Skip to content

Scope signed package components to repository - #1494

Merged
quba42 merged 1 commit into
pulp:mainfrom
daviddavis:1493-scope-signing-components
Aug 26, 2026
Merged

Scope signed package components to repository#1494
quba42 merged 1 commit into
pulp:mainfrom
daviddavis:1493-scope-signing-components

Conversation

@daviddavis

Copy link
Copy Markdown
Contributor

Prevent package signing from adding release-component associations belonging to other repositories.

fixes #1493

@daviddavis
daviddavis force-pushed the 1493-scope-signing-components branch from 47e3ae6 to 5621752 Compare July 29, 2026 15:44
@daviddavis
daviddavis force-pushed the 1493-scope-signing-components branch 4 times, most recently from 977c942 to 757e5c0 Compare July 29, 2026 19:21
Prevent package signing from adding release-component associations belonging to other repositories.

fixes pulp#1493

Assisted-by: GitHub Copilot
@daviddavis
daviddavis force-pushed the 1493-scope-signing-components branch from 757e5c0 to 27d001d Compare July 29, 2026 19:49

@quba42 quba42 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code wise this LGTM. I really just wanted to still test that the new test will fail without the fix. However, I ran into some trouble running the signing tests locally. I am getting:

$ oci-env test -i -p pulp_deb functional 
Using Python 3.12.13 environment at: /usr
Checked 8 packages in 4ms
pytest is /usr/local/bin/pytest
=============================================== test session starts ===============================================
platform linux -- Python 3.12.13, pytest-7.4.4, pluggy-1.6.0
rootdir: /var/lib/pulp
plugins: xdist-3.8.0, timeout-2.4.0, custom-exit-code-0.3.0, pulpcore-3.116.0.dev0
collected 132 items / 1 error                                                                                     

===================================================== ERRORS ======================================================
__________________________________ ERROR collecting api/test_package_signing.py ___________________________________
pulp_deb/tests/functional/api/test_package_signing.py:10: in <module>
    from pulp_deb.app.models import AptPackageSigningService
pulp_deb/app/models/__init__.py:3: in <module>
    from .content.content import (
pulp_deb/app/models/content/content.py:16: in <module>
    from pulpcore.plugin.models import Content
../pulpcore/pulpcore/plugin/models/__init__.py:6: in <module>
    from pulpcore.app.models import (
../pulpcore/pulpcore/app/models/__init__.py:6: in <module>
    from .base import (
../pulpcore/pulpcore/app/models/base.py:4: in <module>
    from django.contrib.contenttypes.fields import GenericRelation
/usr/local/lib/python3.12/site-packages/django/contrib/contenttypes/fields.py:8: in <module>
    from django.contrib.contenttypes.models import ContentType
/usr/local/lib/python3.12/site-packages/django/contrib/contenttypes/models.py:134: in <module>
    class ContentType(models.Model):
/usr/local/lib/python3.12/site-packages/django/db/models/base.py:131: in __new__
    app_config = apps.get_containing_app_config(module)
/usr/local/lib/python3.12/site-packages/django/apps/registry.py:260: in get_containing_app_config
    self.check_apps_ready()
/usr/local/lib/python3.12/site-packages/django/apps/registry.py:138: in check_apps_ready
    raise AppRegistryNotReady("Apps aren't loaded yet.")
E   django.core.exceptions.AppRegistryNotReady: Apps aren't loaded yet.
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! Interrupted: 1 error during collection !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
================================================ 1 error in 3.24s =================================================

I am getting this error on main branch, on this issue branch, everywhere. If I remove pulp_deb/tests/functional/api/test_package_signing.py from my local repo, other tests run normally.

Any ideas (so I can finish this review)?

@quba42

quba42 commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator

Also, given how this is a pretty serious bug (even if the feature is tech preview), I am thinking we should backport this to 3.10. Thoughts?

@daviddavis

Copy link
Copy Markdown
Contributor Author

Yea, backporting makes sense.

I am working on a fix for the test issue you are running into here: #1496

@quba42 quba42 added .bugfix CHANGES/<issue_number>.bugfix backport-3.10 labels Jul 30, 2026

@quba42 quba42 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So I have now seen the test fail without the fix and succeed with it. That plus my code review is good enough for me for this change.

Side Note: Apparently adding pulp_rpm to my oci_env had the side effect of fixing my local test run.

@quba42
quba42 merged commit 1b6479b into pulp:main Aug 26, 2026
14 checks passed
@patchback

patchback Bot commented Aug 26, 2026

Copy link
Copy Markdown

Backport to 3.10: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.10/1b6479bb99d59b22d6cb077be5dfc577c0f065f6/pr-1494

Backported as #1512

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

quba42 added a commit that referenced this pull request Aug 26, 2026
…9d59b22d6cb077be5dfc577c0f065f6/pr-1494

[PR #1494/1b6479bb backport][3.10] Scope signed package components to repository
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-3.10 .bugfix CHANGES/<issue_number>.bugfix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Package signing adds release-component associations from unrelated repositories

2 participants