KPackageKit fails to install package from untrusted sources (GPG key missing), but asks anyway

Bug #573321 reported by Daniel Hahler
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
packagekit (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

Binary package hint: kpackagekit

The following fails silently, after having asked me if I want to install the unverified package:
  $ kpackagekit --install-package-name kcachegrind-dbgsym

(the GPG key was missing).

After having added/imported the key, it would probably work, but now failed with another/irrelevant(?):
"Failed to fetch http://ddebs.ubuntu.com/pool/main/k/kdesdk/kcachegrind-dbgsym_4.4.2-0ubuntu3_i386.ddeb 403 Forbidden file type or location" (also with apt-get, but Firefox worked then).

ProblemType: Bug
DistroRelease: Ubuntu 10.04
Package: kpackagekit 0.5.4-0ubuntu4
ProcVersionSignature: Ubuntu 2.6.32-22.33-generic 2.6.32.11+drm33.2
Uname: Linux 2.6.32-22-generic i686
Architecture: i386
Date: Sat May 1 23:54:52 2010
ProcEnviron:
 LANGUAGE=de_DE:de:en_US:en_GB:en
 PATH=(custom, user)
 LANG=de_DE.UTF-8
 SHELL=/bin/bash
SourcePackage: kpackagekit

Revision history for this message
Daniel Hahler (blueyed) wrote :
Revision history for this message
Jonathan Thomas (echidnaman) wrote :

A missing GPG key won't give anything more than a warning. I'd say that the 403 was the root cause both times.

affects: kpackagekit (Ubuntu) → packagekit (Ubuntu)
Changed in packagekit (Ubuntu):
status: New → Invalid
Revision history for this message
Daniel Hahler (blueyed) wrote :

Sorry, re-opening (I think we misunderstood):

it pops up a dialog to ask if I want to install from the untrusted source - and does not just issue a warning.

Why does it ask, when it will only issue a warning anyway?

description: updated
Changed in packagekit (Ubuntu):
status: Invalid → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for packagekit (Ubuntu) because there has been no activity for 60 days.]

Changed in packagekit (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.