Hi,

* David Kalnischkies [Mon Jul 27, 2026 at 11:48:12AM +0200]:
> Am Fri, Jul 24, 2026 at 06:15:07PM +0200, schrieb Michael Prokop:

> > IMO we should clearly exit with non-zero in case of failures in apt
> > in such situations.
> > 
> > The behavior in apt v3.0.3 is still like this:
> > 
> > | % sudo apt update
[...]

> > I've seen too many unpatched + hacked systems which ended up as such
> > due to expired GPG keys in their (usually 3rd party) Debian
> > repositories. IMO this might even warrant a CVE.
> 
> If apt were to exit non-zero in these situations you would "see too many
> unpatched + hacked systems" as unattended upgrades from the main
> (and security) repositories of your distribution are not applied thanks
> to some tiny long forgotten 3rd party repo the user might not even have
> any packages installed from any longer…
> So, I don't think there is a trivial black-or-white answer.

Ah good point, thanks.

> I also note that with `--error-on=any` nowadays you can make these types
> of problems result in a non-zero exit code. There exists currently no
> way of programmatically knowing the difference through.

Hm, couldn't we consider 'apt update' + 'apt upgrade' two separate
steps, so even if 'apt update' returns with an exit code other than
zero, its consecutive 'apt upgrade' gets still executed/applied
(with only the repositories considered that do *not* raise an
error)?

Maybe I'm missing something, but isn't it already
apt-daily.service's "/usr/lib/apt/apt.systemd.daily update" which
does the update part, and unattended-upgrades.service (from
unattended-upgrades) which does the actual upgrade part then (so the
exit code not actually being relevant)?

regards
-mika-

Attachment: signature.asc
Description: PGP signature

Reply via email to