Skip to content

budgie-session-v0.9.1.tar.xz signature public key not trusted

Description:

The key used in budgie-session-v0.9.1.tar.xz.asc is not present in the repo. After manually running gpg --recv-keys C2EAA8A26ADC59EE, makepkg complains about the key not being trusted:

==> Building in chroot for [extra] (x86_64)...
==> Synchronizing chroot copy [/var/lib/archbuild/extra-x86_64/root] -> [hacker]...done
==> Making package: budgie-session 0.9.1-1 (Tue Jun 18 14:48:26 2024)
==> Retrieving sources...
  -> Found budgie-session-v0.9.1.tar.xz
  -> Found budgie-session-v0.9.1.tar.xz.asc
==> Validating source files with b2sums...
    budgie-session-v0.9.1.tar.xz ... Passed
    budgie-session-v0.9.1.tar.xz.asc ... Skipped
==> Verifying source file signatures with gpg...
    budgie-session-v0.9.1.tar.xz ... FAILED (the public key 1E1FB0017C998A8AE2C498A6C2EAA8A26ADC59EE is not trusted)
==> ERROR: One or more PGP signatures could not be verified!
==> ERROR: Could not download sources.

The shown key should be listed in validgpgkeys=() array.

Additional info:

  • package version(s):
  • config and/or log files:
  • link to upstream bug report, if any:

Steps to reproduce:

  1. makepkg
  2. gpg --recv-keys C2EAA8A26ADC59EE
  3. makepkg
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information