2025-08-05 11:31:01,225 - oe-selftest - INFO - signing.Signing.test_signing_packages (subunit.RemotedTestCase) 2025-08-05 11:31:01,226 - oe-selftest - INFO - ... FAIL Stderr: 2025-08-05 09:26:36,272 - oe-selftest - INFO - Adding: "include selftest.inc" in /srv/pokybuild/yocto-worker/oe-selftest-fedora/build/build-st-3368757/conf/local.conf 2025-08-05 09:26:36,273 - oe-selftest - INFO - Adding: "include bblayers.inc" in bblayers.conf 2025-08-05 11:31:01,226 - oe-selftest - INFO - 1: 43/58 549/634 (233.48s) (0 failed) (signing.Signing.test_signing_packages) 2025-08-05 11:31:01,226 - oe-selftest - INFO - testtools.testresult.real._StringException: Traceback (most recent call last): File "/srv/pokybuild/yocto-worker/oe-selftest-fedora/build/meta/lib/oeqa/selftest/cases/signing.py", line 113, in test_signing_packages runCmd('%s/rpmkeys --define "_dbpath %s" --import %s' % File "/srv/pokybuild/yocto-worker/oe-selftest-fedora/build/meta/lib/oeqa/utils/commands.py", line 214, in runCmd raise AssertionError("Command '%s' returned non-zero exit status %d:\n%s" % (command, result.status, exc_output)) AssertionError: Command '/srv/pokybuild/yocto-worker/oe-selftest-fedora/build/build-st-3368757/tmp/work/core2-64-poky-linux/ed/1.21.1/recipe-sysroot-native/usr/bin/rpmkeys --define "_dbpath /tmp/oeqa-rpmdbzlvymqxn" --import /srv/pokybuild/yocto-worker/oe-selftest-fedora/build/build-st-3368757/meta-selftest/files/signing/key.pub' returned non-zero exit status 1: error: Certificate 7B31316B5D64AD52: Policy rejects 7B31316B5D64AD52: No binding signature at time 2025-08-05T11:30:40Z error: /srv/pokybuild/yocto-worker/oe-selftest-fedora/build/build-st-3368757/meta-selftest/files/signing/key.pub: key 1 import failed.
oe-selftest-fedora stream9-vk-1 mathieu/master-next completed at 2025-08-05 12:33:50+00:00 https://autobuilder.yoctoproject.org/valkyrie/#/builders/48/builds/2026/steps/14/logs/stdio
This might be related to the valid time stamp range of the generated certificate. In general we should make sure that the first valid date of the certificate is sufficiently in the past such that if the wall clock time on the host changes slightly it won't fall before the first valid date. Generally 24 hours or so should be sufficient to account for most clock discrepancies.
oe-selftest-fedora stream9-vk-1 mathieu/master-next completed at 2025-08-19 08:50:08+00:00 https://autobuilder.yoctoproject.org/valkyrie/#/builders/48/builds/2105/steps/14/logs/stdio
oe-selftest-fedora stream9-vk-1 mathieu/master-next completed at 2025-08-21 11:50:03+00:00 https://autobuilder.yoctoproject.org/valkyrie/#/builders/48/builds/2124/steps/14/logs/stdio
CC Yi who might check on this bug. It hasn't been reported for a while so maybe it's fixed somehow.
Not seen since: 2025-08-21 bump to 6.0 and likely resolve when we clean-up those bugs.
If this recurs we can look at creating certificates with valid from dates 24h in the past.