Arch Linux

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#67870 - Empty Package for ca-certificates

Attached to Project: Arch Linux
Opened by GI Jack (GI_Jack) - Friday, 11 September 2020, 00:17 GMT
Last edited by Eli Schwartz (eschwartz) - Friday, 11 September 2020, 00:36 GMT
Task Type Bug Report
Category Packages: Core
Status Closed
Assigned To No-one
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 1
Private No

Details

Description:
Package ca-certificates in [core] is empty. Just has metadata. Files are listed in package tracker, but do NOT show up in package

Additional info:
* package version(s)

pacman -Q ca-certificates
ca-certificates 20181109-4

* config and/or log files etc.

* link to upstream bug report, if any

Steps to reproduce:
sudo pacman -S ca-certificates

/usr/share/ca-certificates$ ls
trust-source

Expected files: https://www.archlinux.org/packages/core/any/ca-certificates/files/
This task depends upon

Closed by  Eli Schwartz (eschwartz)
Friday, 11 September 2020, 00:36 GMT
Reason for closing:  Not a bug
Comment by GI Jack (GI_Jack) - Friday, 11 September 2020, 00:27 GMT
Also checked the signature:

gpg --verify ca-certificates-20181109-4-any.pkg.tar.zst.sig
gpg: assuming signed data in 'ca-certificates-20181109-4-any.pkg.tar.zst'
gpg: Signature made Tue 28 Jul 2020 12:48:12 PM EDT
gpg: using EDDSA key 06687A1D9D4FAB08B50FD92B3B94A80E50A477C7
gpg: issuer "heftig@archlinux.org"
gpg: Can't check signature: No public key

Does not match heftig's keys
https://git.archlinux.org/archlinux-keyring.git/tree/packager-keyids
8218F88849AAC522E94CF470A5E9288C4FA415FA heftig
A2FF3A36AAA56654109064AB19802F8B0D70FC30 heftig
Comment by Eli Schwartz (eschwartz) - Friday, 11 September 2020, 00:36 GMT
I have no idea what this bug report is supposed to mean. You failed to verify the file due to not having the key in gpg, but pacman-key --verify (which embeds its keyring in archlinux-keyring) works fine.

ca-certificates is *supposed* to not contain files. It's a metapackage. I don't know why you think this is an accident.

Loading...