[Dev] [News] Hyperbola users are now mitigated against Microarchitectural Data Sampling (MDS) vulnerabilities

Nelson H. F. Beebe beebe at math.utah.edu
Fri May 17 18:38:19 EEST 2019


Following today's announcement of patches for the Microarchitectural
Data Sampling (MDS) vulnerabilities, I ran updates on my two Hyperbola
VMs.  One updated without problems, but the other one consistently
gets signing key errors for one particular key.  I tried key refreshing,
without effect.

I then tried the drastic solution of destroy the key directory and
recreate it with

	rm -rf /etc/pacman.d/gnupg
	pacman-key --init
	pacman-key --populate archlinux
	pacman-key --populate parabola
	pacman-key --populate hyperbola
	pacman-key --refresh-keys

I still get the same error, which looks like this:

	# pacman -Sy hyperbola-keyring
	:: Synchronizing package databases...
	 core is up to date
	 extra is up to date
	 community is up to date
	resolving dependencies...
	looking for conflicting packages...

	Packages (1) hyperbola-keyring-20190203-0

	Total Download Size:    0.14 MiB
	Total Installed Size:   0.21 MiB
	Net Upgrade Size:      -0.07 MiB

	:: Proceed with installation? [Y/n] y
	:: Retrieving packages...
	 hyperbola-keyring-20190203-0-any ...
	(1/1) checking keys in keyring       ...
	downloading required keys...
	:: Import PGP key 1024D/328E93B83AF8ED58EA6556171583217AE1AC7510, "Fomm Oberon <Urano>", created: 1999-02-27? [Y/n] y
	(1/1) checking package integrity        
	error: hyperbola-keyring: key "5AA99D86E1AC7510" is unknown
	:: Import PGP key 1024D/328E93B83AF8ED58EA6556171583217AE1AC7510, "Fomm Oberon <Urano>", created: 1999-02-27? [Y/n] y
	:: File /var/cache/pacman/pkg/hyperbola-keyring-20190203-0-any.pkg.tar.xz is corrupted (invalid or corrupted package (PGP signature)).
	Do you want to delete it? [Y/n] n
	error: failed to commit transaction (invalid or corrupted package (PGP signature))

If I invert any of the response (yes <--> no), pacman terminates
anyway.

Does any list member have an idea how to repair this blockage? I have
more than 100 packages in need of updates.

-------------------------------------------------------------------------------
- Nelson H. F. Beebe                    Tel: +1 801 581 5254                  -
- University of Utah                    FAX: +1 801 581 4148                  -
- Department of Mathematics, 110 LCB    Internet e-mail: beebe at math.utah.edu  -
- 155 S 1400 E RM 233                       beebe at acm.org  beebe at computer.org -
- Salt Lake City, UT 84112-0090, USA    URL: http://www.math.utah.edu/~beebe/ -
-------------------------------------------------------------------------------



More information about the Dev mailing list