]> git.saurik.com Git - apt.git/blobdiff - apt-pkg/deb/debmetaindex.cc
handle weak-security repositories as unauthenticated
[apt.git] / apt-pkg / deb / debmetaindex.cc
index 5b84ea5e8b119205e410671582e18fdd86179937..0c9cde620e048f4299ced4b48e890c4d31212678 100644 (file)
@@ -33,13 +33,13 @@ class APT_HIDDEN debReleaseIndexPrivate                                     /*{{{*/
    public:
    struct APT_HIDDEN debSectionEntry
    {
-      std::string sourcesEntry;
-      std::string Name;
-      std::vector<std::string> Targets;
-      std::vector<std::string> Architectures;
-      std::vector<std::string> Languages;
-      bool UsePDiffs;
-      std::string UseByHash;
+      std::string const sourcesEntry;
+      std::string const Name;
+      std::vector<std::string> const Targets;
+      std::vector<std::string> const Architectures;
+      std::vector<std::string> const Languages;
+      bool const UsePDiffs;
+      std::string const UseByHash;
    };
 
    std::vector<debSectionEntry> DebEntries;
@@ -80,20 +80,19 @@ std::string debReleaseIndex::MetaIndexFile(const char *Type) const
    return _config->FindDir("Dir::State::lists") +
       URItoFileName(MetaIndexURI(Type));
 }
-
-std::string debReleaseIndex::MetaIndexURI(const char *Type) const
+static std::string constructMetaIndexURI(std::string URI, std::string const &Dist, char const * const Type)
 {
-   std::string Res;
-
    if (Dist == "/")
-      Res = URI;
+      ;
    else if (Dist[Dist.size()-1] == '/')
-      Res = URI + Dist;
+      URI += Dist;
    else
-      Res = URI + "dists/" + Dist + "/";
-   
-   Res += Type;
-   return Res;
+      URI += "dists/" + Dist + "/";
+   return URI + Type;
+}
+std::string debReleaseIndex::MetaIndexURI(const char *Type) const
+{
+   return constructMetaIndexURI(URI, Dist, Type);
 }
                                                                        /*}}}*/
 // ReleaseIndex Con- and Destructors                                   /*{{{*/
@@ -153,7 +152,8 @@ static void GetIndexTargetsFor(char const * const Type, std::string const &URI,
       }
       DefKeepCompressedAs += "uncompressed";
    }
-   std::string const NativeArch = _config->Find("APT::Architecture");
+
+   std::vector<std::string> const NativeArchs = { _config->Find("APT::Architecture"), "all" };
    bool const GzipIndex = _config->FindB("Acquire::GzipIndexes", false);
    for (std::vector<debReleaseIndexPrivate::debSectionEntry>::const_iterator E = entries.begin(); E != entries.end(); ++E)
    {
@@ -164,6 +164,7 @@ static void GetIndexTargetsFor(char const * const Type, std::string const &URI,
         std::string const tplMetaKey = APT_T_CONFIG_STR(flatArchive ? "flatMetaKey" : "MetaKey", "");
         std::string const tplShortDesc = APT_T_CONFIG_STR("ShortDescription", "");
         std::string const tplLongDesc = "$(SITE) " + APT_T_CONFIG_STR(flatArchive ? "flatDescription" : "Description", "");
+        std::string const tplIdentifier = APT_T_CONFIG_STR("Identifier", *T);
         bool const IsOptional = APT_T_CONFIG_BOOL("Optional", true);
         bool const KeepCompressed = APT_T_CONFIG_BOOL("KeepCompressed", GzipIndex);
         bool const DefaultEnabled = APT_T_CONFIG_BOOL("DefaultEnabled", true);
@@ -171,6 +172,7 @@ static void GetIndexTargetsFor(char const * const Type, std::string const &URI,
         std::string const UseByHash = APT_T_CONFIG_STR("By-Hash", E->UseByHash);
         std::string const CompressionTypes = APT_T_CONFIG_STR("CompressionTypes", DefCompressionTypes);
         std::string KeepCompressedAs = APT_T_CONFIG_STR("KeepCompressedAs", "");
+        std::string const FallbackOf = APT_T_CONFIG_STR("Fallback-Of", "");
 #undef APT_T_CONFIG_BOOL
 #undef APT_T_CONFIG_STR
         if (tplMetaKey.empty())
@@ -206,113 +208,125 @@ static void GetIndexTargetsFor(char const * const Type, std::string const &URI,
 
            for (std::vector<std::string>::const_iterator A = E->Architectures.begin(); A != E->Architectures.end(); ++A)
            {
-              // available in templates
-              std::map<std::string, std::string> Options;
-              Options.insert(std::make_pair("SITE", Site));
-              Options.insert(std::make_pair("RELEASE", Release));
-              if (tplMetaKey.find("$(COMPONENT)") != std::string::npos)
-                 Options.insert(std::make_pair("COMPONENT", E->Name));
-              if (tplMetaKey.find("$(LANGUAGE)") != std::string::npos)
-                 Options.insert(std::make_pair("LANGUAGE", *L));
-              if (tplMetaKey.find("$(ARCHITECTURE)") != std::string::npos)
-                 Options.insert(std::make_pair("ARCHITECTURE", *A));
-              else if (tplMetaKey.find("$(NATIVE_ARCHITECTURE)") != std::string::npos)
-                 Options.insert(std::make_pair("ARCHITECTURE", NativeArch));
-              if (tplMetaKey.find("$(NATIVE_ARCHITECTURE)") != std::string::npos)
-                 Options.insert(std::make_pair("NATIVE_ARCHITECTURE", NativeArch));
-
-              std::string MetaKey = tplMetaKey;
-              std::string ShortDesc = tplShortDesc;
-              std::string LongDesc = tplLongDesc;
-              for (std::map<std::string, std::string>::const_iterator O = Options.begin(); O != Options.end(); ++O)
+              for (auto const &NativeArch: NativeArchs)
               {
-                 MetaKey = SubstVar(MetaKey, std::string("$(") + O->first + ")", O->second);
-                 ShortDesc = SubstVar(ShortDesc, std::string("$(") + O->first + ")", O->second);
-                 LongDesc = SubstVar(LongDesc, std::string("$(") + O->first + ")", O->second);
-              }
+                 constexpr static auto BreakPoint = "$(NATIVE_ARCHITECTURE)";
+                 // available in templates
+                 std::map<std::string, std::string> Options;
+                 Options.insert(std::make_pair("SITE", Site));
+                 Options.insert(std::make_pair("RELEASE", Release));
+                 if (tplMetaKey.find("$(COMPONENT)") != std::string::npos)
+                    Options.insert(std::make_pair("COMPONENT", E->Name));
+                 if (tplMetaKey.find("$(LANGUAGE)") != std::string::npos)
+                    Options.insert(std::make_pair("LANGUAGE", *L));
+                 if (tplMetaKey.find("$(ARCHITECTURE)") != std::string::npos)
+                    Options.insert(std::make_pair("ARCHITECTURE", *A));
+                 else if (tplMetaKey.find("$(NATIVE_ARCHITECTURE)") != std::string::npos)
+                    Options.insert(std::make_pair("ARCHITECTURE", NativeArch));
+                 if (tplMetaKey.find("$(NATIVE_ARCHITECTURE)") != std::string::npos)
+                    Options.insert(std::make_pair("NATIVE_ARCHITECTURE", NativeArch));
+
+                 std::string MetaKey = tplMetaKey;
+                 std::string ShortDesc = tplShortDesc;
+                 std::string LongDesc = tplLongDesc;
+                 std::string Identifier = tplIdentifier;
+                 for (std::map<std::string, std::string>::const_iterator O = Options.begin(); O != Options.end(); ++O)
+                 {
+                    std::string const varname = "$(" + O->first + ")";
+                    MetaKey = SubstVar(MetaKey, varname, O->second);
+                    ShortDesc = SubstVar(ShortDesc, varname, O->second);
+                    LongDesc = SubstVar(LongDesc, varname, O->second);
+                    Identifier = SubstVar(Identifier, varname, O->second);
+                 }
 
-              {
-                 auto const dup = std::find_if(IndexTargets.begin(), IndexTargets.end(), [&](IndexTarget const &IT) {
-                    return MetaKey == IT.MetaKey && baseURI == IT.Option(IndexTarget::BASE_URI) &&
-                       E->sourcesEntry == IT.Option(IndexTarget::SOURCESENTRY) && *T == IT.Option(IndexTarget::CREATED_BY);
-                 });
-                 if (dup != IndexTargets.end())
                  {
-                    if (tplMetaKey.find("$(ARCHITECTURE)") == std::string::npos)
-                       break;
-                    continue;
+                    auto const dup = std::find_if(IndexTargets.begin(), IndexTargets.end(), [&](IndexTarget const &IT) {
+                       return MetaKey == IT.MetaKey && baseURI == IT.Option(IndexTarget::BASE_URI) &&
+                          E->sourcesEntry == IT.Option(IndexTarget::SOURCESENTRY) && *T == IT.Option(IndexTarget::CREATED_BY);
+                    });
+                    if (dup != IndexTargets.end())
+                    {
+                       if (tplMetaKey.find(BreakPoint) == std::string::npos)
+                          break;
+                       continue;
+                    }
                  }
-              }
 
-              {
-                 auto const dup = std::find_if(IndexTargets.begin(), IndexTargets.end(), [&](IndexTarget const &IT) {
-                    return MetaKey == IT.MetaKey && baseURI == IT.Option(IndexTarget::BASE_URI) &&
-                       E->sourcesEntry == IT.Option(IndexTarget::SOURCESENTRY) && *T != IT.Option(IndexTarget::CREATED_BY);
-                 });
-                 if (dup != IndexTargets.end())
                  {
-                    std::string const dupT = dup->Option(IndexTarget::CREATED_BY);
-                    std::string const dupEntry = dup->Option(IndexTarget::SOURCESENTRY);
-                    //TRANSLATOR: an identifier like Packages; Releasefile key indicating
-                    // a file like main/binary-amd64/Packages; another identifier like Contents;
-                    // filename and linenumber of the sources.list entry currently parsed
-                    _error->Warning(_("Target %s wants to acquire the same file (%s) as %s from source %s"),
-                          T->c_str(), MetaKey.c_str(), dupT.c_str(), dupEntry.c_str());
-                    if (tplMetaKey.find("$(ARCHITECTURE)") == std::string::npos)
-                       break;
-                    continue;
+                    auto const dup = std::find_if(IndexTargets.begin(), IndexTargets.end(), [&](IndexTarget const &IT) {
+                       return MetaKey == IT.MetaKey && baseURI == IT.Option(IndexTarget::BASE_URI) &&
+                          E->sourcesEntry == IT.Option(IndexTarget::SOURCESENTRY) && *T != IT.Option(IndexTarget::CREATED_BY);
+                       });
+                    if (dup != IndexTargets.end())
+                    {
+                       std::string const dupT = dup->Option(IndexTarget::CREATED_BY);
+                       std::string const dupEntry = dup->Option(IndexTarget::SOURCESENTRY);
+                       //TRANSLATOR: an identifier like Packages; Releasefile key indicating
+                       // a file like main/binary-amd64/Packages; another identifier like Contents;
+                       // filename and linenumber of the sources.list entry currently parsed
+                       _error->Warning(_("Target %s wants to acquire the same file (%s) as %s from source %s"),
+                             T->c_str(), MetaKey.c_str(), dupT.c_str(), dupEntry.c_str());
+                       if (tplMetaKey.find(BreakPoint) == std::string::npos)
+                          break;
+                       continue;
+                    }
                  }
-              }
 
-              {
-                 auto const dup = std::find_if(IndexTargets.begin(), IndexTargets.end(), [&](IndexTarget const &T) {
-                    return MetaKey == T.MetaKey && baseURI == T.Option(IndexTarget::BASE_URI) &&
-                       E->sourcesEntry != T.Option(IndexTarget::SOURCESENTRY);
-                 });
-                 if (dup != IndexTargets.end())
                  {
-                    std::string const dupEntry = dup->Option(IndexTarget::SOURCESENTRY);
-                    //TRANSLATOR: an identifier like Packages; Releasefile key indicating
-                    // a file like main/binary-amd64/Packages; filename and linenumber of
-                    // two sources.list entries
-                    _error->Warning(_("Target %s (%s) is configured multiple times in %s and %s"),
-                          T->c_str(), MetaKey.c_str(), dupEntry.c_str(), E->sourcesEntry.c_str());
-                    if (tplMetaKey.find("$(ARCHITECTURE)") == std::string::npos)
-                       break;
-                    continue;
+                    auto const dup = std::find_if(IndexTargets.begin(), IndexTargets.end(), [&](IndexTarget const &T) {
+                       return MetaKey == T.MetaKey && baseURI == T.Option(IndexTarget::BASE_URI) &&
+                          E->sourcesEntry != T.Option(IndexTarget::SOURCESENTRY);
+                    });
+                    if (dup != IndexTargets.end())
+                    {
+                       std::string const dupEntry = dup->Option(IndexTarget::SOURCESENTRY);
+                       //TRANSLATOR: an identifier like Packages; Releasefile key indicating
+                       // a file like main/binary-amd64/Packages; filename and linenumber of
+                       // two sources.list entries
+                       _error->Warning(_("Target %s (%s) is configured multiple times in %s and %s"),
+                             T->c_str(), MetaKey.c_str(), dupEntry.c_str(), E->sourcesEntry.c_str());
+                       if (tplMetaKey.find(BreakPoint) == std::string::npos)
+                          break;
+                       continue;
+                    }
                  }
-              }
 
-              // not available in templates, but in the indextarget
-              Options.insert(std::make_pair("BASE_URI", baseURI));
-              Options.insert(std::make_pair("REPO_URI", URI));
-              Options.insert(std::make_pair("TARGET_OF", Type));
-              Options.insert(std::make_pair("CREATED_BY", *T));
-              Options.insert(std::make_pair("PDIFFS", UsePDiffs ? "yes" : "no"));
-              Options.insert(std::make_pair("BY_HASH", UseByHash));
-              Options.insert(std::make_pair("DEFAULTENABLED", DefaultEnabled ? "yes" : "no"));
-              Options.insert(std::make_pair("COMPRESSIONTYPES", CompressionTypes));
-              Options.insert(std::make_pair("KEEPCOMPRESSEDAS", KeepCompressedAs));
-              Options.insert(std::make_pair("SOURCESENTRY", E->sourcesEntry));
-
-              bool IsOpt = IsOptional;
-              if (IsOpt == false)
-              {
-                 auto const arch = Options.find("ARCHITECTURE");
-                 if (arch != Options.end() && arch->second == "all")
-                    IsOpt = true;
-              }
+                 // not available in templates, but in the indextarget
+                 Options.insert(std::make_pair("BASE_URI", baseURI));
+                 Options.insert(std::make_pair("REPO_URI", URI));
+                 Options.insert(std::make_pair("IDENTIFIER", Identifier));
+                 Options.insert(std::make_pair("TARGET_OF", Type));
+                 Options.insert(std::make_pair("CREATED_BY", *T));
+                 Options.insert(std::make_pair("FALLBACK_OF", FallbackOf));
+                 Options.insert(std::make_pair("PDIFFS", UsePDiffs ? "yes" : "no"));
+                 Options.insert(std::make_pair("BY_HASH", UseByHash));
+                 Options.insert(std::make_pair("DEFAULTENABLED", DefaultEnabled ? "yes" : "no"));
+                 Options.insert(std::make_pair("COMPRESSIONTYPES", CompressionTypes));
+                 Options.insert(std::make_pair("KEEPCOMPRESSEDAS", KeepCompressedAs));
+                 Options.insert(std::make_pair("SOURCESENTRY", E->sourcesEntry));
+
+                 bool IsOpt = IsOptional;
+                 if (IsOpt == false)
+                 {
+                    auto const arch = Options.find("ARCHITECTURE");
+                    if (arch != Options.end() && arch->second == "all")
+                       IsOpt = true;
+                 }
 
-              IndexTarget Target(
-                    MetaKey,
-                    ShortDesc,
-                    LongDesc,
-                    Options.find("BASE_URI")->second + MetaKey,
-                    IsOpt,
-                    KeepCompressed,
-                    Options
-                    );
-              IndexTargets.push_back(Target);
+                 IndexTarget Target(
+                       MetaKey,
+                       ShortDesc,
+                       LongDesc,
+                       Options.find("BASE_URI")->second + MetaKey,
+                       IsOpt,
+                       KeepCompressed,
+                       Options
+                       );
+                 IndexTargets.push_back(Target);
+
+                 if (tplMetaKey.find(BreakPoint) == std::string::npos)
+                    break;
+              }
 
               if (tplMetaKey.find("$(ARCHITECTURE)") == std::string::npos)
                  break;
@@ -426,23 +440,18 @@ bool debReleaseIndex::Load(std::string const &Filename, std::string * const Erro
       }
    }
 
+   bool AuthPossible = false;
    if(FoundHashSum == false)
-   {
-      if (ErrorText != NULL)
-        strprintf(*ErrorText, _("No Hash entry in Release file %s"), Filename.c_str());
-      return false;
-   }
-   if(FoundStrongHashSum == false)
-   {
-      if (ErrorText != NULL)
-        strprintf(*ErrorText, _("No Hash entry in Release file %s which is considered strong enough for security purposes"), Filename.c_str());
-      return false;
-   }
+      _error->Warning(_("No Hash entry in Release file %s"), Filename.c_str());
+   else if(FoundStrongHashSum == false)
+      _error->Warning(_("No Hash entry in Release file %s which is considered strong enough for security purposes"), Filename.c_str());
+   else
+      AuthPossible = true;
 
    std::string const StrDate = Section.FindS("Date");
    if (RFC1123StrToTime(StrDate.c_str(), Date) == false)
    {
-      _error->Warning( _("Invalid 'Date' entry in Release file %s"), Filename.c_str());
+      _error->Warning( _("Invalid '%s' entry in Release file %s"), "Date", Filename.c_str());
       Date = 0;
    }
 
@@ -463,7 +472,7 @@ bool debReleaseIndex::Load(std::string const &Filename, std::string * const Erro
         if(RFC1123StrToTime(StrValidUntil.c_str(), ValidUntil) == false)
         {
            if (ErrorText != NULL)
-              strprintf(*ErrorText, _("Invalid 'Valid-Until' entry in Release file %s"), Filename.c_str());
+              strprintf(*ErrorText, _("Invalid '%s' entry in Release file %s"), "Valid-Until", Filename.c_str());
            return false;
         }
       }
@@ -498,8 +507,36 @@ bool debReleaseIndex::Load(std::string const &Filename, std::string * const Erro
       }
    }
 
-   LoadedSuccessfully = TRI_YES;
-   return true;
+   /* as the Release file is parsed only after it was verified, the Signed-By field
+      does not effect the current, but the "next" Release file */
+   auto Sign = Section.FindS("Signed-By");
+   if (Sign.empty() == false)
+   {
+      std::transform(Sign.begin(), Sign.end(), Sign.begin(), [&](char const c) {
+        return (isspace(c) == 0) ? c : ',';
+      });
+      auto fingers = VectorizeString(Sign, ',');
+      std::transform(fingers.begin(), fingers.end(), fingers.begin(), [&](std::string finger) {
+        std::transform(finger.begin(), finger.end(), finger.begin(), ::toupper);
+        if (finger.length() != 40 || finger.find_first_not_of("0123456789ABCDEF") != std::string::npos)
+        {
+           if (ErrorText != NULL)
+              strprintf(*ErrorText, _("Invalid '%s' entry in Release file %s"), "Signed-By", Filename.c_str());
+           return std::string();
+        }
+        return finger;
+      });
+      if (fingers.empty() == false && std::find(fingers.begin(), fingers.end(), "") == fingers.end())
+      {
+        std::stringstream os;
+        std::copy(fingers.begin(), fingers.end(), std::ostream_iterator<std::string>(os, ","));
+        SignedBy = os.str();
+      }
+   }
+
+   if (AuthPossible)
+      LoadedSuccessfully = TRI_YES;
+   return AuthPossible;
 }
                                                                        /*}}}*/
 metaIndex * debReleaseIndex::UnloadedClone() const                     /*{{{*/
@@ -574,16 +611,15 @@ bool debReleaseIndex::parseSumData(const char *&Start, const char *End,   /*{{{*/
 
 bool debReleaseIndex::GetIndexes(pkgAcquire *Owner, bool const &GetAll)/*{{{*/
 {
-   std::vector<IndexTarget> const targets = GetIndexTargets();
 #define APT_TARGET(X) IndexTarget("", X, MetaIndexInfo(X), MetaIndexURI(X), false, false, std::map<std::string,std::string>())
    pkgAcqMetaClearSig * const TransactionManager = new pkgAcqMetaClearSig(Owner,
-        APT_TARGET("InRelease"), APT_TARGET("Release"), APT_TARGET("Release.gpg"),
-        targets, this);
+        APT_TARGET("InRelease"), APT_TARGET("Release"), APT_TARGET("Release.gpg"), this);
 #undef APT_TARGET
    // special case for --print-uris
    if (GetAll)
-      for (auto const &Target: targets)
-        new pkgAcqIndex(Owner, TransactionManager, Target);
+      for (auto const &Target: GetIndexTargets())
+        if (Target.Option(IndexTarget::FALLBACK_OF).empty())
+           new pkgAcqIndex(Owner, TransactionManager, Target);
 
    return true;
 }
@@ -647,9 +683,18 @@ bool debReleaseIndex::SetSignedBy(std::string const &pSignedBy)
         std::copy(fingers.begin(), fingers.end(), std::ostream_iterator<std::string>(os, ","));
         SignedBy = os.str();
       }
+      // Normalize the string: Remove trailing commas
+      while (SignedBy[SignedBy.size() - 1] == ',')
+        SignedBy.resize(SignedBy.size() - 1);
+   }
+   else {
+      // Only compare normalized strings
+      auto pSignedByView = APT::StringView(pSignedBy);
+      while (pSignedByView[pSignedByView.size() - 1] == ',')
+        pSignedByView = pSignedByView.substr(0, pSignedByView.size() - 1);
+      if (pSignedByView != SignedBy)
+        return _error->Error(_("Conflicting values set for option %s regarding source %s %s: %s != %s"), "Signed-By", URI.c_str(), Dist.c_str(), SignedBy.c_str(), pSignedByView.to_string().c_str());
    }
-   else if (SignedBy != pSignedBy)
-      return _error->Error(_("Conflicting values set for option %s regarding source %s %s"), "Signed-By", URI.c_str(), Dist.c_str());
    return true;
 }
                                                                        /*}}}*/
@@ -869,27 +914,30 @@ class APT_HIDDEN debSLTypeDebian : public pkgSourceList::Type             /*{{{*/
                           std::string const &Dist, std::string const &Section,
                           bool const &IsSrc, std::map<std::string, std::string> const &Options) const
    {
-      debReleaseIndex *Deb = NULL;
-      for (std::vector<metaIndex *>::const_iterator I = List.begin();
-          I != List.end(); ++I)
+      debReleaseIndex * Deb = nullptr;
+      std::string const FileName = URItoFileName(constructMetaIndexURI(URI, Dist, "Release"));
+      for (auto const &I: List)
       {
         // We only worry about debian entries here
-        if (strcmp((*I)->GetType(), "deb") != 0)
+        if (strcmp(I->GetType(), "deb") != 0)
            continue;
 
-        /* This check insures that there will be only one Release file
+        auto const D = dynamic_cast<debReleaseIndex*>(I);
+        if (unlikely(D == nullptr))
+           continue;
+
+        /* This check ensures that there will be only one Release file
            queued for all the Packages files and Sources files it
            corresponds to. */
-        if ((*I)->GetURI() == URI && (*I)->GetDist() == Dist)
+        if (URItoFileName(D->MetaIndexURI("Release")) == FileName)
         {
-           Deb = dynamic_cast<debReleaseIndex*>(*I);
-           if (Deb != NULL)
-              break;
+           Deb = D;
+           break;
         }
       }
 
       // No currently created Release file indexes this entry, so we create a new one.
-      if (Deb == NULL)
+      if (Deb == nullptr)
       {
         Deb = new debReleaseIndex(URI, Dist);
         List.push_back(Deb);
@@ -909,12 +957,40 @@ class APT_HIDDEN debSLTypeDebian : public pkgSourceList::Type             /*{{{*/
         std::map<std::string, std::string>::const_iterator const opt = Options.find(target);
         if (opt == Options.end())
            continue;
-        auto const tarItr = std::find(mytargets.begin(), mytargets.end(), target);
-        bool const optValue = StringToBool(opt->second);
-        if (optValue == true && tarItr == mytargets.end())
-           mytargets.push_back(target);
-        else if (optValue == false && tarItr != mytargets.end())
-           mytargets.erase(std::remove(mytargets.begin(), mytargets.end(), target), mytargets.end());
+        auto const idMatch = [&](std::string const &t) {
+           return target == _config->Find(std::string("Acquire::IndexTargets::") + Name + "::" + t + "::Identifier", t);
+        };
+        if (StringToBool(opt->second))
+           std::copy_if(alltargets.begin(), alltargets.end(), std::back_inserter(mytargets), idMatch);
+        else
+           mytargets.erase(std::remove_if(mytargets.begin(), mytargets.end(), idMatch), mytargets.end());
+      }
+      // if we can't order it in a 1000 steps we give up… probably a cycle
+      for (auto i = 0; i < 1000; ++i)
+      {
+        bool Changed = false;
+        for (auto t = mytargets.begin(); t != mytargets.end(); ++t)
+        {
+           std::string const fallback = _config->Find(std::string("Acquire::IndexTargets::") + Name + "::" + *t + "::Fallback-Of");
+           if (fallback.empty())
+              continue;
+           auto const faller = std::find(mytargets.begin(), mytargets.end(), fallback);
+           if (faller == mytargets.end() || faller < t)
+              continue;
+           Changed = true;
+           auto const tv = *t;
+           mytargets.erase(t);
+           mytargets.emplace_back(tv);
+        }
+        if (Changed == false)
+           break;
+      }
+      // remove duplicates without changing the order (in first appearance)
+      {
+        std::set<std::string> seenOnce;
+        mytargets.erase(std::remove_if(mytargets.begin(), mytargets.end(), [&](std::string const &t) {
+           return seenOnce.insert(t).second == false;
+        }), mytargets.end());
       }
 
       bool UsePDiffs = _config->FindB("Acquire::PDiffs", true);
@@ -956,7 +1032,30 @@ class APT_HIDDEN debSLTypeDebian : public pkgSourceList::Type             /*{{{*/
       std::map<std::string, std::string>::const_iterator const signedby = Options.find("signed-by");
       if (signedby == Options.end())
       {
-        if (Deb->SetSignedBy("") == false)
+        bool alreadySet = false;
+        std::string filename;
+        if (ReleaseFileName(Deb, filename))
+        {
+           auto OldDeb = Deb->UnloadedClone();
+           _error->PushToStack();
+           OldDeb->Load(filename, nullptr);
+           bool const goodLoad = _error->PendingError() == false;
+           _error->RevertToStack();
+           if (goodLoad)
+           {
+              if (OldDeb->GetValidUntil() > 0)
+              {
+                 time_t const invalid_since = time(NULL) - OldDeb->GetValidUntil();
+                 if (invalid_since <= 0)
+                 {
+                    Deb->SetSignedBy(OldDeb->GetSignedBy());
+                    alreadySet = true;
+                 }
+              }
+           }
+           delete OldDeb;
+        }
+        if (alreadySet == false && Deb->SetSignedBy("") == false)
            return false;
       }
       else