diff --git a/scripts/install-apt.sh b/scripts/install-apt.sh index b9f862c..15ba9cb 100755 --- a/scripts/install-apt.sh +++ b/scripts/install-apt.sh @@ -123,9 +123,11 @@ if [ "$($SUDO curl "${CURL_AUTH[@]}" -sSL -o /dev/null -w '%{http_code}' "$RELEA fi # Newer apt verifies with sqv (Sequoia), which rejects the signature Forgejo -# currently produces for its Debian registry (malformed Ed25519 MPI encoding -# in the upstream signing library). Try the properly signed source first so -# this heals automatically once the forge is fixed. Only that signature-error +# currently produces for its Debian registry. The cause is recorded on #1; it +# is not the key algorithm, because the registry serves an RSA-2048 signing +# key (`gpg --list-packets` on repository.key reports `algo 1` with a +# 2048-bit pkey[0]). Try the properly signed source first so this heals +# automatically once the forge is fixed. Only that signature-error # class permits the compatibility fallback; auth, network, and other failures # must leave verification enabled and retain apt's original diagnostic. if update_output="$(update_only_source "$LIST" 2>&1)"; then