cenko.tech

Making apt repository setup fail where the problem is

A Linux bootstrap script kept going when a repo signing key failed to download, so the error showed up later as an unrelated apt failure. Here is the fix.

bootstrap_linux_pc sets up a fresh Fedora or Ubuntu machine with one command. On Ubuntu it adds the Google Chrome and VS Code apt repositories before installing packages from them.

The symptom#

If something goes wrong while adding a repository, you do not find out there. You find out a few steps later, when apt-get update or a package install fails with an error that says nothing about signing keys. I wrote this up as issue #3.

The cause#

Each repository was added like this:

curl -fsSL https://dl.google.com/linux/linux_signing_key.pub \
  | sudo gpg --dearmor -o /usr/share/keyrings/google-chrome.gpg
echo "deb [arch=amd64 signed-by=/usr/share/keyrings/google-chrome.gpg] http://dl.google.com/linux/chrome/deb/ stable main" \
  | sudo tee /etc/apt/sources.list.d/google-chrome.list >/dev/null

Nothing checks whether the key download or the gpg --dearmor step worked. If the download fails, the script carries on and still writes the sources.list.d entry. Apt is now pointed at a repository it has no valid key for, and the failure surfaces later, somewhere else.

The fix#

The pull request splits the job into two functions.

add_apt_repo_key() downloads the key to a temporary file, checks the download succeeded and is not empty, then dearmors it. If dearmoring fails, it removes any partial keyring file:

if ! curl -fsSL "$url" -o "$tmp_key"; then
  err "Failed to download signing key from $url"
  rm -f "$tmp_key"
  return 1
fi

if [[ ! -s "$tmp_key" ]]; then
  err "Downloaded signing key from $url is empty."
  rm -f "$tmp_key"
  return 1
fi

add_apt_repo() only writes the repository file if the key step succeeded. If it did not, it names the repository that failed and skips it, instead of leaving a repo file with no matching key:

if ! add_apt_repo_key "$key_url" "$keyring_path"; then
  warn "Skipping $name repository setup — $name install will be skipped."
  return 1
fi

Both repositories now go through add_apt_repo. The already-configured path and the normal success path behave exactly as before.

How I tested it#

  • bash -n distro/ubuntu.sh for syntax.
  • An Ubuntu 24.04 VM with the key URL blocked through an /etc/hosts entry, to confirm the script now warns and skips cleanly.
  • A normal run on the same VM, to confirm both repositories are still configured.

The general rule: when a step is a prerequisite for later steps, check it where it happens. An error message that names the real cause saves the next person a long search.

cd ~/blog