public inbox for isar-users@googlegroups.com
 help / color / mirror / Atom feed
From: "'MOESSBAUER, Felix' via isar-users" <isar-users@googlegroups.com>
To: "isar-users@googlegroups.com" <isar-users@googlegroups.com>
Subject: Build failure of mc:rpi-arm-v7-bullseye:isar-image-base on trixie hosts
Date: Thu, 5 Mar 2026 08:30:51 +0000	[thread overview]
Message-ID: <a103328be2ce982535c374048f87925bc5507b8a.camel@siemens.com> (raw)

Hi,

the mc:rpi-arm-v7-bullseye:isar-image-base target currently cannot be
build because it uses an SHA1 hashed key. This only affects trixie
hosts, as bookworm does not have this check.

This also breaks the CI test: citest.py:CrossTest.test_cross_rpi

Best regards,
Felix

---snip---

ERROR: Logfile of failure stored in: /work/build/tmp/work/raspios-
bullseye-armhf/isar-mmdebstrap-target/1.0-r0/temp/log.do_bootstrap.2507
Log data follows:
| DEBUG: Executing python function sstate_task_prefunc
| DEBUG: Python function sstate_task_prefunc finished
| DEBUG: Executing shell function do_bootstrap
| '/work/build/tmp/work/raspios-bullseye-armhf/isar-mmdebstrap-
target/1.0-r0/apt-sources' -> '/work/build/tmp/work/raspios-bullseye-
armhf/isar-mmdebstrap-target/1.0-r0/sources.list.d/bootstrap.list'
| I: armhf cannot be executed natively, but transparently using qemu-
user binfmt emulation
| I: finding correct signed-by value...
| I: automatically chosen format: tar
| I: using /work/build/tmp/work/raspios-bullseye-armhf/isar-mmdebstrap-
target/1.0-r0/tempdir/mmdebstrap.N4elBIlcRU as tempdir
| W: Download is performed unsandboxed as root as file
/work/build/tmp/work/raspios-bullseye-armhf/isar-mmdebstrap-target/1.0-
r0/tempdir/mmdebstrap.N4elBIlcRU/var/lib/apt/lists/partial couldn't be
accessed by user _apt
| I: running --setup-hook in shell: sh -c 'mkdir -p
"$1/var/cache/apt/archives/"' exec /work/build/tmp/work/raspios-
bullseye-armhf/isar-mmdebstrap-target/1.0-
r0/tempdir/mmdebstrap.N4elBIlcRU
| I: running --setup-hook in shell: sh -c 'flock -s
/work/build/downloads/deb/raspios-bullseye.lock cp -n --no-
preserve=owner \
|                       "/work/build/tmp/work/raspios-bullseye-
armhf/isar-mmdebstrap-target/1.0-
r0/dl_dir/var/cache/apt/archives/"*.deb \
|                       "$1/var/cache/apt/archives/" || true' exec
/work/build/tmp/work/raspios-bullseye-armhf/isar-mmdebstrap-target/1.0-
r0/tempdir/mmdebstrap.N4elBIlcRU
| cp: cannot stat '/work/build/tmp/work/raspios-bullseye-armhf/isar-
mmdebstrap-target/1.0-r0/dl_dir/var/cache/apt/archives/*.deb': No such
file or directory
| I: running special hook: upload "/work/build/tmp/work/raspios-
bullseye-armhf/isar-mmdebstrap-target/1.0-r0/apt-preferences"
/etc/apt/preferences.d/bootstrap
| I: running special hook: upload "/work/build/tmp/work/raspios-
bullseye-armhf/isar-mmdebstrap-target/1.0-r0/apt-sources-init"
/etc/apt/sources-list
| I: running special hook: upload "/work/build/tmp/work/raspios-
bullseye-armhf/isar-mmdebstrap-target/1.0-r0/locale" /etc/locale
| I: running --setup-hook in shell: sh -c 'mkdir -p
"$1/etc/apt/trusted.gpg.d"' exec /work/build/tmp/work/raspios-bullseye-
armhf/isar-mmdebstrap-target/1.0-r0/tempdir/mmdebstrap.N4elBIlcRU
| I: running special hook: sync-in "/work/build/tmp/work/raspios-
bullseye-armhf/isar-mmdebstrap-target/1.0-r0/trusted.gpg.d"
/etc/apt/trusted.gpg.d
| I: running --setup-hook in shell: sh -c 'install -v -m755
"/work/build/tmp/work/raspios-bullseye-armhf/isar-mmdebstrap-
target/1.0-r0/chroot-setup.sh" "$1/chroot-setup.sh"' exec
/work/build/tmp/work/raspios-bullseye-armhf/isar-mmdebstrap-target/1.0-
r0/tempdir/mmdebstrap.N4elBIlcRU
| '/work/build/tmp/work/raspios-bullseye-armhf/isar-mmdebstrap-
target/1.0-r0/chroot-setup.sh' -> '/work/build/tmp/work/raspios-
bullseye-armhf/isar-mmdebstrap-target/1.0-
r0/tempdir/mmdebstrap.N4elBIlcRU/chroot-setup.sh'
| I: running apt-get update...
| Get:1 http://raspbian.raspberrypi.org/raspbian bullseye InRelease
[15.0 kB]
| Get:2 http://archive.raspberrypi.org/debian bullseye InRelease [39.0
kB]
| Err:2 http://archive.raspberrypi.org/debian bullseye InRelease
|   Sub-process /usr/bin/sqv returned an error code (1), error message
is: Signing key on CF8A1AF502A2AA2D763BAE7E82B129927FA3303E is not
bound:            No binding signature at time 2026-03-04T20:31:49Z  
because: Policy rejected non-revocation signature
(PositiveCertification) requiring second pre-image resistance  
because: SHA1 is not considered secure since 2026-02-01T00:00:00Z
| Err:1 http://raspbian.raspberrypi.org/raspbian bullseye InRelease
|   Sub-process /usr/bin/sqv returned an error code (1), error message
is: Signing key on A0DA38D0D76E8B5D638872819165938D90FDDD2E is not
bound:            No binding signature at time 2026-03-05T04:17:28Z  
because: Policy rejected non-revocation signature
(PositiveCertification) requiring second pre-image resistance  
because: SHA1 is not considered secure since 2026-02-01T00:00:00Z
| Reading package lists...
| W: http://archive.raspberrypi.org/debian/dists/bullseye/InRelease:
Loading /work/build/tmp/work/raspios-bullseye-armhf/isar-mmdebstrap-
target/1.0-r0/distro-keyring.gpg from deprecated option
Dir::Etc::Trusted
| W: OpenPGP signature verification failed:
http://archive.raspberrypi.org/debian bullseye InRelease: Sub-process
/usr/bin/sqv returned an error code (1), error message is: Signing key
on CF8A1AF502A2AA2D763BAE7E82B129927FA3303E is not bound:            No
binding signature at time 2026-03-04T20:31:49Z   because: Policy
rejected non-revocation signature (PositiveCertification) requiring
second pre-image resistance   because: SHA1 is not considered secure
since 2026-02-01T00:00:00Z
| E: The repository 'http://archive.raspberrypi.org/debian bullseye
InRelease' is not signed.
| W: http://raspbian.raspberrypi.org/raspbian/dists/bullseye/InRelease:
Loading /work/build/tmp/work/raspios-bullseye-armhf/isar-mmdebstrap-
target/1.0-r0/distro-keyring.gpg from deprecated option
Dir::Etc::Trusted
| W: OpenPGP signature verification failed:
http://raspbian.raspberrypi.org/raspbian bullseye InRelease: Sub-
process /usr/bin/sqv returned an error code (1), error message is:
Signing key on A0DA38D0D76E8B5D638872819165938D90FDDD2E is not bound: 
No binding signature at time 2026-03-05T04:17:28Z   because: Policy
rejected non-revocation signature (PositiveCertification) requiring
second pre-image resistance   because: SHA1 is not considered secure
since 2026-02-01T00:00:00Z
| E: The repository 'http://raspbian.raspberrypi.org/raspbian bullseye
InRelease' is not signed.
| E: apt-get update --error-on=any -oAPT::Status-Fd=<$fd> -oDpkg::Use-
Pty=false failed: process exited with 100 and error in console output
| W: hooklistener errored out: E: received eof on socket
| 
| I: main() received signal PIPE: waiting for setup...
| I: removing tempdir /work/build/tmp/work/raspios-bullseye-armhf/isar-
mmdebstrap-target/1.0-r0/tempdir/mmdebstrap.N4elBIlcRU...
| E: mmdebstrap failed to run

-- 
Siemens AG
Linux Expert Center
Friedrich-Ludwig-Bauer-Str. 3
85748 Garching, Germany

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/a103328be2ce982535c374048f87925bc5507b8a.camel%40siemens.com.

                 reply	other threads:[~2026-03-05  8:31 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=a103328be2ce982535c374048f87925bc5507b8a.camel@siemens.com \
    --to=isar-users@googlegroups.com \
    --cc=felix.moessbauer@siemens.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox