility flags: gpg: enabled compatibility flags: gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: enabled compatibility flags: gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: sec rsa4096/E9F3837DB59CDACD 2022-07-18 Debsig Origin Test Key <debsig-test@example.com> gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: Total number processed: 1 gpg: imported: 1 gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: Total number processed: 1 gpg: imported: 1 gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key 4832DEA0A066232B: public key "Debsig Origin Test Key <debsig-test@example.com>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: Total number processed: 1 gpg: imported: 1 gpg: Total number processed: 1 gpg: imported: 1 gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported gpg: key E9F3837DB59CDACD: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: enabled compatibility flags: gpg: key E9F3837DB59CDACD: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported gpg: key E9F3837DB59CDACD: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: Total number processed: 1 gpg: imported: 1 gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported gpg: key E9F3837DB59CDACD: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: enabled compatibility flags: gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported gpg: key E9F3837DB59CDACD: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: enabled compatibility flags: gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported gpg: key E9F3837DB59CDACD: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: enabled compatibility flags: gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: enabled compatibility flags: gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported gpg: key E9F3837DB59CDACD: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key E9F3837DB59CDACD/E9F3837DB59CDACD: secret key imported gpg: key E9F3837DB59CDACD: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: enabled compatibility flags: gpg: sec rsa4096/4832DEA0A066232B 2023-12-20 Debsig Origin Test Key <debsig-test@example.com> gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported gpg: key 4832DEA0A066232B: secret key imported gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported gpg: key 4832DEA0A066232B: "Debsig Origin Test Key <debsig-test@example.com>" not changed gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported gpg: key 4832DEA0A066232B: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported gpg: key 4832DEA0A066232B: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported gpg: key 4832DEA0A066232B: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported gpg: key 4832DEA0A066232B/4832DEA0A066232B: secret key imported gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported gpg: key 4832DEA0A066232B: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported gpg: key 4832DEA0A066232B: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported gpg: key 4832DEA0A066232B: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 gpg: key 4832DEA0A066232B/4C2E30ED5C790356: secret key imported gpg: key 4832DEA0A066232B: secret key imported gpg: Total number processed: 1 gpg: unchanged: 1 gpg: secret keys read: 1 gpg: secret keys imported: 1 ../../test/debsig-sig.at:57: $DEBSIG --use-policy nameid.pol debsig_1.0.deb ../../test/debsig-sig.at:35: mkdir -p policies/$TESTKEYID $DEBSIG --policies-dir "policies" debsig_1.0.deb ../../test/debsig-sig.at:20: $DEBSIG --policies-dir "nonexistent" debsig_1.0.deb stdout: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: getDbPathname: using policies/E9F3837DB59CDACD keyring debsig: Using policy directory: policies/E9F3837DB59CDACD debsig: No applicable policy found. stdout: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Could not find Origin directory for B2551A215CE5C74584C6AE0DE9F3837DB59CDACD 7. debsig-sig.at:31: ok 5. debsig-sig.at:16: ok stderr: gpg: Signature made Sat Mar 28 11:23:05 2026 UTC gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD stdout: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD keyring debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/nameid.pol debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/nameid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped Debsig Origin Test Key <debsig-test@example.com> -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/nameid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) 10. debsig-sig.at:53: ok ../../test/debsig-sig.at:64: mkdir -p policies/$TESTKEYID cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID $DEBSIG --policies-dir policies debsig_1.0.deb ../../test/debsig-sig.at:108: $DEBSIG --use-policy subid.pol debsig_1.0.deb ../../test/debsig-sig.at:124: mkdir -p policies/$TESTKEYID cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID $DEBSIG --policies-dir policies debsig_1.0.deb ../../test/debsig-sig.at:154: mkdir -p policies/$TESTKEYID cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID $DEBSIG --policies-dir policies --use-policy nameid.pol debsig_1.0.deb ../../test/debsig-sig.at:13: $DEBSIG debsig_1.0.deb stderr: gpg: Signature made Sat Mar 28 11:23:05 2026 UTC gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD stdout: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: getDbPathname: using policies/E9F3837DB59CDACD keyring debsig: Using policy directory: policies/E9F3837DB59CDACD debsig: Parsing policy file: policies/E9F3837DB59CDACD/keyid.pol debsig: parsePolicyFile: parsing 'policies/E9F3837DB59CDACD/keyid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: policies/E9F3837DB59CDACD/keyid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) ../../test/debsig-sig.at:144: mkdir -p policies/$TESTKEYID cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID $DEBSIG --policies-dir policies --use-policy subid.pol debsig_1.0.deb 11. debsig-sig.at:60: ok ../../test/debsig-sig.at:82: mkdir -p policies/$TESTKEYID cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID $DEBSIG --policies-dir policies --use-policy nameid.pol debsig_1.0.deb stderr: gpg: Signature made Sat Mar 28 11:23:05 2026 UTC gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD gpg: BAD signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] stdout: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD keyring debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: sigVerify: gpg exited abnormally or with non-zero exit status debsig: verifyGroupRules: failed for origin debsig: Verification group failed checks. debsig: Failed verification for debsig_1.0.deb. stderr: gpg: Signature made Sat Mar 28 11:23:06 2026 UTC gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 stdout: 4. debsig-sig.at:9: ok debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 keyring debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/subid.pol debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/subid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/subid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) 16. debsig-sig.at:103: ok stderr: gpg: Signature made Sat Mar 28 11:23:06 2026 UTC gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 stdout: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: getDbPathname: using policies/4C2E30ED5C790356 keyring debsig: Using policy directory: policies/4C2E30ED5C790356 debsig: Parsing policy file: policies/4C2E30ED5C790356/subid.pol debsig: parsePolicyFile: parsing 'policies/4C2E30ED5C790356/subid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: policies/4C2E30ED5C790356/subid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) stderr: gpg: Signature made Sat Mar 28 11:23:06 2026 UTC gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 stdout: 18. debsig-sig.at:119: ok debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: getDbPathname: using policies/4C2E30ED5C790356 keyring debsig: Using policy directory: policies/4C2E30ED5C790356 debsig: Parsing policy file: policies/4C2E30ED5C790356/nameid.pol debsig: parsePolicyFile: parsing 'policies/4C2E30ED5C790356/nameid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped Debsig Origin Test Key <debsig-test@example.com> -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: policies/4C2E30ED5C790356/nameid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) ../../test/debsig-sig.at:50: $DEBSIG --use-policy keyid.pol debsig_1.0.deb 21. debsig-sig.at:149: ok ../../test/debsig-sig.at:27: mkdir -p policies/$TESTFPRID $DEBSIG --policies-dir "policies" debsig_1.0.deb stderr: ../../test/debsig-sig.at:43: $DEBSIG debsig_1.0.deb ../../test/debsig-sig.at:73: mkdir -p policies/$TESTKEYID cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID $DEBSIG --policies-dir policies --use-policy keyid.pol debsig_1.0.deb gpg: Signature made Sat Mar 28 11:23:05 2026 UTC gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD stdout: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: getDbPathname: using policies/E9F3837DB59CDACD keyring debsig: Using policy directory: policies/E9F3837DB59CDACD debsig: Parsing policy file: policies/E9F3837DB59CDACD/nameid.pol debsig: parsePolicyFile: parsing 'policies/E9F3837DB59CDACD/nameid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped Debsig Origin Test Key <debsig-test@example.com> -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: policies/E9F3837DB59CDACD/nameid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped B2551A215CE5C74584C6AE0DE9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) 13. debsig-sig.at:78: ok stdout: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: getDbPathname: using policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD keyring debsig: Using policy directory: policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: No applicable policy found. 6. debsig-sig.at:23: ok ../../test/debsig-sig.at:134: mkdir -p policies/$TESTKEYID cp -a $TESTPOLICIES/$TESTFPRID/* policies/$TESTKEYID $DEBSIG --policies-dir policies --use-policy keyid.pol debsig_1.0.deb ../../test/debsig-sig.at:116: $DEBSIG --use-policy nameid.pol debsig_1.0.deb ../../test/debsig-sig.at:92: $DEBSIG debsig_1.0.deb stderr: gpg: Signature made Sat Mar 28 11:23:06 2026 UTC gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 stdout: ../../test/debsig-sig.at:100: $DEBSIG --use-policy keyid.pol debsig_1.0.deb debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: getDbPathname: using policies/4C2E30ED5C790356 keyring debsig: Using policy directory: policies/4C2E30ED5C790356 debsig: Parsing policy file: policies/4C2E30ED5C790356/subid.pol debsig: parsePolicyFile: parsing 'policies/4C2E30ED5C790356/subid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: policies/4C2E30ED5C790356/subid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) stderr: gpg: Signature made Sat Mar 28 11:23:05 2026 UTC gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD stdout: 20. debsig-sig.at:139: ok debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD keyring debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) 9. debsig-sig.at:46: ok stderr: gpg: Signature made Sat Mar 28 11:23:05 2026 UTC gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD stdout: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD keyring debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/keyid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) 8. debsig-sig.at:39: stderr: ok gpg: Signature made Sat Mar 28 11:23:05 2026 UTC gpg: using RSA key B2551A215CE5C74584C6AE0DE9F3837DB59CDACD gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: B255 1A21 5CE5 C745 84C6 AE0D E9F3 837D B59C DACD stdout: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: getDbPathname: using policies/E9F3837DB59CDACD keyring debsig: Using policy directory: policies/E9F3837DB59CDACD debsig: Parsing policy file: policies/E9F3837DB59CDACD/keyid.pol debsig: parsePolicyFile: parsing 'policies/E9F3837DB59CDACD/keyid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: policies/E9F3837DB59CDACD/keyid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/B2551A215CE5C74584C6AE0DE9F3837DB59CDACD/pubring.pgp keyring debsig: getKeyID: mapped E9F3837DB59CDACD -> B2551A215CE5C74584C6AE0DE9F3837DB59CDACD debsig: getSigKeyID: got B2551A215CE5C74584C6AE0DE9F3837DB59CDACD for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) 12. debsig-sig.at:69: ok stderr: gpg: Signature made Sat Mar 28 11:23:06 2026 UTC gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 stdout: stderr: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 keyring debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/nameid.pol debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/nameid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped Debsig Origin Test Key <debsig-test@example.com> -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/nameid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) gpg: Signature made Sat Mar 28 11:23:06 2026 UTC gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 stdout: 17. debsig-sig.at:111: ok debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: getDbPathname: using policies/4C2E30ED5C790356 keyring debsig: Using policy directory: policies/4C2E30ED5C790356 debsig: Parsing policy file: policies/4C2E30ED5C790356/keyid.pol debsig: parsePolicyFile: parsing 'policies/4C2E30ED5C790356/keyid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: policies/4C2E30ED5C790356/keyid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) 19. debsig-sig.at:129: ok stderr: gpg: Signature made Sat Mar 28 11:23:06 2026 UTC gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 stderr: stdout: gpg: Signature made Sat Mar 28 11:23:06 2026 UTC gpg: using RSA key 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 gpg: Good signature from "Debsig Origin Test Key <debsig-test@example.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 900A C211 3233 F5DF 47C0 B665 4832 DEA0 A066 232B Subkey fingerprint: 0DB5 9D1F 9C5B 1C3A 4504 175B 4C2E 30ED 5C79 0356 debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 keyring debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/subid.pol debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/subid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/subid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) stdout: 14. debsig-sig.at:87: debsig: Starting verification for: debsig_1.0.deb debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 keyring debsig: Using policy directory: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: Parsing policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/keyid.pol debsig: parsePolicyFile: parsing '/build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/keyid.pol' debsig: parsePolicyFile: completed debsig: Checking Selection group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Selection group(s) passed, policy is usable. debsig: Using policy file: /build/reproducible-path/debsig-verify-0.32/build-tree/../test/policies/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/keyid.pol debsig: Checking Verification group(s). debsig: Processing 'origin' key... debsig: getDbPathname: using /build/reproducible-path/debsig-verify-0.32/build-tree/../test/keyrings/0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356/pubring.pgp keyring debsig: getKeyID: mapped 4C2E30ED5C790356 -> 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 debsig: getSigKeyID: got 0DB59D1F9C5B1C3A4504175B4C2E30ED5C790356 for origin key debsig: Verification group(s) passed, deb is validated. debsig: Verified package from 'Debsig testing' (Debsig) ok 15. debsig-sig.at:95: ok ## ------------- ## ## Test results. ## ## ------------- ## All 21 tests were successful. make[3]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree/test' make[2]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree/test' make[1]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree' create-stamp debian/debhelper-build-stamp dh_testroot -O--builddir=build-tree dh_prep -O--builddir=build-tree dh_auto_install --destdir=debian/debsig-verify/ -O--builddir=build-tree cd build-tree && make -j22 install DESTDIR=/build/reproducible-path/debsig-verify-0.32/debian/debsig-verify AM_UPDATE_INFO_DIR=no make[1]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree' Making install in . make[2]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree' make[3]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree' /usr/bin/mkdir -p /build/reproducible-path/debsig-verify-0.32/debian/debsig-verify/etc/debsig/policies /usr/bin/mkdir -p '/build/reproducible-path/debsig-verify-0.32/debian/debsig-verify/usr/bin' /usr/bin/mkdir -p /build/reproducible-path/debsig-verify-0.32/debian/debsig-verify/usr/share/debsig/keyrings /usr/bin/mkdir -p '/build/reproducible-path/debsig-verify-0.32/debian/debsig-verify/usr/share/man/man1' /usr/bin/install -c src/debsig-verify '/build/reproducible-path/debsig-verify-0.32/debian/debsig-verify/usr/bin' /usr/bin/install -c -m 644 doc/debsig-verify.1 '/build/reproducible-path/debsig-verify-0.32/debian/debsig-verify/usr/share/man/man1' make[3]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree' make[2]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree' Making install in test make[2]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree/test' make[3]: Entering directory '/build/reproducible-path/debsig-verify-0.32/build-tree/test' make[3]: Nothing to be done for 'install-exec-am'. make[3]: Nothing to be done for 'install-data-am'. make[3]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree/test' make[2]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree/test' make[1]: Leaving directory '/build/reproducible-path/debsig-verify-0.32/build-tree' dh_installdocs -O--builddir=build-tree debian/rules override_dh_installchangelogs make[1]: Entering directory '/build/reproducible-path/debsig-verify-0.32' dh_installchangelogs --no-trim make[1]: Leaving directory '/build/reproducible-path/debsig-verify-0.32' dh_installexamples -O--builddir=build-tree dh_installman -O--builddir=build-tree dh_installsystemduser -O--builddir=build-tree dh_lintian -O--builddir=build-tree dh_perl -O--builddir=build-tree dh_link -O--builddir=build-tree dh_strip_nondeterminism -O--builddir=build-tree dh_compress -O--builddir=build-tree dh_fixperms -O--builddir=build-tree dh_missing -O--builddir=build-tree dh_dwz -a -O--builddir=build-tree dh_strip -a -O--builddir=build-tree dh_makeshlibs -a -O--builddir=build-tree dh_shlibdeps -a -O--builddir=build-tree dh_installdeb -O--builddir=build-tree debian/rules override_dh_gencontrol make[1]: Entering directory '/build/reproducible-path/debsig-verify-0.32' dh_gencontrol -- -Vsourcedep:libdpkg-dev='dpkg (= 1.22.15)' make[1]: Leaving directory '/build/reproducible-path/debsig-verify-0.32' dh_md5sums -O--builddir=build-tree dh_builddeb -O--builddir=build-tree dpkg-deb: building package 'debsig-verify' in '../debsig-verify_0.32_i386.deb'. dpkg-deb: building package 'debsig-verify-dbgsym' in '../debsig-verify-dbgsym_0.32_i386.deb'. dpkg-genbuildinfo --build=binary -O../debsig-verify_0.32_i386.buildinfo dpkg-genchanges --build=binary -O../debsig-verify_0.32_i386.changes dpkg-genchanges: info: binary-only upload (no source code included) dpkg-source --after-build . dpkg-buildpackage: info: binary-only upload (no source included) dpkg-genchanges: info: including full source code in upload I: copying local configuration I: unmounting dev/ptmx filesystem I: unmounting dev/pts filesystem I: unmounting dev/shm filesystem I: unmounting proc filesystem I: unmounting sys filesystem I: cleaning the build env I: removing directory /srv/workspace/pbuilder/70588 and its subdirectories I: Current time: Fri Mar 27 23:23:09 -12 2026 I: pbuilder-time-stamp: 1774696989 Sun Feb 23 05:00:11 UTC 2025 I: 1st build successful. Starting 2nd build on remote node ionos2-i386.debian.net. Sun Feb 23 05:00:11 UTC 2025 I: Preparing to do remote build '2' on ionos2-i386.debian.net. Sun Feb 23 05:01:55 UTC 2025 I: Deleting $TMPDIR on ionos2-i386.debian.net. Sun Feb 23 05:01:56 UTC 2025 I: debsig-verify_0.32_i386.changes: Format: 1.8 Date: Sat, 22 Feb 2025 14:24:41 +0100 Source: debsig-verify Binary: debsig-verify debsig-verify-dbgsym Architecture: i386 Version: 0.32 Distribution: unstable Urgency: medium Maintainer: Dpkg Developers <debian-dpkg@lists.debian.org> Changed-By: Guillem Jover <guillem@debian.org> Description: debsig-verify - Debian package signature verification tool Changes: debsig-verify (0.32) unstable; urgency=medium . * Fix OpenPGP implementation array traversal. * Documentation: - Update TODO. * Packaging: - Switch to Standards-Version 4.7.1 (no changes needed). - Add <!nocheck> Build-Depends on gpg | gpg-from-sq to run debsig-verify. * Test suite: - Pass --root-owner-group to dpkg-deb. Checksums-Sha1: 89967f2b19b216920274419aad1c926d1298e7e6 31988 debsig-verify-dbgsym_0.32_i386.deb b58b492edd15964ddef8d7d6005ec4d11292b0cd 5465 debsig-verify_0.32_i386.buildinfo 99b1d44259898a85b2af76c272f2267c26eaae3f 42892 debsig-verify_0.32_i386.deb Checksums-Sha256: 12b16a1fd36cb3e1087f315da54b2df5d185e1259a7898f80df6e7bf944b1a94 31988 debsig-verify-dbgsym_0.32_i386.deb 7857b8916ad56b84388f5443ba29afcdc6468febde3c1feb28b750f11be82972 5465 debsig-verify_0.32_i386.buildinfo 3b72d14d6acf818c6f202d10ea480e810d2b6a78513d7234210bef8d68b6d7c7 42892 debsig-verify_0.32_i386.deb Files: 0b3e3648805fad4a5cc9f1aff607b314 31988 debug optional debsig-verify-dbgsym_0.32_i386.deb a7518fab2773f8c56598d2ba2794707e 5465 admin optional debsig-verify_0.32_i386.buildinfo e2e9af737187a8f330e556fcf90af54b 42892 admin optional debsig-verify_0.32_i386.deb Sun Feb 23 05:01:57 UTC 2025 I: diffoscope 288 will be used to compare the two builds: Running as unit: rb-diffoscope-i386_10-44892.service # Profiling output for: /usr/bin/diffoscope --timeout 7200 --html /srv/reproducible-results/rbuild-debian/r-b-build.UjJP7fXV/debsig-verify_0.32.diffoscope.html --text /srv/reproducible-results/rbuild-debian/r-b-build.UjJP7fXV/debsig-verify_0.32.diffoscope.txt --json /srv/reproducible-results/rbuild-debian/r-b-build.UjJP7fXV/debsig-verify_0.32.diffoscope.json --profile=- /srv/reproducible-results/rbuild-debian/r-b-build.UjJP7fXV/b1/debsig-verify_0.32_i386.changes /srv/reproducible-results/rbuild-debian/r-b-build.UjJP7fXV/b2/debsig-verify_0.32_i386.changes ## command (total time: 0.000s) 0.000s 1 call cmp (internal) ## has_same_content_as (total time: 0.000s) 0.000s 1 call diffoscope.comparators.binary.FilesystemFile ## main (total time: 0.004s) 0.004s 2 calls outputs 0.000s 1 call cleanup Finished with result: success Main processes terminated with: code=exited/status=0 Service runtime: 243ms CPU time consumed: 245ms Sun Feb 23 05:02:02 UTC 2025 I: diffoscope 288 found no differences in the changes files, and a .buildinfo file also exists. Sun Feb 23 05:02:02 UTC 2025 I: debsig-verify from unstable built successfully and reproducibly on i386. Sun Feb 23 05:02:03 UTC 2025 I: Submitting .buildinfo files to external archives: Sun Feb 23 05:02:03 UTC 2025 I: Submitting 8.0K b1/debsig-verify_0.32_i386.buildinfo.asc Sun Feb 23 05:02:04 UTC 2025 I: Submitting 8.0K b2/debsig-verify_0.32_i386.buildinfo.asc Sun Feb 23 05:02:05 UTC 2025 I: Done submitting .buildinfo files to http://buildinfo.debian.net/api/submit. Sun Feb 23 05:02:05 UTC 2025 I: Done submitting .buildinfo files. Sun Feb 23 05:02:05 UTC 2025 I: Removing signed debsig-verify_0.32_i386.buildinfo.asc files: removed './b1/debsig-verify_0.32_i386.buildinfo.asc' removed './b2/debsig-verify_0.32_i386.buildinfo.asc'