Hi, * David Kalnischkies [Mon Jul 27, 2026 at 11:48:12AM +0200]: > Am Fri, Jul 24, 2026 at 06:15:07PM +0200, schrieb Michael Prokop:
> > IMO we should clearly exit with non-zero in case of failures in apt > > in such situations. > > > > The behavior in apt v3.0.3 is still like this: > > > > | % sudo apt update [...] > > I've seen too many unpatched + hacked systems which ended up as such > > due to expired GPG keys in their (usually 3rd party) Debian > > repositories. IMO this might even warrant a CVE. > > If apt were to exit non-zero in these situations you would "see too many > unpatched + hacked systems" as unattended upgrades from the main > (and security) repositories of your distribution are not applied thanks > to some tiny long forgotten 3rd party repo the user might not even have > any packages installed from any longer… > So, I don't think there is a trivial black-or-white answer. Ah good point, thanks. > I also note that with `--error-on=any` nowadays you can make these types > of problems result in a non-zero exit code. There exists currently no > way of programmatically knowing the difference through. Hm, couldn't we consider 'apt update' + 'apt upgrade' two separate steps, so even if 'apt update' returns with an exit code other than zero, its consecutive 'apt upgrade' gets still executed/applied (with only the repositories considered that do *not* raise an error)? Maybe I'm missing something, but isn't it already apt-daily.service's "/usr/lib/apt/apt.systemd.daily update" which does the update part, and unattended-upgrades.service (from unattended-upgrades) which does the actual upgrade part then (so the exit code not actually being relevant)? regards -mika-
signature.asc
Description: PGP signature

