[PATCH v2] 2026-04-29-portage-default-binpkg-verification: new news item

Sam James <[email protected]>
Newsgroups gmane.linux.gentoo.devel
Message-ID <2646b832a5e47cb4524c1ec9e5246df46882641e.1777427045.git.sam@gentoo.org>
Warn users running their own binary hosts that they will need to either
start signing binary packages or disable verification explicitly.

Bug: https://bugs.gentoo.org/930730
Bug: https://bugs.gentoo.org/945384
Bug: https://bugs.gentoo.org/945385
Bug: https://bugs.gentoo.org/969086
Signed-off-by: Sam James <[email protected]>
---
v2: Talk about location changes too, which were required for the verification
    change.

 .../2026-04-29-portage-binpkg-changes.en.txt  | 64 +++++++++++++++++++
 1 file changed, 64 insertions(+)
 create mode 100644 2026-04-29-portage-binpkg-changes/2026-04-29-portage-binpkg-changes.en.txt

diff --git a/2026-04-29-portage-binpkg-changes/2026-04-29-portage-binpkg-changes.en.txt b/2026-04-29-portage-binpkg-changes/2026-04-29-portage-binpkg-changes.en.txt
new file mode 100644
index 0000000..f281602
--- /dev/null
+++ b/2026-04-29-portage-binpkg-changes/2026-04-29-portage-binpkg-changes.en.txt
@@ -0,0 +1,64 @@
+Title: Portage binpkg changes
+Author: Sam James <[email protected]>
+Posted: 2026-04-29
+Revision: 1
+News-Item-Format: 2.0
+
+Newer versions of Portage are making two changes to how binary packages
+work:
+1) binary package signatures are now verified by default [0];
+2) fetched binary packages are stored separately from locally-built binaries
+   (this change is already in a recent Portage release) [1].
+
+  Remote binary packages are now cached in /var/cache/binhost/NAME where
+  NAME is given by the configuration item in /etc/portage/binrepos.conf. This
+  allows clean separation of locally built binary packages vs. those with
+  remote provenance, and to allow verification of fetched packages without
+  forcing signing to be set up for local binpkgs.
+
+  The cache location can be customised by setting `location` in binrepos.conf.
+  gentoolkit has been updated to handle these cache locations too.
+
+Official binhost users
+======================
+
+Fetched binary packages are now stored at /var/cache/binhost/gentoo (or a
+similar path, depending on contents of /etc/portage/binrepos.conf/*).
+
+No action is required, for two reasons:
+1) all of the documentation included FEATURES="binpkg-request-signature", and
+2) attempts to install a binpkg that is signed without any configuration
+   would fail early.
+
+The only impact is that future binary package installs will need less
+setup.
+
+Users of just the official binary host can stop reading at this point.
+
+Custom binhosts
+===============
+
+Users who host their own binary packages and redistribute them to their
+machines will need to either:
+1) start signing their binpkgs [2], or
+2) set `verify-signature = false` in /etc/portage/binrepos.conf/* for
+   the relevant configuration file for your binhost.
+
+Otherwise, fetched binpkgs will fail verification.
+
+To set up signing for binpkgs, a signing keyring must reside (by default)
+at /root/.gnupg and a verification keyring must reside (by default)
+at /etc/portage/gnupg. The verification keyring must mark the signing
+key as trusted. Signing is toggled by FEATURES="binpkg-signing".
+
+You can opt-in to this change early by setting `verify-signature = true`
+in /etc/portage/binrepos.conf/* for each binary repository configured, or
+under the special '[DEFAULT]' section.
+
+This does not apply if your binhost uses the old XPAK binary package
+format, but we encourage switching to BINPKG_FORMAT="gpkg" if that is
+the case.
+
+[0] https://bugs.gentoo.org/945384
+[1] https://bugs.gentoo.org/945385
+[2] https://wiki.gentoo.org/wiki/Binary_package_guide#Binary_package_OpenPGP_signing

base-commit: 841acfa1f5709b242ce24d1ac88293bae9e9227b
-- 
2.54.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.