pingcap / pingcap/tiup

Tiup upgrade hit many warning like "invalid signature for file snapshot.json"

Open
#2,122 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

type/bug
Dominant language
Go
Stars
466
Forks
338
Avg merge
3d 7h
Merged PRs (30d)
8

Description

Bug Report

Please answer these questions before submitting your issue. Thanks!

  1. What did you do?
  1. What did you expect to see?
    Hit such warnings many time, not sure what is caused and how to fix.
    Warn: invalid signature for file snapshot.json: crypto/rsa: verification error
    Warn: invalid signature for file snapshot.json: crypto/rsa: verification error
    Warn: invalid signature for file snapshot.json: crypto/rsa: verification error
    Warn: invalid signature for file snapshot.json: crypto/rsa: verification error
    Warn: invalid signature for file snapshot.json: crypto/rsa: verification error
    Warn: invalid signature for file snapshot.json: crypto/rsa: verification error
    Warn: invalid signature for file snapshot.json: crypto/rsa: verification error
    Warn: invalid signature for file snapshot.json: crypto/rsa: verification error
    Warn: invalid signature for file snapshot.json: crypto/rsa: verification error
    Warn: invalid signature for file snapshot.json: crypto/rsa: verification error

  2. What did you see instead?
    a、Should give more information about why and how to fix.
    b、No such warnings.

  3. What version of TiUP are you using (tiup --version)?
    [root@436 brlog]# tiup --version
    1.10.3 tiup
    Go Version: go1.18.5
    Git Ref: v1.10.3
    GitHash: e198ac54996fa5a29f1961a460d6634ee9e75d2

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the TiUP upgrade command with the reported v1.10.3 environment and repeated snapshot.json signature warnings. Trace where the warning is emitted and determine why verification fails. Done means explaining the cause and either eliminating the spurious warnings or providing actionable remediation, with a regression check.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.