XYZ File Manager
Current Path:
/usr/bin
usr
/
bin
/
π
..
π
X11
π
[
(66.89 KB)
π
ab
(58.42 KB)
π
addpart
(30.31 KB)
π
apt
(18.31 KB)
π
apt-cache
(86.38 KB)
π
apt-cdrom
(22.38 KB)
π
apt-config
(26.31 KB)
π
apt-get
(50.38 KB)
π
apt-key
(27.32 KB)
π
apt-mark
(58.38 KB)
π
arch
(42.86 KB)
π
awk
(154.66 KB)
π
b2sum
(58.98 KB)
π
base32
(46.89 KB)
π
base64
(46.89 KB)
π
basename
(42.83 KB)
π
basenc
(54.89 KB)
π
bash
(1.21 MB)
π
bashbug
(6.7 KB)
π
bdftopcf
(42.45 KB)
π
bdftruncate
(10.22 KB)
π
busctl
(90.5 KB)
π
c_rehash
(6.68 KB)
π
captoinfo
(90.34 KB)
π
cat
(42.98 KB)
π
certbot
(958 B)
π
chage
(78.49 KB)
π
chardet
(221 B)
π
chardetect
(221 B)
π
chattr
(14.24 KB)
π
chcon
(67.11 KB)
π
checkgid
(14.23 KB)
π
chfn
(61.2 KB)
π
chgrp
(67.05 KB)
π
chmod
(62.98 KB)
π
choom
(54.31 KB)
π
chown
(71.05 KB)
π
chrt
(66.31 KB)
π
chsh
(51.64 KB)
π
cksum
(139.05 KB)
π
clear
(14.24 KB)
π
clear_console
(14.15 KB)
π
cmp
(50.95 KB)
π
comm
(46.92 KB)
π
corelist
(15.01 KB)
π
cp
(147.61 KB)
π
cpan
(8.16 KB)
π
cpan5.36-x86_64-linux-gnu
(8.18 KB)
π
csplit
(119.17 KB)
π
ctstat
(26.59 KB)
π
cut
(46.98 KB)
π
dash
(122.7 KB)
π
date
(119.05 KB)
π
dbus-cleanup-sockets
(14.22 KB)
π
dbus-daemon
(238.56 KB)
π
dbus-monitor
(26.23 KB)
π
dbus-run-session
(14.23 KB)
π
dbus-send
(30.22 KB)
π
dbus-update-activation-environment
(14.22 KB)
π
dbus-uuidgen
(14.22 KB)
π
dd
(87.15 KB)
π
deb-systemd-helper
(23.79 KB)
π
deb-systemd-invoke
(6.09 KB)
π
debconf
(2.79 KB)
π
debconf-apt-progress
(11.27 KB)
π
debconf-communicate
(608 B)
π
debconf-copydb
(1.68 KB)
π
debconf-escape
(647 B)
π
debconf-set-selections
(2.92 KB)
π
debconf-show
(1.78 KB)
π
delpart
(30.31 KB)
π
df
(99.8 KB)
π
dialog
(247.85 KB)
π
diff
(151.58 KB)
π
diff3
(67.14 KB)
π
dir
(147.8 KB)
π
dircolors
(50.92 KB)
π
dirname
(38.83 KB)
π
dmesg
(86.58 KB)
π
dnsdomainname
(22.15 KB)
π
domainname
(22.15 KB)
π
dpkg
(310.64 KB)
π
dpkg-deb
(166.52 KB)
π
dpkg-divert
(154.55 KB)
π
dpkg-maintscript-helper
(20.71 KB)
π
dpkg-query
(158.58 KB)
π
dpkg-realpath
(4.09 KB)
π
dpkg-split
(126.48 KB)
π
dpkg-statoverride
(62.33 KB)
π
dpkg-trigger
(86.48 KB)
π
du
(171.33 KB)
π
dvipdf
(1007 B)
π
echo
(42.83 KB)
π
editor
(3.48 MB)
π
egrep
(41 B)
π
enc2xs
(40.96 KB)
π
encguess
(3 KB)
π
env
(47.4 KB)
π
eps2eps
(639 B)
π
ex
(3.48 MB)
π
expand
(42.92 KB)
π
expiry
(30.45 KB)
π
expr
(115.05 KB)
π
factor
(83.2 KB)
π
faillog
(22.53 KB)
π
fallocate
(34.31 KB)
π
false
(34.83 KB)
π
fcgistarter
(14.23 KB)
π
fgrep
(41 B)
π
fincore
(34.36 KB)
π
find
(219.58 KB)
π
findmnt
(83.59 KB)
π
flock
(34.39 KB)
π
fmt
(46.89 KB)
π
fold
(42.89 KB)
π
fonttosfnt
(34.41 KB)
π
free
(26.3 KB)
π
fuser
(39.83 KB)
π
getconf
(26.5 KB)
π
getent
(35.47 KB)
π
getopt
(34.31 KB)
π
ghostscript
(14.23 KB)
π
gpasswd
(86.42 KB)
π
gpgv
(463 KB)
π
grep
(198.39 KB)
π
groups
(42.89 KB)
π
gs
(14.23 KB)
π
gsbj
(350 B)
π
gsdj
(352 B)
π
gsdj500
(352 B)
π
gslj
(353 B)
π
gslp
(350 B)
π
gsnd
(277 B)
π
gunzip
(2.29 KB)
π
gzexe
(6.3 KB)
π
gzip
(95.84 KB)
π
h2ph
(28.54 KB)
π
h2xs
(59.51 KB)
π
hardlink
(50.39 KB)
π
head
(46.95 KB)
π
helpztags
(2.46 KB)
π
hostid
(38.83 KB)
π
hostname
(22.15 KB)
π
hostnamectl
(30.38 KB)
π
htcacheclean
(34.24 KB)
π
htdbm
(26.23 KB)
π
htdigest
(14.23 KB)
π
htpasswd
(26.23 KB)
π
i386
(26.58 KB)
π
iconv
(63.13 KB)
π
id
(47.02 KB)
π
infocmp
(62.31 KB)
π
infotocap
(90.34 KB)
π
install
(155.8 KB)
π
instmodsh
(4.27 KB)
π
ionice
(34.31 KB)
π
ip
(674.82 KB)
π
ipcmk
(34.38 KB)
π
ipcrm
(34.31 KB)
π
ipcs
(74.31 KB)
π
ischroot
(14.32 KB)
π
join
(54.98 KB)
π
journalctl
(74.64 KB)
π
json_pp
(4.88 KB)
π
kernel-install
(12.75 KB)
π
kill
(22.3 KB)
π
killall
(31.95 KB)
π
last
(50.31 KB)
π
lastb
(50.31 KB)
π
lastlog
(31.75 KB)
π
lcf
(7.6 KB)
π
ld.so
(205.96 KB)
π
ldd
(5.28 KB)
π
letsencrypt
(958 B)
π
libnetcfg
(15.41 KB)
π
link
(38.83 KB)
π
linux32
(26.58 KB)
π
linux64
(26.58 KB)
π
ln
(71.12 KB)
π
lnstat
(26.59 KB)
π
locale
(46.16 KB)
π
localectl
(26.38 KB)
π
localedef
(291.91 KB)
π
logger
(54.9 KB)
π
login
(51.78 KB)
π
loginctl
(58.48 KB)
π
logname
(38.83 KB)
π
logresolve
(14.24 KB)
π
ls
(147.8 KB)
π
lsattr
(14.24 KB)
π
lsb_release
(2.59 KB)
π
lsblk
(202.31 KB)
π
lscpu
(126.31 KB)
π
lsfd
(120.3 KB)
π
lsipc
(98.31 KB)
π
lsirq
(34.48 KB)
π
lslocks
(70.7 KB)
π
lslogins
(94.31 KB)
π
lsmem
(66.31 KB)
π
lsns
(82.31 KB)
π
mawk
(154.66 KB)
π
mcookie
(34.38 KB)
π
md5sum
(50.95 KB)
π
md5sum.textutils
(50.95 KB)
π
mesg
(18.3 KB)
π
mkdir
(95.27 KB)
π
mkfifo
(67.17 KB)
π
mkfontdir
(65 B)
π
mkfontscale
(39.05 KB)
π
mknod
(71.2 KB)
π
mktemp
(42.92 KB)
π
more
(58.31 KB)
π
mount
(58.3 KB)
π
mountpoint
(18.3 KB)
π
mv
(139.62 KB)
π
namei
(34.31 KB)
π
nawk
(154.66 KB)
π
netstat
(151.66 KB)
π
networkctl
(106.38 KB)
π
newgrp
(47.75 KB)
π
nice
(42.86 KB)
π
nisdomainname
(22.15 KB)
π
nl
(111.11 KB)
π
nohup
(42.89 KB)
π
normalizer
(244 B)
π
nproc
(42.89 KB)
π
nsenter
(34.54 KB)
π
nstat
(104.45 KB)
π
numfmt
(67.02 KB)
π
od
(79.02 KB)
π
openssl
(953.26 KB)
π
pager
(58.31 KB)
π
paperconf
(14.34 KB)
π
partx
(118.31 KB)
π
passwd
(66.65 KB)
π
paste
(42.89 KB)
π
pathchk
(42.86 KB)
π
pdb3
(62.4 KB)
π
pdb3.11
(62.4 KB)
π
pdf2dsc
(698 B)
π
pdf2ps
(909 B)
π
peekfd
(14.5 KB)
π
perl
(3.63 MB)
π
perl5.36-x86_64-linux-gnu
(14.41 KB)
π
perl5.36.0
(3.63 MB)
π
perlbug
(44.12 KB)
π
perldoc
(125 B)
π
perlivp
(10.61 KB)
π
perlthanks
(44.12 KB)
π
pf2afm
(498 B)
π
pfbtopfa
(516 B)
π
pgrep
(34.42 KB)
π
phar
(14.88 KB)
π
phar.phar
(14.88 KB)
π
phar.phar8.2
(14.88 KB)
π
phar8.2
(14.88 KB)
π
phar8.2.phar
(14.88 KB)
π
php
(5.4 MB)
π
php8.2
(5.4 MB)
π
piconv
(8.16 KB)
π
pidof
(26.31 KB)
π
pidwait
(34.42 KB)
π
pinky
(47.05 KB)
π
pkill
(34.42 KB)
π
pl2pm
(4.43 KB)
π
pldd
(22.69 KB)
π
pmap
(34.34 KB)
π
pod2html
(4.04 KB)
π
pod2man
(14.68 KB)
π
pod2text
(10.55 KB)
π
pod2usage
(4.01 KB)
π
podchecker
(3.57 KB)
π
pphs
(404 B)
π
pr
(79.11 KB)
π
printafm
(395 B)
π
printenv
(34.83 KB)
π
printf
(62.92 KB)
π
prlimit
(38.83 KB)
π
prove
(13.34 KB)
π
prtstat
(18.57 KB)
π
ps
(142.93 KB)
π
ps2ascii
(631 B)
π
ps2epsi
(1.23 KB)
π
ps2pdf
(272 B)
π
ps2pdf12
(215 B)
π
ps2pdf13
(215 B)
π
ps2pdf14
(215 B)
π
ps2pdfwr
(1.05 KB)
π
ps2ps
(647 B)
π
ps2ps2
(669 B)
π
ps2txt
(631 B)
π
pslog
(14.45 KB)
π
pstree
(35.78 KB)
π
pstree.x11
(35.78 KB)
π
ptar
(3.48 KB)
π
ptardiff
(2.58 KB)
π
ptargrep
(4.29 KB)
π
ptx
(135.23 KB)
π
pwd
(42.92 KB)
π
pwdx
(14.3 KB)
π
py3clean
(7.63 KB)
π
py3compile
(13 KB)
π
py3versions
(12.52 KB)
π
pydoc3
(79 B)
π
pydoc3.11
(79 B)
π
pygettext3
(23.67 KB)
π
pygettext3.11
(23.67 KB)
π
python3
(6.52 MB)
π
python3.11
(6.52 MB)
π
rbash
(1.21 MB)
π
rdma
(180.6 KB)
π
readlink
(50.89 KB)
π
realpath
(50.92 KB)
π
rename.ul
(22.3 KB)
π
renice
(14.3 KB)
π
reset
(30.24 KB)
π
resizepart
(70.31 KB)
π
rev
(14.3 KB)
π
rgrep
(30 B)
π
rm
(71.05 KB)
π
rmdir
(54.92 KB)
π
rotatelogs
(26.31 KB)
π
routel
(1.62 KB)
π
rtstat
(26.59 KB)
π
run-parts
(26.91 KB)
π
runcon
(42.95 KB)
π
rview
(3.48 MB)
π
rvim
(3.48 MB)
π
savelog
(10.24 KB)
π
scp
(266.63 KB)
π
script
(70.3 KB)
π
scriptlive
(54.3 KB)
π
scriptreplay
(46.3 KB)
π
sdiff
(55.08 KB)
π
sed
(123.46 KB)
π
select-editor
(2.39 KB)
π
sensible-browser
(1.26 KB)
π
sensible-editor
(1.24 KB)
π
sensible-pager
(565 B)
π
seq
(58.92 KB)
π
setarch
(26.58 KB)
π
setpriv
(78.31 KB)
π
setsid
(14.3 KB)
π
setterm
(46.31 KB)
π
sftp
(282.59 KB)
π
sg
(47.75 KB)
π
sh
(122.7 KB)
π
sha1sum
(54.95 KB)
π
sha224sum
(58.95 KB)
π
sha256sum
(58.95 KB)
π
sha384sum
(62.95 KB)
π
sha512sum
(62.95 KB)
π
shasum
(9.75 KB)
π
shred
(63.14 KB)
π
shuf
(58.98 KB)
π
skill
(30.33 KB)
π
slabtop
(22.37 KB)
π
sleep
(42.86 KB)
π
slogin
(1.07 MB)
π
snice
(30.33 KB)
π
sort
(115.68 KB)
π
splain
(18.99 KB)
π
split
(59.55 KB)
π
ss
(189.14 KB)
π
ssh
(1.07 MB)
π
ssh-add
(518.44 KB)
π
ssh-agent
(474.38 KB)
π
ssh-argv0
(1.42 KB)
π
ssh-copy-id
(12.38 KB)
π
ssh-keygen
(646.44 KB)
π
ssh-keyscan
(622.47 KB)
π
stat
(95.2 KB)
π
stdbuf
(58.92 KB)
π
streamzip
(7.75 KB)
π
stty
(83.02 KB)
π
su
(70.31 KB)
π
sum
(50.96 KB)
π
sync
(38.89 KB)
π
systemctl
(1.29 MB)
π
systemd
(90.38 KB)
π
systemd-analyze
(182.61 KB)
π
systemd-ask-password
(18.48 KB)
π
systemd-cat
(18.38 KB)
π
systemd-cgls
(22.48 KB)
π
systemd-cgtop
(38.4 KB)
π
systemd-creds
(42.61 KB)
π
systemd-cryptenroll
(58.6 KB)
π
systemd-delta
(26.38 KB)
π
systemd-detect-virt
(18.37 KB)
π
systemd-escape
(18.37 KB)
π
systemd-firstboot
(50.59 KB)
π
systemd-id128
(22.37 KB)
π
systemd-inhibit
(22.39 KB)
π
systemd-machine-id-setup
(18.48 KB)
π
systemd-mount
(50.59 KB)
π
systemd-notify
(18.38 KB)
π
systemd-path
(18.37 KB)
π
systemd-repart
(150.69 KB)
π
systemd-run
(58.57 KB)
π
systemd-socket-activate
(26.38 KB)
π
systemd-stdio-bridge
(18.38 KB)
π
systemd-sysext
(42.49 KB)
π
systemd-sysusers
(62.68 KB)
π
systemd-tmpfiles
(110.57 KB)
π
systemd-tty-ask-password-agent
(34.38 KB)
π
systemd-umount
(50.59 KB)
π
tabs
(18.23 KB)
π
tac
(111.05 KB)
π
tail
(75.14 KB)
π
tar
(519.52 KB)
π
taskset
(62.31 KB)
π
tee
(42.95 KB)
π
tempfile
(14.18 KB)
π
test
(58.89 KB)
π
tic
(90.34 KB)
π
timedatectl
(42.37 KB)
π
timeout
(47.49 KB)
π
tload
(18.32 KB)
π
toe
(22.23 KB)
π
top
(131.58 KB)
π
touch
(107.05 KB)
π
tput
(26.27 KB)
π
tr
(54.89 KB)
π
true
(34.83 KB)
π
truncate
(42.89 KB)
π
tset
(30.24 KB)
π
tsort
(54.89 KB)
π
tty
(34.86 KB)
π
tzselect
(14.99 KB)
π
ucf
(40.69 KB)
π
ucfq
(18.91 KB)
π
ucfr
(10.85 KB)
π
uclampset
(62.31 KB)
π
ucs2any
(18.32 KB)
π
umount
(34.3 KB)
π
uname
(42.86 KB)
π
uncompress
(2.29 KB)
π
unexpand
(42.92 KB)
π
uniq
(46.95 KB)
π
unlink
(38.83 KB)
π
unshare
(82.54 KB)
π
update-alternatives
(58.31 KB)
π
update-mime-database
(59.27 KB)
π
uptime
(14.3 KB)
π
users
(38.89 KB)
π
utmpdump
(30.3 KB)
π
vdir
(147.8 KB)
π
vi
(3.48 MB)
π
view
(3.48 MB)
π
vim
(3.48 MB)
π
vim.basic
(3.48 MB)
π
vimdiff
(3.48 MB)
π
vimtutor
(2.1 KB)
π
vmstat
(34.72 KB)
π
w
(22.3 KB)
π
wall
(38.3 KB)
π
watch
(26.71 KB)
π
wc
(51.05 KB)
π
wdctl
(70.34 KB)
π
wget
(527.36 KB)
π
whereis
(30.77 KB)
π
which
(946 B)
π
which.debianutils
(946 B)
π
who
(59.02 KB)
π
whoami
(38.86 KB)
π
x86_64
(26.58 KB)
π
xargs
(70.45 KB)
π
xdg-user-dir
(234 B)
π
xdg-user-dirs-update
(26.16 KB)
π
xsubpp
(5.05 KB)
π
xxd
(18.21 KB)
π
yes
(38.83 KB)
π
ypdomainname
(22.15 KB)
π
zcat
(1.94 KB)
π
zcmp
(1.64 KB)
π
zdiff
(6.31 KB)
π
zdump
(22.52 KB)
π
zegrep
(29 B)
π
zfgrep
(29 B)
π
zforce
(2.03 KB)
π
zgrep
(7.91 KB)
π
zipdetails
(68.55 KB)
π
zless
(2.15 KB)
π
zmore
(1.8 KB)
π
znew
(4.47 KB)
Editing: apt-key
#!/bin/sh set -e unset GREP_OPTIONS GPGHOMEDIR CURRENTTRAP export IFS="$(printf "\n\b")" MASTER_KEYRING='' eval "$(apt-config shell MASTER_KEYRING APT::Key::MasterKeyring)" ARCHIVE_KEYRING='' eval "$(apt-config shell ARCHIVE_KEYRING APT::Key::ArchiveKeyring)" REMOVED_KEYS='' eval "$(apt-config shell REMOVED_KEYS APT::Key::RemovedKeys)" ARCHIVE_KEYRING_URI='' eval "$(apt-config shell ARCHIVE_KEYRING_URI APT::Key::ArchiveKeyringURI)" aptkey_echo() { echo "$@"; } find_gpgv_status_fd() { while [ -n "$1" ]; do if [ "$1" = '--status-fd' ]; then shift echo "$1" break fi shift done } GPGSTATUSFD="$(find_gpgv_status_fd "$@")" apt_warn() { if [ -z "$GPGHOMEDIR" ]; then echo >&2 'W:' "$@" else echo 'W:' "$@" > "${GPGHOMEDIR}/aptwarnings.log" fi if [ -n "$GPGSTATUSFD" ]; then echo >&${GPGSTATUSFD} '[APTKEY:] WARNING' "$@" fi } apt_error() { if [ -z "$GPGHOMEDIR" ]; then echo >&2 'E:' "$@" else echo 'E:' "$@" > "${GPGHOMEDIR}/aptwarnings.log" fi if [ -n "$GPGSTATUSFD" ]; then echo >&${GPGSTATUSFD} '[APTKEY:] ERROR' "$@" fi } cleanup_gpg_home() { if [ -z "$GPGHOMEDIR" ]; then return; fi if [ -s "$GPGHOMEDIR/aptwarnings.log" ]; then cat >&2 "$GPGHOMEDIR/aptwarnings.log" fi if command_available 'gpgconf'; then GNUPGHOME="${GPGHOMEDIR}" gpgconf --kill all >/dev/null 2>&1 || true fi rm -rf "$GPGHOMEDIR" } # gpg needs (in different versions more or less) files to function correctly, # so we give it its own homedir and generate some valid content for it later on create_gpg_home() { # for cases in which we want to cache a homedir due to expensive setup if [ -n "$GPGHOMEDIR" ]; then return fi if [ -n "$TMPDIR" ]; then # tmpdir is a directory and current user has rwx access to it # same tests as in apt-pkg/contrib/fileutl.cc GetTempDir() if [ ! -d "$TMPDIR" ] || [ ! -r "$TMPDIR" ] || [ ! -w "$TMPDIR" ] || [ ! -x "$TMPDIR" ]; then unset TMPDIR fi fi GPGHOMEDIR="$(mktemp --directory --tmpdir 'apt-key-gpghome.XXXXXXXXXX')" CURRENTTRAP="${CURRENTTRAP} cleanup_gpg_home;" trap "${CURRENTTRAP}" 0 HUP INT QUIT ILL ABRT FPE SEGV PIPE TERM if [ -z "$GPGHOMEDIR" ]; then apt_error "Could not create temporary gpg home directory in $TMPDIR (wrong permissions?)" exit 28 fi chmod 700 "$GPGHOMEDIR" } requires_root() { if [ "$(id -u)" -ne 0 ]; then apt_error "This command can only be used by root." exit 1 fi } command_available() { if [ -x "$1" ]; then return 0; fi command -v "$1" >/dev/null # required by policy, see #747320 } escape_shell() { echo "$@" | sed -e "s#'#'\"'\"'#g" } get_fingerprints_of_keyring() { aptkey_execute "$GPG_SH" --keyring "$1" --with-colons --fingerprint | while read publine; do # search for a public key if [ "${publine%%:*}" != 'pub' ]; then continue; fi # search for the associated fingerprint (should be the very next line) while read fprline; do if [ "${fprline%%:*}" = 'sub' ]; then break; # should never happen elif [ "${fprline%%:*}" != 'fpr' ]; then continue; fi echo "$fprline" | cut -d':' -f 10 done # order in the keyring shouldn't be important done | sort } add_keys_with_verify_against_master_keyring() { ADD_KEYRING="$1" MASTER="$2" if [ ! -f "$ADD_KEYRING" ]; then apt_error "Keyring '$ADD_KEYRING' to be added not found" return fi if [ ! -f "$MASTER" ]; then apt_error "Master-Keyring '$MASTER' not found" return fi # when adding new keys, make sure that the archive-master-keyring # is honored. so: # all keys that are exported must have a valid signature # from a key in the $distro-master-keyring add_keys="$(get_fingerprints_of_keyring "$ADD_KEYRING")" all_add_keys="$(aptkey_execute "$GPG_SH" --keyring "$ADD_KEYRING" --with-colons --list-keys | grep ^[ps]ub | cut -d: -f5)" master_keys="$(aptkey_execute "$GPG_SH" --keyring "$MASTER" --with-colons --list-keys | grep ^pub | cut -d: -f5)" # ensure there are no colisions LP: #857472 for all_add_key in $all_add_keys; do for master_key in $master_keys; do if [ "$all_add_key" = "$master_key" ]; then echo >&2 "Keyid collision for '$all_add_key' detected, operation aborted" return 1 fi done done for add_key in $add_keys; do # export the add keyring one-by-one local TMP_KEYRING="${GPGHOMEDIR}/tmp-keyring.gpg" aptkey_execute "$GPG_SH" --batch --yes --keyring "$ADD_KEYRING" --output "$TMP_KEYRING" --export "$add_key" if ! aptkey_execute "$GPG_SH" --batch --yes --keyring "$TMP_KEYRING" --import "$MASTER" > "${GPGHOMEDIR}/gpgoutput.log" 2>&1; then cat >&2 "${GPGHOMEDIR}/gpgoutput.log" false fi # check if signed with the master key and only add in this case ADDED=0 for master_key in $master_keys; do if aptkey_execute "$GPG_SH" --keyring "$TMP_KEYRING" --check-sigs --with-colons "$add_key" \ | grep '^sig:!:' | cut -d: -f5 | grep -q "$master_key"; then aptkey_execute "$GPG_SH" --batch --yes --keyring "$ADD_KEYRING" --export "$add_key" \ | aptkey_execute "$GPG" --batch --yes --import ADDED=1 fi done if [ $ADDED = 0 ]; then echo >&2 "Key '$add_key' not added. It is not signed with a master key" fi rm -f "${TMP_KEYRING}" done } # update the current archive signing keyring from a network URI # the archive-keyring keys needs to be signed with the master key # (otherwise it does not make sense from a security POV) net_update() { local APT_DIR='/' eval $(apt-config shell APT_DIR Dir) # Disabled for now as code is insecure (LP: #1013639 (and 857472, 1013128)) APT_KEY_NET_UPDATE_ENABLED="" eval $(apt-config shell APT_KEY_NET_UPDATE_ENABLED APT::Key::Net-Update-Enabled) if [ -z "$APT_KEY_NET_UPDATE_ENABLED" ]; then exit 1 fi if [ -z "$ARCHIVE_KEYRING_URI" ]; then apt_error 'Your distribution is not supported in net-update as no uri for the archive-keyring is set' exit 1 fi # in theory we would need to depend on wget for this, but this feature # isn't usable in debian anyway as we have no keyring uri nor a master key if ! command_available 'wget'; then apt_error 'wget is required for a network-based update, but it is not installed' exit 1 fi if [ ! -d "${APT_DIR}/var/lib/apt/keyrings" ]; then mkdir -p "${APT_DIR}/var/lib/apt/keyrings" fi keyring="${APT_DIR}/var/lib/apt/keyrings/$(basename "$ARCHIVE_KEYRING_URI")" old_mtime=0 if [ -e $keyring ]; then old_mtime=$(stat -c %Y "$keyring") fi (cd "${APT_DIR}/var/lib/apt/keyrings"; wget --timeout=90 -q -N "$ARCHIVE_KEYRING_URI") if [ ! -e "$keyring" ]; then return fi new_mtime=$(stat -c %Y "$keyring") if [ $new_mtime -ne $old_mtime ]; then aptkey_echo "Checking for new archive signing keys now" add_keys_with_verify_against_master_keyring "$keyring" "$MASTER_KEYRING" fi } update() { if [ -z "$APT_KEY_DONT_WARN_ON_DANGEROUS_USAGE" ]; then echo >&2 "Warning: 'apt-key update' is deprecated and should not be used anymore!" if [ -z "$ARCHIVE_KEYRING" ]; then echo >&2 "Note: In your distribution this command is a no-op and can therefore be removed safely." exit 0 fi fi if [ ! -f "$ARCHIVE_KEYRING" ]; then apt_error "Can't find the archive-keyring (Is the debian-archive-keyring package installed?)" exit 1 fi # add new keys from the package; # we do not use add_keys_with_verify_against_master_keyring here, # because "update" is run on regular package updates. A # attacker might as well replace the master-archive-keyring file # in the package and add his own keys. so this check wouldn't # add any security. we *need* this check on net-update though import_keyring_into_keyring "$ARCHIVE_KEYRING" '' && cat "${GPGHOMEDIR}/gpgoutput.log" if [ -r "$REMOVED_KEYS" ]; then # remove no-longer supported/used keys get_fingerprints_of_keyring "$(dearmor_filename "$REMOVED_KEYS")" | while read key; do foreach_keyring_do 'remove_key_from_keyring' "$key" done else apt_warn "Removed keys keyring '$REMOVED_KEYS' missing or not readable" fi } remove_key_from_keyring() { local KEYRINGFILE="$1" shift # non-existent keyrings have by definition no keys if [ ! -e "$KEYRINGFILE" ]; then return fi local FINGERPRINTS="${GPGHOMEDIR}/keyringfile.keylst" local DEARMOR="$(dearmor_filename "$KEYRINGFILE")" get_fingerprints_of_keyring "$DEARMOR" > "$FINGERPRINTS" for KEY in "$@"; do # strip leading 0x, if present: KEY="$(echo "${KEY#0x}" | tr -d ' ')" # check if the key is in this keyring if ! grep -iq "^[0-9A-F]*${KEY}$" "$FINGERPRINTS"; then continue fi if [ ! -w "$KEYRINGFILE" ]; then apt_warn "Key ${KEY} is in keyring ${KEYRINGFILE}, but can't be removed as it is read only." continue fi # check if it is the only key in the keyring and if so remove the keyring altogether if [ '1' = "$(uniq "$FINGERPRINTS" | wc -l)" ]; then mv -f "$KEYRINGFILE" "${KEYRINGFILE}~" # behave like gpg return fi # we can't just modify pointed to files as these might be in /usr or something local REALTARGET if [ -L "$DEARMOR" ]; then REALTARGET="$(readlink -f "$DEARMOR")" mv -f "$DEARMOR" "${DEARMOR}.dpkg-tmp" cp -a "$REALTARGET" "$DEARMOR" fi # delete the key from the keyring aptkey_execute "$GPG_SH" --keyring "$DEARMOR" --batch --delete-keys --yes "$KEY" if [ -n "$REALTARGET" ]; then # the real backup is the old link, not the copy we made mv -f "${DEARMOR}.dpkg-tmp" "${DEARMOR}~" fi if [ "$DEARMOR" != "$KEYRINGFILE" ]; then mv -f "$KEYRINGFILE" "${KEYRINGFILE}~" create_new_keyring "$KEYRINGFILE" aptkey_execute "$GPG_SH" --keyring "$DEARMOR" --armor --export > "$KEYRINGFILE" fi get_fingerprints_of_keyring "$DEARMOR" > "$FINGERPRINTS" done } accessible_file_exists() { if ! test -s "$1"; then return 1 fi if test -r "$1"; then return 0 fi apt_warn "The key(s) in the keyring $1 are ignored as the file is not readable by user '$USER' executing apt-key." return 1 } is_supported_keyring() { # empty files are always supported if ! test -s "$1"; then return 0 fi local FILEEXT="${1##*.}" if [ "$FILEEXT" = 'gpg' ]; then # 0x98, 0x99 and 0xC6 via octal as hex isn't supported by dashs printf if printf '\231' | cmp -s -n 1 - "$1"; then true elif printf '\230' | cmp -s -n 1 - "$1"; then true elif printf '\306' | cmp -s -n 1 - "$1"; then true else apt_warn "The key(s) in the keyring $1 are ignored as the file has an unsupported filetype." return 1 fi elif [ "$FILEEXT" = 'asc' ]; then true #dearmor_filename will deal with them else # most callers ignore unsupported extensions silently apt_warn "The key(s) in the keyring $1 are ignored as the file has an unsupported filename extension." return 1 fi return 0 } foreach_keyring_do() { local ACTION="$1" shift # if a --keyring was given, just work on this one if [ -n "$FORCED_KEYRING" ]; then $ACTION "$FORCED_KEYRING" "$@" else # otherwise all known keyrings are up for inspection if accessible_file_exists "$TRUSTEDFILE" && is_supported_keyring "$TRUSTEDFILE"; then $ACTION "$TRUSTEDFILE" "$@" fi local TRUSTEDPARTS="/etc/apt/trusted.gpg.d" eval "$(apt-config shell TRUSTEDPARTS Dir::Etc::TrustedParts/d)" if [ -d "$TRUSTEDPARTS" ]; then TRUSTEDPARTS="$(readlink -f "$TRUSTEDPARTS")" local TRUSTEDPARTSLIST="$(cd /; find "$TRUSTEDPARTS" -mindepth 1 -maxdepth 1 \( -name '*.gpg' -o -name '*.asc' \))" for trusted in $(echo "$TRUSTEDPARTSLIST" | sort); do if accessible_file_exists "$trusted" && is_supported_keyring "$trusted"; then $ACTION "$trusted" "$@" fi done fi fi } list_keys_in_keyring() { local KEYRINGFILE="$1" shift # fingerprint and co will fail if key isn't in this keyring aptkey_execute "$GPG_SH" --keyring "$(dearmor_filename "$KEYRINGFILE")" "$@" > "${GPGHOMEDIR}/gpgoutput.log" 2> "${GPGHOMEDIR}/gpgoutput.err" || true if [ ! -s "${GPGHOMEDIR}/gpgoutput.log" ]; then return fi # we fake gpg header here to refer to the real asc file rather than a temp file if [ "${KEYRINGFILE##*.}" = 'asc' ]; then if expr match "$(sed -n '2p' "${GPGHOMEDIR}/gpgoutput.log")" '^-\+$' >/dev/null 2>&1; then echo "$KEYRINGFILE" echo "$KEYRINGFILE" | sed 's#[^-]#-#g' sed '1,2d' "${GPGHOMEDIR}/gpgoutput.log" || true else cat "${GPGHOMEDIR}/gpgoutput.log" fi else cat "${GPGHOMEDIR}/gpgoutput.log" fi if [ -s "${GPGHOMEDIR}/gpgoutput.err" ]; then cat >&2 "${GPGHOMEDIR}/gpgoutput.err" fi } export_key_from_to() { local FROM="$1" local TO="$2" shift 2 if ! aptkey_execute "$GPG_SH" --keyring "$(dearmor_filename "$FROM")" --export "$@" > "$TO" 2> "${GPGHOMEDIR}/gpgoutput.log"; then cat >&2 "${GPGHOMEDIR}/gpgoutput.log" false else chmod 0644 -- "$TO" fi } import_keyring_into_keyring() { local FROM="${1:-${GPGHOMEDIR}/pubring.gpg}" local TO="${2:-${GPGHOMEDIR}/pubring.gpg}" shift 2 rm -f "${GPGHOMEDIR}/gpgoutput.log" # the idea is simple: We take keys from one keyring and copy it to another # we do this with so many checks in between to ensure that WE control the # creation, so we know that the (potentially) created $TO keyring is a # simple keyring rather than a keybox as gpg2 would create it which in turn # can't be read by gpgv. # BEWARE: This is designed more in the way to work with the current # callers, than to have a well defined it would be easy to add new callers to. if [ ! -s "$TO" ]; then if [ -s "$FROM" ]; then if [ -z "$2" ]; then local OPTS if [ "${TO##*.}" = 'asc' ]; then OPTS='--armor' fi export_key_from_to "$(dearmor_filename "$FROM")" "$TO" $OPTS ${1:+"$1"} else create_new_keyring "$TO" fi else create_new_keyring "$TO" fi elif [ -s "$FROM" ]; then local EXPORTLIMIT="$1" if [ -n "$1$2" ]; then shift; fi local DEARMORTO="$(dearmor_filename "$TO")" if ! aptkey_execute "$GPG_SH" --keyring "$(dearmor_filename "$FROM")" --export ${EXPORTLIMIT:+"$EXPORTLIMIT"} \ | aptkey_execute "$GPG_SH" --keyring "$DEARMORTO" --batch --import "$@" > "${GPGHOMEDIR}/gpgoutput.log" 2>&1; then cat >&2 "${GPGHOMEDIR}/gpgoutput.log" false fi if [ "$DEARMORTO" != "$TO" ]; then export_key_from_to "$DEARMORTO" "${DEARMORTO}.asc" --armor if ! cmp -s "$TO" "${DEARMORTO}.asc" 2>/dev/null; then cp -a "$TO" "${TO}~" mv -f "${DEARMORTO}.asc" "$TO" fi fi fi } dearmor_keyring() { # https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=831409#67 # The awk script is more complex through to skip surrounding garbage and # to support multiple keys in one file (old gpgs generate version headers # which get printed with the original and hence result in garbage input for base64 awk '/^-----BEGIN/{ x = 1; } /^$/{ if (x == 1) { x = 2; }; } /^[^=-]/{ if (x == 2) { print $0; }; } /^-----END/{ x = 0; }' | base64 -d } dearmor_filename() { if [ "${1##*.}" = 'asc' ]; then local trusted="${GPGHOMEDIR}/${1##*/}.gpg" if [ -s "$1" ]; then dearmor_keyring < "$1" > "$trusted" fi echo "$trusted" elif [ "${1##*.}" = 'gpg' ]; then echo "$1" elif [ "$(head -n 1 "$1" 2>/dev/null)" = '-----BEGIN PGP PUBLIC KEY BLOCK-----' ]; then local trusted="${GPGHOMEDIR}/${1##*/}.gpg" dearmor_keyring < "$1" > "$trusted" echo "$trusted" else echo "$1" fi } catfile() { cat "$(dearmor_filename "$1")" >> "$2" } merge_all_trusted_keyrings_into_pubring() { # does the same as: # foreach_keyring_do 'import_keys_from_keyring' "${GPGHOMEDIR}/pubring.gpg" # but without using gpg, just cat and find local PUBRING="$(readlink -f "${GPGHOMEDIR}")/pubring.gpg" rm -f "$PUBRING" touch "$PUBRING" foreach_keyring_do 'catfile' "$PUBRING" } import_keys_from_keyring() { import_keyring_into_keyring "$1" "$2" } merge_keys_into_keyrings() { import_keyring_into_keyring "$2" "$1" '' --import-options 'merge-only' } merge_back_changes() { if [ -n "$FORCED_KEYRING" ]; then # if the keyring was forced merge is already done if [ "$FORCED_KEYRING" != "$TRUSTEDFILE" ]; then mv -f "$FORCED_KEYRING" "${FORCED_KEYRING}~" export_key_from_to "$TRUSTEDFILE" "$FORCED_KEYRING" --armor fi return fi if [ -s "${GPGHOMEDIR}/pubring.gpg" ]; then # merge all updated keys foreach_keyring_do 'merge_keys_into_keyrings' "${GPGHOMEDIR}/pubring.gpg" fi # look for keys which were added or removed get_fingerprints_of_keyring "${GPGHOMEDIR}/pubring.orig.gpg" > "${GPGHOMEDIR}/pubring.orig.keylst" get_fingerprints_of_keyring "${GPGHOMEDIR}/pubring.gpg" > "${GPGHOMEDIR}/pubring.keylst" comm -3 "${GPGHOMEDIR}/pubring.keylst" "${GPGHOMEDIR}/pubring.orig.keylst" > "${GPGHOMEDIR}/pubring.diff" # key isn't part of new keyring, so remove cut -f 2 "${GPGHOMEDIR}/pubring.diff" | while read key; do if [ -z "$key" ]; then continue; fi foreach_keyring_do 'remove_key_from_keyring' "$key" done # key is only part of new keyring, so we need to import it cut -f 1 "${GPGHOMEDIR}/pubring.diff" | while read key; do if [ -z "$key" ]; then continue; fi import_keyring_into_keyring '' "$TRUSTEDFILE" "$key" done } setup_merged_keyring() { if [ -n "$FORCED_KEYID" ]; then merge_all_trusted_keyrings_into_pubring FORCED_KEYRING="${GPGHOMEDIR}/forcedkeyid.gpg" TRUSTEDFILE="${FORCED_KEYRING}" echo "#!/bin/sh exec sh '($(escape_shell "${GPG}")' --keyring '$(escape_shell "${TRUSTEDFILE}")' \"\$@\"" > "${GPGHOMEDIR}/gpg.1.sh" GPG="${GPGHOMEDIR}/gpg.1.sh" # ignore error as this "just" means we haven't found the forced keyid and the keyring will be empty import_keyring_into_keyring '' "$TRUSTEDFILE" "$FORCED_KEYID" || true elif [ -z "$FORCED_KEYRING" ]; then merge_all_trusted_keyrings_into_pubring if [ -r "${GPGHOMEDIR}/pubring.gpg" ]; then cp -a "${GPGHOMEDIR}/pubring.gpg" "${GPGHOMEDIR}/pubring.orig.gpg" else touch "${GPGHOMEDIR}/pubring.gpg" "${GPGHOMEDIR}/pubring.orig.gpg" fi echo "#!/bin/sh exec sh '$(escape_shell "${GPG}")' --keyring '$(escape_shell "${GPGHOMEDIR}/pubring.gpg")' \"\$@\"" > "${GPGHOMEDIR}/gpg.1.sh" GPG="${GPGHOMEDIR}/gpg.1.sh" else TRUSTEDFILE="$(dearmor_filename "$FORCED_KEYRING")" create_new_keyring "$TRUSTEDFILE" echo "#!/bin/sh exec sh '$(escape_shell "${GPG}")' --keyring '$(escape_shell "${TRUSTEDFILE}")' \"\$@\"" > "${GPGHOMEDIR}/gpg.1.sh" GPG="${GPGHOMEDIR}/gpg.1.sh" fi } create_new_keyring() { # gpg defaults to mode 0600 for new keyrings. Create one with 0644 instead. if ! [ -e "$1" ]; then if [ -w "$(dirname "$1")" ]; then touch -- "$1" chmod 0644 -- "$1" fi fi } aptkey_execute() { sh "$@"; } usage() { echo "Usage: apt-key [--keyring file] [command] [arguments]" echo echo "Manage apt's list of trusted keys" echo echo " apt-key add <file> - add the key contained in <file> ('-' for stdin)" echo " apt-key del <keyid> - remove the key <keyid>" echo " apt-key export <keyid> - output the key <keyid>" echo " apt-key exportall - output all trusted keys" echo " apt-key update - update keys using the keyring package" echo " apt-key net-update - update keys using the network" echo " apt-key list - list keys" echo " apt-key finger - list fingerprints" echo " apt-key adv - pass advanced options to gpg (download key)" echo echo "If no specific keyring file is given the command applies to all keyring files." } while [ -n "$1" ]; do case "$1" in --keyring) shift if [ -z "$FORCED_KEYRING" -o "$FORCED_KEYRING" = '/dev/null' ]; then TRUSTEDFILE="$1" FORCED_KEYRING="$1" elif [ "$TRUSTEDFILE" = "$FORCED_KEYRING" ]; then create_gpg_home FORCED_KEYRING="${GPGHOMEDIR}/mergedkeyrings.gpg" echo -n '' > "$FORCED_KEYRING" chmod 0644 -- "$FORCED_KEYRING" catfile "$TRUSTEDFILE" "$FORCED_KEYRING" catfile "$1" "$FORCED_KEYRING" else catfile "$1" "$FORCED_KEYRING" fi ;; --keyid) shift if [ -n "$FORCED_KEYID" ]; then apt_error 'Specifying --keyid multiple times is not supported' exit 1 fi FORCED_KEYID="$1" ;; --secret-keyring) shift FORCED_SECRET_KEYRING="$1" ;; --readonly) merge_back_changes() { true; } create_new_keyring() { if [ ! -r "$FORCED_KEYRING" ]; then TRUSTEDFILE='/dev/null'; FORCED_KEYRING="$TRUSTEDFILE"; fi; } ;; --fakeroot) requires_root() { true; } ;; --quiet) aptkey_echo() { true; } ;; --debug1) # some cmds like finger redirect stderr to /dev/null ⦠aptkey_execute() { echo 'EXEC:' "$@"; sh "$@"; } ;; --debug2) # ⦠other more complicated ones pipe gpg into gpg. aptkey_execute() { echo >&2 'EXEC:' "$@"; sh "$@"; } ;; --homedir) # force usage of a specific homedir instead of creating a temporary shift GPGHOMEDIR="$1" ;; --*) echo >&2 "Unknown option: $1" usage exit 1;; *) break;; esac shift done if [ -z "$TRUSTEDFILE" ]; then TRUSTEDFILE="/etc/apt/trusted.gpg" eval $(apt-config shell TRUSTEDFILE Apt::GPGV::TrustedKeyring) eval $(apt-config shell TRUSTEDFILE Dir::Etc::Trusted/f) if [ "$APT_KEY_NO_LEGACY_KEYRING" ]; then TRUSTEDFILE="/dev/null" fi fi command="$1" if [ -z "$command" ]; then usage exit 1 fi shift prepare_gpg_home() { # crude detection if we are called from a maintainerscript where the # package depends on gnupg or not. We accept recommends here as # well as the script hopefully uses apt-key optionally then like e.g. # debian-archive-keyring for (upgrade) cleanup did if [ -n "$DPKG_MAINTSCRIPT_PACKAGE" ] && [ -z "$APT_KEY_DONT_WARN_ON_DANGEROUS_USAGE" ]; then if ! dpkg-query --show --showformat '${Pre-Depends}${Depends}${Recommends}\n' "$DPKG_MAINTSCRIPT_PACKAGE" 2>/dev/null | grep -E -q 'gpg|gnupg'; then cat >&2 <<EOF Warning: The $DPKG_MAINTSCRIPT_NAME maintainerscript of the package $DPKG_MAINTSCRIPT_PACKAGE Warning: seems to use apt-key (provided by apt) without depending on gpg, gnupg, or gnupg2. Warning: This will BREAK in the future and should be fixed by the package maintainer(s). Note: Check first if apt-key functionality is needed at all - it probably isn't! EOF fi fi eval "$(apt-config shell GPG_EXE Apt::Key::gpgcommand)" if [ -n "$GPG_EXE" ] && command_available "$GPG_EXE"; then true elif command_available 'gpg'; then GPG_EXE="gpg" elif command_available 'gpg2'; then GPG_EXE="gpg2" elif command_available 'gpg1'; then GPG_EXE="gpg1" else apt_error 'gnupg, gnupg2 and gnupg1 do not seem to be installed, but one of them is required for this operation' exit 255 fi create_gpg_home # now tell gpg that it shouldn't try to maintain this trustdb file echo "#!/bin/sh exec '$(escape_shell "${GPG_EXE}")' --ignore-time-conflict --no-options --no-default-keyring \\ --homedir '$(escape_shell "${GPGHOMEDIR}")' --no-auto-check-trustdb --trust-model always \"\$@\"" > "${GPGHOMEDIR}/gpg.0.sh" GPG_SH="${GPGHOMEDIR}/gpg.0.sh" GPG="$GPG_SH" # create the trustdb with an (empty) dummy keyring # older gpgs required it, newer gpgs even warn that it isn't needed, # but require it nonetheless for some commands, so we just play safe # here for the foreseeable future and create a dummy one touch "${GPGHOMEDIR}/empty.gpg" if ! "$GPG_EXE" --ignore-time-conflict --no-options --no-default-keyring \ --homedir "$GPGHOMEDIR" --quiet --check-trustdb --keyring "${GPGHOMEDIR}/empty.gpg" >"${GPGHOMEDIR}/gpgoutput.log" 2>&1; then cat >&2 "${GPGHOMEDIR}/gpgoutput.log" false fi # We don't usually need a secret keyring, of course, but # for advanced operations, we might really need a secret keyring after all if [ -n "$FORCED_SECRET_KEYRING" ] && [ -r "$FORCED_SECRET_KEYRING" ]; then if ! aptkey_execute "$GPG" -v --batch --import "$FORCED_SECRET_KEYRING" >"${GPGHOMEDIR}/gpgoutput.log" 2>&1; then # already imported keys cause gpg1 to fail for some reason⦠ignore this error if ! grep -q 'already in secret keyring' "${GPGHOMEDIR}/gpgoutput.log"; then cat >&2 "${GPGHOMEDIR}/gpgoutput.log" false fi fi else # and then, there are older versions of gpg which panic and implode # if there isn't one available - and writeable for imports # and even if not output is littered with the creation of a secring, # so lets call import once to have it create what it wants in silence echo -n | aptkey_execute "$GPG" --batch --import >/dev/null 2>&1 || true fi } warn_on_script_usage() { if [ -n "$APT_KEY_DONT_WARN_ON_DANGEROUS_USAGE" ]; then return fi # (Maintainer) scripts should not be using apt-key if [ -n "$DPKG_MAINTSCRIPT_PACKAGE" ]; then echo >&2 "Warning: apt-key should not be used in scripts (called from $DPKG_MAINTSCRIPT_NAME maintainerscript of the package ${DPKG_MAINTSCRIPT_PACKAGE})" fi echo >&2 "Warning: apt-key is deprecated. Manage keyring files in trusted.gpg.d instead (see apt-key(8))." } warn_outside_maintscript() { # In del, we want to warn in interactive use, but not inside maintainer # scripts, so as to give people a chance to migrate keyrings. # # FIXME: We should always warn starting in 2022. if [ -z "$DPKG_MAINTSCRIPT_PACKAGE" ]; then echo >&2 "Warning: apt-key is deprecated. Manage keyring files in trusted.gpg.d instead (see apt-key(8))." fi } if [ "$command" != 'help' ] && [ "$command" != 'verify' ]; then prepare_gpg_home fi case "$command" in add) warn_on_script_usage requires_root setup_merged_keyring aptkey_execute "$GPG" --quiet --batch --import "$@" merge_back_changes aptkey_echo "OK" ;; del|rm|remove) # no script warning here as removing 'add' usage needs 'del' for cleanup warn_outside_maintscript requires_root foreach_keyring_do 'remove_key_from_keyring' "$@" aptkey_echo "OK" ;; update) warn_on_script_usage requires_root setup_merged_keyring update merge_back_changes ;; net-update) warn_on_script_usage requires_root setup_merged_keyring net_update merge_back_changes ;; list|finger*) warn_on_script_usage foreach_keyring_do 'list_keys_in_keyring' --fingerprint "$@" ;; export|exportall) warn_on_script_usage merge_all_trusted_keyrings_into_pubring aptkey_execute "$GPG_SH" --keyring "${GPGHOMEDIR}/pubring.gpg" --armor --export "$@" ;; adv*) warn_on_script_usage setup_merged_keyring aptkey_echo "Executing: $GPG" "$@" aptkey_execute "$GPG" "$@" merge_back_changes ;; verify) GPGV='' eval $(apt-config shell GPGV Apt::Key::gpgvcommand) if [ -n "$GPGV" ] && command_available "$GPGV"; then true; elif command_available 'gpgv'; then GPGV='gpgv'; elif command_available 'gpgv2'; then GPGV='gpgv2'; elif command_available 'gpgv1'; then GPGV='gpgv1'; else apt_error 'gpgv, gpgv2 or gpgv1 required for verification, but neither seems installed' exit 29 fi # for a forced keyid we need gpg --export, so full wrapping required if [ -n "$FORCED_KEYID" ]; then prepare_gpg_home else create_gpg_home fi setup_merged_keyring if [ -n "$FORCED_KEYRING" ]; then "$GPGV" --homedir "${GPGHOMEDIR}" --keyring "$(dearmor_filename "${FORCED_KEYRING}")" --ignore-time-conflict "$@" else "$GPGV" --homedir "${GPGHOMEDIR}" --keyring "${GPGHOMEDIR}/pubring.gpg" --ignore-time-conflict "$@" fi ;; help) usage ;; *) usage exit 1 ;; esac
Upload File
Create Folder