Please support InRelease files

Bug #804252 reported by Michael Vogt
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
Low
Colin Watson
ubuntu-archive-publishing
Fix Released
Low
Colin Watson

Bug Description

This is a splitout of bug #716535 into two features.

Debian has a new features for Release files that we should support as well:

InRelease
 That is just the release file with a inline signature (e.g. http://security.debian.org/debian-security/dists/lenny/updates/InRelease)
 One nice property is that Release and Release.gpg can no longer get out-of-sync

Related bugs:
 * bug 804252: Please support InRelease files
 * bug 1430011: support apt by-hash mirrors
 * bug 972077: apt repository disk format has race conditions

Tags: qa-ok

Related branches

Changed in launchpad:
status: New → Triaged
importance: Undecided → Low
Colin Watson (cjwatson)
Changed in launchpad:
assignee: nobody → Colin Watson (cjwatson)
Revision history for this message
Colin Watson (cjwatson) wrote :

E-mail consensus appears to be:

 * It is quite possibly not safe to deploy anything that generates inline signatures with the primary archive key until we no longer support Ubuntu 11.04, which was vulnerable to bug 784473 at release time (since attacks using the clearsigned material would be possible against users who have performed a fresh install and are in the process of upgrading).
 * We should audit to make sure there are no other similar vulnerabilities in Ubuntu 11.10.

Thus, although I've written the code, we'll need to defer deploying this for the time being.

Revision history for this message
Colin Watson (cjwatson) wrote :

The part of this that applies to the primary archive needs to be fixed in ubuntu-archive-publishing rather than Launchpad, now that we've split those scripts out. The PPA side of things should still be fixed in Launchpad.

Changed in ubuntu-archive-publishing:
status: New → Triaged
importance: Undecided → Low
Scott Moser (smoser)
description: updated
Colin Watson (cjwatson)
Changed in ubuntu-archive-publishing:
assignee: nobody → Colin Watson (cjwatson)
Changed in launchpad:
status: Triaged → In Progress
Changed in ubuntu-archive-publishing:
status: Triaged → In Progress
Revision history for this message
Launchpad QA Bot (lpqabot) wrote :
tags: added: qa-needstesting
Changed in launchpad:
status: In Progress → Fix Committed
Colin Watson (cjwatson)
tags: added: qa-ok
removed: qa-needstesting
William Grant (wgrant)
Changed in launchpad:
status: Fix Committed → Fix Released
Colin Watson (cjwatson)
Changed in ubuntu-archive-publishing:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.