--- /dev/null
+#!/usr/bin/env python
+# coding=utf8
+
+"""
+Allow per-suite signing keys
+
+@contact: Debian FTP Master <ftpmaster@debian.org>
+@copyright: 2011 Mark Hymers <mhy@debian.org>
+@license: GNU General Public License version 2 or later
+"""
+
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 2 of the License, or
+# (at your option) any later version.
+
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
+
+################################################################################
+
+import psycopg2
+from daklib.dak_exceptions import DBUpdateError
+
+################################################################################
+def do_update(self):
+ """
+ Allow per-suite signing keys
+ """
+ print __doc__
+ try:
+ c = self.db.cursor()
+
+ c.execute("""ALTER TABLE suite ADD COLUMN signingkeys TEXT[]""")
+ c.execute("""UPDATE suite SET signingkeys = signingkeys || (SELECT value FROM config WHERE name = 'signingkeyids')""")
+ c.execute("""DELETE FROM config WHERE name = 'signingkeyids'""")
+
+ c.execute("UPDATE config SET value = '57' WHERE name = 'db_revision'")
+ self.db.commit()
+
+ except psycopg2.ProgrammingError, msg:
+ self.db.rollback()
+ raise DBUpdateError, 'Unable to apply sick update 57, rollback issued. Error message : %s' % (str(msg))
if arg:
results.append(arg)
-def sign_release_dir(dirname):
+def sign_release_dir(suite, dirname):
cnf = Config()
if cnf.has_key("Dinstall::SigningKeyring"):
keyring += " --keyring \"%s\"" % cnf["Dinstall::SigningPubKeyring"]
arguments = "--no-options --batch --no-tty --armour"
- signkeyids = cnf.signingkeyids.split()
relname = os.path.join(dirname, 'Release')
if os.path.exists(inlinedest):
os.unlink(inlinedest)
- for keyid in signkeyids:
- if keyid != "":
- defkeyid = "--default-key %s" % keyid
- else:
- defkeyid = ""
+ # We can only use one key for inline signing so use the first one in
+ # the array for consistency
+ firstkey = False
+
+ for keyid in suite.signingkeyids:
+ defkeyid = "--default-key %s" % keyid
os.system("gpg %s %s %s --detach-sign <%s >>%s" %
(keyring, defkeyid, arguments, relname, dest))
- os.system("gpg %s %s %s --clearsign <%s >>%s" %
- (keyring, defkeyid, arguments, relname, inlinedest))
+ if firstkey:
+ os.system("gpg %s %s %s --clearsign <%s >>%s" %
+ (keyring, defkeyid, arguments, relname, inlinedest))
+ firstkey = False
class ReleaseWriter(object):
def __init__(self, suite):
out.close()
- sign_release_dir(os.path.dirname(outfile))
+ sign_release_dir(suite, os.path.dirname(outfile))
os.chdir(oldcwd)
################################################################################
Cnf = None
-required_database_schema = 54
+required_database_schema = 57
################################################################################
"""
for field in [('db_revision', None, int),
('defaultsuitename', 'unstable', str),
- ('signingkeyids', '', str),
('exportpath', '', str)
]:
setattr(self, 'get_%s' % field[0], lambda s=None, x=field[0], y=field[1], z=field[2]: self.get_db_value(x, y, z))