System message about wrong repositories on system update

Hello,
This night when I wanted to update system, I ve got this message:

zlatic@localhost:~> sudo zypper update
[судо] root password: 
Refreshing service 'openSUSE'.
Looking for gpg keys in repository google-chrome.
  gpgkey=https://dl.google.com/linux/linux_signing_key.pub
Signature verification failed for file 'repomd.xml' from repository 'google-chrome'.

    Note: Signing data enables the recipient to verify that no modifications occurred after the data
    were signed. Accepting data with no, wrong or unknown signature can lead to a corrupted system
    and in extreme cases even to a system compromise.

    Note: File 'repomd.xml' is the repositories master index file. It ensures the integrity of the
    whole repo.

    Warning: This file was modified after it has been signed. This may have been a malicious change,
    so it might not be trustworthy anymore! You should not continue unless you know it's safe.

    Note: This might be a transient issue if the server is in the midst of receiving new data. The
    data file and its signature are two files which must fit together. In case the request hit the
    server in the midst of updating them, the signature verification might fail. After a few
    minutes, when the server has updated its data, it should work again.

Signature verification failed for file 'repomd.xml' from repository 'google-chrome'. Continue? [yes/no] (no): 


What to do? By now, I choose “no”. (in this question, in system message, translated some words from serbian in english; i know you could understand, but I translated it - root password, for exampe)

Thank you for answering my questions.

This might come from temporary connectivity failure. Have you repeated the attempt after a short or longer wait?

Have you had this google-chrome repo enabled and used previously, or did you just add it, and if you just added it, how did you do so?

I also use the Google Chrome repos directly from Google.

The last update I got for Chrome was July 16.

I just now did a “zypper up” … and yes, I see the same error. I will wait and try again later.

...
Signature verification failed for file 'repomd.xml' 
from repository 'google-chrome'. 
Continue? [yes/no] (no): no

Retrieving repository 'google-chrome' metadata ...............................................[error]
Repository 'google-chrome' is invalid.
[google-chrome|https://dl.google.com/linux/chrome/rpm/stable/x86_64] Failed to retrieve new repository metadata.
History:
 - Signature verification failed for repomd.xml
Please check if the URIs defined for this repository are pointing to a valid repository.
Warning: Skipping repository 'google-chrome' because of the above error.
...

I would suggest that you disable the chrome repo. And then update. This should allow you to update everything other than chrome.

Then re-enable the chrome repo after a few days, and try again to see if it has been fixed.

3 Likes

@vajcek … some additional information.

The Chrome version on this Leap (laptop) is:

Version 150.0.7871.128 (Official Build) (64-bit)

.
The Chrome version on my Window 10 (laptop) was:

Version 150.0.7871.130 (Official Build) (64-bit)

About a minute later, Chrome showed a message:
“Please restart Chrome to update to the newest version”.
… which is now (Windows 10):

Version 150.0.7871.182 (Official Build) (64-bit)

.
I should download the current “linux_signing_key.pub” from Google and compare the same file that is already installed.
.

If there is still a problem tomorrow, I might post a thead at the Google Chrome User Forum.
https://support.google.com/chrome/community?hl=en

@vajcek … have you tried to update your Chrome browser today?

I have a thread at Google and have been doing troubleshooting, and so far, still get the same error. So, no update for Chrome on my computer.

Here’s my thread at Google Chrome forum

https://support.google.com/chrome/thread/453694878/chrome-on-linux-os-will-not-update?hl=en

1 Like

There is also a correct bugreport for this issue:

https://issues.chromium.org/issues/537630725

1 Like

My Google Chrome repos have been Disabled until we find the fix.

The Chrome Forum admin who is Replying in that thread, has proposed another possible solution. So, I just now Enabled the Chrome repo. But I have a question.

See the #4 “google-chrome” entry, in the “GPG Check” column. What does “( p)” signify??

All the other entries are labled “(r )”.

#  | Alias                      |Enable|GPG Check|Refrsh| Name  
---+----------------------------+------+---------+------+-------
 1 | Leap_15.6_Main_repo        | Yes  |(r ) Yes |Yes   | Leap 1
 2 | brave-browser              | Yes  |(r ) Yes |Yes   | Brave 
 3 | brave-browser-beta         | Yes  |(r ) Yes |Yes   | Brave 
 
 4 | google-chrome              | Yes  |( p) Yes |Yes   | google

 5 | google-chrome-beta         | No   |----     |----  | google
 6 | google-chrome-unstable     | No   |----     |----  | google
 7 | repo-backports-debug-update| No   |----     |----  | Update
[...]

From man zypper

repos (lr) [options] [repo]…

List all defined repositories or show detailed information about those specified as arguments

The following data can be printed for each repository found on the system: # (repository number), Alias (unique identifier), Name, Enabled (whether the repository is enabled), GPG Check (whether GPG check for repository metadata (r) and/or downloaded rpm packages (p) is enabled), Refresh (whether auto-refresh is enabled for the repository), Priority, Type (repository meta-data type: rpm-md, yast2, plaindir). Which of the data is shown is determined by command line options listed below and the main.repoListColumns setting from zypper.conf. By default, #, Alias, Name, Enabled, GPG Check and Refresh is shown.

1 Like

I tried, but got this:

zlatic@localhost:~> sudo zypper update
[судо] лозинка за корисника root: 
Refreshing service 'openSUSE'.
Looking for gpg keys in repository google-chrome.
  gpgkey=https://dl.google.com/linux/linux_signing_key.pub
Signature verification failed for file 'repomd.xml' from repository 'google-chrome'.

    Note: Signing data enables the recipient to verify that no modifications occurred after the data
    were signed. Accepting data with no, wrong or unknown signature can lead to a corrupted system
    and in extreme cases even to a system compromise.

    Note: File 'repomd.xml' is the repositories master index file. It ensures the integrity of the
    whole repo.

    Warning: This file was modified after it has been signed. This may have been a malicious change,
    so it might not be trustworthy anymore! You should not continue unless you know it's safe.

    Note: This might be a transient issue if the server is in the midst of receiving new data. The
    data file and its signature are two files which must fit together. In case the request hit the
    server in the midst of updating them, the signature verification might fail. After a few
    minutes, when the server has updated its data, it should work again.

Signature verification failed for file 'repomd.xml' from repository 'google-chrome'. Continue? [yes/no] (no): 
Retrieving repository 'google-chrome' metadata ........................................................[error]
Repository 'google-chrome' is invalid.
[google-chrome|https://dl.google.com/linux/chrome/rpm/stable/x86_64] Failed to retrieve new repository metadata.
History:
 - Signature verification failed for repomd.xml
Please check if the URIs defined for this repository are pointing to a valid repository.
Warning: Skipping repository 'google-chrome' because of the above error.
Retrieving repository 'packman' metadata ...............................................................[done]
Building repository 'packman' cache ....................................................................[done]
Some of the repositories have not been refreshed because of an error.
Loading repository data...

The Chromium ticket made progress. A developer replicated the issue and it is assigned and investigated. There should be some more informations shortly.

1 Like

Everyone will continue to see that error until Google fixes it.

The issue is fixed. Everybody can update again.
The issue was (quote from issue tracker):

It appears that the signing script is reusing the aarch64 repository signature for the x86_64 repository.

2 Likes

Update worked !! Appreciate those who assisted.

The following 2 packages are going to be upgraded:
  brave-browser-beta    1.93.120-1 -> 1.94.94-1
  google-chrome-stable  150.0.7871.128-1 -> 150.0.7871.181-1

Couple of minutes ago, I updated system, and it finished successfully. Thanks to all of you who worked to this problem be fixed (sorry if this sentence is confused :slight_smile: ) .

1 Like