Bug 25091 - Update Isodumper to 1.09
Summary: Update Isodumper to 1.09
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard: MGA6-64-OK MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-07-10 20:25 CEST by papoteur
Modified: 2019-07-20 22:10 CEST (History)
5 users (show)

See Also:
Source RPM: isodumper
CVE:
Status comment:


Attachments

Description papoteur 2019-07-10 20:25:47 CEST
Signatures for Mageia 7 are now computed in a manner that needs to specify the file to check the signature against.
Isodumper 1.09 takes this into account and now the signature can be checked

Before, 1.08
Have Mageia 7 iso in a directory with sha512 sum file and its gpg signature
Launch the writing.
The verification ends saying that sum is OK but signature is not found.

With 1.09
The verification ends saying that the sums match and are signed.
Comment 1 David GEIGER 2019-07-11 05:25:49 CEST
So list of packages:


Packages in 6/core/updates_testing:
========================
isodumper-1.09-1.mga6.noarch.rpm
isodumper-qt-1.09-1.mga6.noarch.rpm
isodumper-gtk-1.09-1.mga6.noarch.rpm

Source RPM:
========================
isodumper-1.09-1.mga6.src.rpm



Packages in 7/core/updates_testing:
========================
isodumper-1.09-1.mga7.noarch.rpm
isodumper-qt-1.09-1.mga7.noarch.rpm
isodumper-gtk-1.09-1.mga7.noarch.rpm

Source RPM:
========================
isodumper-1.09-1.mga7.src.rpm

CC: (none) => geiger.david68210

Comment 2 papoteur 2019-07-11 10:25:48 CEST
Suggested advisory
===================================
Signatures for Mageia 7 are now computed in a manner that needs to specify the file to check the signature against.
Isodumper 1.09 takes this into account and now the signature can be checked.
===================================
Marja Van Waes 2019-07-13 17:34:34 CEST

Assignee: bugsquad => qa-bugs
CC: (none) => marja11

Marja Van Waes 2019-07-13 17:34:57 CEST

Whiteboard: (none) => MGA6TOO

Comment 3 Morgan Leijström 2019-07-14 07:49:46 CEST
OK here 64 bit mga6.
Log window output:

"

Target Device: SMI USB DISK (/dev/sdd) 15240.0Mb
Image : /mnt/WDred/AnvMorgan/TillArkivet/Mageia-7-x86_64/Mageia-7-x86_64.iso
Executing copy from /mnt/WDred/AnvMorgan/TillArkivet/Mageia-7-x86_64/Mageia-7-x86_64.iso to /dev/sdd
Image Mageia-7-x86_64.iso successfully written to /dev/sdd
Bytes written: 4447385600

The sha512 sum check is OK and the sum is signed 

   "

CC: (none) => fri

Comment 4 Len Lawrence 2019-07-18 10:57:17 CEST
mga7, x86_64

Installed version 1.09-1 with the gtk interface.
Used it to dump the Xfce Live x86_64 iso to a 16 GB USB drive.
...
Bytes written: 2463238144
Invalid signature for /data/isos/mageia7/Mageia-7.1-Live-Xfce-x86_64/Mageia-7.1-Live-Xfce-x86_64.iso.sha512The sha512 sum check is OK but the signature can't be found
Adding persistent partition
...

$ rpm -qa | grep isodumper
isodumper-1.09-1.mga7
isodumper-gtk-1.09-1.mga7

Where would isodumper look for the signature and what is it called?

[lcl@canopus Mageia-7.1-Live-Xfce-x86_64]$ ls
DATE.txt
Mageia-7.1-Live-Xfce-x86_64.iso
Mageia-7.1-Live-Xfce-x86_64.iso.gpg
Mageia-7.1-Live-Xfce-x86_64.iso.md5
Mageia-7.1-Live-Xfce-x86_64.iso.md5.gpg
Mageia-7.1-Live-Xfce-x86_64.iso.sha3
Mageia-7.1-Live-Xfce-x86_64.iso.sha3.gpg
Mageia-7.1-Live-Xfce-x86_64.iso.sha512
Mageia-7.1-Live-Xfce-x86_64.iso.sha512.gpg
Mageia-7.1-Live-Xfce-x86_64.langs
Mageia-7.1-Live-Xfce-x86_64.lst
Mageia-7.1-Live-Xfce-x86_64.lst.full
Mageia-7.1-Live-Xfce-x86_64.lst.leaves
Mageia-7.1-Live-Xfce-x86_64.lst.names

CC: (none) => tarazed25

Comment 5 papoteur 2019-07-18 11:47:43 CEST
Hi Len,
Did you use isodumper 1.08 in the session before installation of 1.09?
If yes, try again with first this command as root
 systemctl restart magiback

This is a part of isodumper which run indenpendently.
Comment 6 Len Lawrence 2019-07-18 12:31:03 CEST
mga6, x86_64

Ran the update on a different machine with an mga6 partition.  The operation was successful, as before, but the signature could not be found.  Did not add a persistent partition this time.
Comment 7 Len Lawrence 2019-07-18 12:36:03 CEST
@papoteur in reply to comments 4 and 5:

No, not for this particular iso.  So maybe I should find another mga7 partition and try 1.08.  About to try that.  Thanks papoteur.
Comment 8 Len Lawrence 2019-07-18 13:09:00 CEST
@papoteur in reply to comment 5:

Yep, that worked perfectly.
Started witth isodumper 1.08.  Dumped an iso to a USB stick.  Saw the fault.
Restarted magiback and checked that it was running OK.
Ran the update and used isodumper 1.09 to dump the iso again.

Session log:
[...]
Executing copy from /data/isos/mageia7/Mageia-7.1-Live-Xfce-x86_64/Mageia-7.1-Live-Xfce-x86_64.iso to /dev/sdd
Image Mageia-7.1-Live-Xfce-x86_64.iso successfully written to /dev/sdd
Bytes written: 2463238144

The sha512 sum check is OK and the sum is signed

Registering the 64bit OK for mga7 and for maga6 on the basis of Morgan's test.

Whiteboard: MGA6TOO => MGA6-64-OK MGA7-64-OK

Comment 9 papoteur 2019-07-18 18:10:33 CEST
(In reply to Len Lawrence from comment #4)
> 
> Where would isodumper look for the signature and what is it called?

Isodumper looks for the signature and the sum files in the same directory as the iso file, by addind .sha512 and .sha512.gpg respectively to the name.
Comment 10 Rémi Verschelde 2019-07-19 10:21:03 CEST
Advisory uploaded, validating.

Keywords: (none) => advisory, validated_update
CC: (none) => sysadmin-bugs

Comment 11 Mageia Robot 2019-07-20 22:10:36 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGAA-2019-0067.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.