Skip to content

[2.27] Require a newer version of pysequoia to fix signature validation#2339

Merged
dralley merged 1 commit into
pulp:2.27from
dralley:2.27
Apr 24, 2026
Merged

[2.27] Require a newer version of pysequoia to fix signature validation#2339
dralley merged 1 commit into
pulp:2.27from
dralley:2.27

Conversation

@dralley
Copy link
Copy Markdown
Contributor

@dralley dralley commented Apr 24, 2026

skopeo standalone-verify creates slightly atypical (but legal) PGP signatures which pysequoia <= 0.1.32 was rejecting (via gpg_verify() from pulpcore).

We need to declare compatibility with the new version

(cherry picked from commit 4b00944)

📜 Checklist

  • Commits are cleanly separated with meaningful messages (simple features and bug fixes should be squashed to one commit)
  • A changelog entry or entries has been added for any significant changes
  • Follows the Pulp policy on AI Usage
  • (For new features) - User documentation and test coverage has been added

See: Pull Request Walkthrough

skopeo standalone-verify creates slightly atypical (but legal) PGP
signatures which pysequoia <= 0.1.32 was rejecting (via gpg_verify()
from pulpcore).

We need to declare compatibility with the new version

(cherry picked from commit 4b00944)
@dralley dralley changed the title Require a newer version of pysequoia to fix signature validation [2.27] Require a newer version of pysequoia to fix signature validation Apr 24, 2026
@dralley dralley merged commit 7dea180 into pulp:2.27 Apr 24, 2026
14 checks passed
@patchback
Copy link
Copy Markdown

patchback Bot commented Apr 24, 2026

Backport to 2.26: 💚 backport PR created

✅ Backport PR branch: patchback/backports/2.26/7dea1807c48f1df5f965664a140c4b63f459e2ef/pr-2339

Backported as #2341

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

@patchback
Copy link
Copy Markdown

patchback Bot commented Apr 24, 2026

Backport to 2.24: 💔 cherry-picking failed — conflicts found

❌ Failed to cleanly apply 7dea180 on top of patchback/backports/2.24/7dea1807c48f1df5f965664a140c4b63f459e2ef/pr-2339

Backporting merged PR #2339 into 2.27

  1. Ensure you have a local repo clone of your fork. Unless you cloned it
    from the upstream, this would be your origin remote.
  2. Make sure you have an upstream repo added as a remote too. In these
    instructions you'll refer to it by the name upstream. If you don't
    have it, here's how you can add it:
    $ git remote add upstream https://github.com/pulp/pulp_container.git
  3. Ensure you have the latest copy of upstream and prepare a branch
    that will hold the backported code:
    $ git fetch upstream
    $ git checkout -b patchback/backports/2.24/7dea1807c48f1df5f965664a140c4b63f459e2ef/pr-2339 upstream/2.24
  4. Now, cherry-pick PR [2.27] Require a newer version of pysequoia to fix signature validation #2339 contents into that branch:
    $ git cherry-pick -x 7dea1807c48f1df5f965664a140c4b63f459e2ef
    If it'll yell at you with something like fatal: Commit 7dea1807c48f1df5f965664a140c4b63f459e2ef is a merge but no -m option was given., add -m 1 as follows instead:
    $ git cherry-pick -m1 -x 7dea1807c48f1df5f965664a140c4b63f459e2ef
  5. At this point, you'll probably encounter some merge conflicts. You must
    resolve them in to preserve the patch from PR [2.27] Require a newer version of pysequoia to fix signature validation #2339 as close to the
    original as possible.
  6. Push this branch to your fork on GitHub:
    $ git push origin patchback/backports/2.24/7dea1807c48f1df5f965664a140c4b63f459e2ef/pr-2339
  7. Create a PR, ensure that the CI is green. If it's not — update it so that
    the tests and any other checks pass. This is it!
    Now relax and wait for the maintainers to process your pull request
    when they have some cycles to do reviews. Don't worry — they'll tell you if
    any improvements are necessary when the time comes!

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant