From mboxrd@z Thu Jan 1 00:00:00 1970 X-GM-THRID: 6683827867816558592 X-Received: by 2002:a5d:6710:: with SMTP id o16mr18956327wru.173.1557833708818; Tue, 14 May 2019 04:35:08 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com Received: by 2002:a1c:c586:: with SMTP id v128ls795985wmf.1.gmail; Tue, 14 May 2019 04:35:08 -0700 (PDT) X-Google-Smtp-Source: APXvYqzoMtco1z2QnZCTKS6IvvZTBKDbp2+wh9MPWSjMkvr+FlgIOUs5u94g+WJCcpe85XAwbQTu X-Received: by 2002:a1c:3104:: with SMTP id x4mr14573811wmx.23.1557833708380; Tue, 14 May 2019 04:35:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1557833708; cv=none; d=google.com; s=arc-20160816; b=BKTKnBnn2dNBUmzpx84Bf90ZQxY6ooYdP9y0UjjaO3OuRBF9V0jbAZeCntJao+c6jz VpwLuk2MvoeeE7HS6GObeO9NiP9yCINTnUSTvzWS6LV3AL6f4ME9DW3GZ9+DsIIn9Ql6 l8CSlcheZtPLojGyKGIhB2nl57LPE3g2A1fk6FsVkdXiZnW2LfVbjNYTdNHrDUCeqPwq HjG4LSV1RJyyiyQU4dDvreCXDW/3inielgDtA338g+Lj54aXz6k0p2QTjksYer/lEfOu Dw3kncodHdtFAcvpRQdZZnXenFUWWbEgp4EJ2mE2VOSs0Vjtp4jpNgu+KyK9Gr5fG98o 9XEg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:content-language:in-reply-to:mime-version :user-agent:date:message-id:references:to:from:subject; bh=nDgWjlOPUOFKilAeyvGfT8qZ+xPgVhsrUftHsBTFHd8=; b=mRP1tEmblfNdna0zptq+zIwaV2KbT10qysKJtouEnNuH4ZcOv6Tm60t15zLphh1L7G o/PandxmTSwfALZzH2wkCARBqzohvRUE1w182Uv2vCyUDTZttu/IoGWutcsLRKqyUxyR Fqna+OBDv5qpOEKC2CKfjlXCyWC0ZfYMjguTk0e1CdEjngJkfUddnsA9vQX/eLKIdxcu mm51qMSC6GfOhHMr7qMJNfDfhOuD0AwsLs4hMMb9LuCotixw4yp6Ke1fcU+wv5lSRQiE J+jAXxv/s8KEGvPh1v9avIo9ONa0Mqgm/MFK8qn0qI1cJ/422IVGWz+VFgh1LoJneOix j6Ww== ARC-Authentication-Results: i=1; gmr-mx.google.com; spf=pass (google.com: domain of claudius.heine.ext@siemens.com designates 192.35.17.28 as permitted sender) smtp.mailfrom=claudius.heine.ext@siemens.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=siemens.com Return-Path: Received: from goliath.siemens.de (goliath.siemens.de. [192.35.17.28]) by gmr-mx.google.com with ESMTPS id m8si1013747wmc.3.2019.05.14.04.35.08 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 14 May 2019 04:35:08 -0700 (PDT) Received-SPF: pass (google.com: domain of claudius.heine.ext@siemens.com designates 192.35.17.28 as permitted sender) client-ip=192.35.17.28; Authentication-Results: gmr-mx.google.com; spf=pass (google.com: domain of claudius.heine.ext@siemens.com designates 192.35.17.28 as permitted sender) smtp.mailfrom=claudius.heine.ext@siemens.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=siemens.com Received: from mail2.sbs.de (mail2.sbs.de [192.129.41.66]) by goliath.siemens.de (8.15.2/8.15.2) with ESMTPS id x4EBZ7DC019968 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Tue, 14 May 2019 13:35:07 +0200 Received: from [139.25.69.232] (linux-ses-ext02.ppmd.siemens.net [139.25.69.232]) by mail2.sbs.de (8.15.2/8.15.2) with ESMTP id x4EBZ7n5024132; Tue, 14 May 2019 13:35:07 +0200 Subject: Re: [PATCH v4 1/9] isar-bootstrap-host: disable DISTRO_APT_KEYS usage From: Claudius Heine To: Jan Kiszka , Claudius Heine , "Maxim Yu. Osipov" , isar-users@googlegroups.com References: <20190425134450.13443-1-claudius.heine.ext@siemens.com> <20190425134450.13443-2-claudius.heine.ext@siemens.com> <155626421155.10914.2537647574220599237@ardipi> <2a7d8373-b2a7-5530-98bc-c0c0e6986ed8@siemens.com> Message-ID: <53f9a49a-2870-db37-720d-8a6f5bc2ac58@siemens.com> Date: Tue, 14 May 2019 13:35:07 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.6.1 MIME-Version: 1.0 In-Reply-To: <2a7d8373-b2a7-5530-98bc-c0c0e6986ed8@siemens.com> Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 7bit X-TUID: 35+AM7tRTMZ5 small errata: On 14/05/2019 13.32, Claudius Heine wrote: >> >> OTOH, I don't get the problem yet from just reading the commit >> message: Wasn't DISTRO_APT_KEYS designed to be a superset of all >> needed keys? > > DISTRO_APT_KEYS is only used for distros that aren't Debian, because > debootstrap uses the keys of the host distro (Debian) per default. DISTRO_APT_KEYS was renamed by Andreas new patchset and is now called DISTRO_BOOTSTRAP_KEYS. > THIRD_PARTY_APT_KEYS is for the keys of other third party repositories > that are not used to bootstrap from. > > We currently only support raspbian as a non-debian distribution and > before this patchset only 'debian-stretch' as buildchroot-host. > After this patchset we support all Debian versions we currently support > for the target for the buildchroot-host as well. Since raspbian does not > supply packages that can be used for a buildchroot-host environment, it > makes sense to just use the Debian host keys for bootstrapping the > buildchroot-host rootfs in general. > > If at one point we want to support other non-debian apt/dpkg based > distributions like ubuntu, that can be used for the target as well as > the host root file system, then it makes sense to allow specifying > additional keys for the buildchroot-host as well. Until that time > however this fix is enough to go forward. > > regards, > Claudius > >> We are appending raspbian to it when using that distro. So, we are at >> least missing the reasoning here why that model didn't work and cannot >> be made working for the host/target case. And then we can refer to >> that when introducing split key sets. >> >> Thanks, >> Jan >> >> > -- DENX Software Engineering GmbH, Managing Director: Wolfgang Denk HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany Phone: (+49)-8142-66989-54 Fax: (+49)-8142-66989-80 Email: ch@denx.de