3.1 Configuration

A repository is configured by a file naming its base URL and the policy peipkg applies to it.

SettingMeaning
Base URLWhere the descriptor and everything it points at are served from
Trust anchorsExpected key fingerprints, supplied out of band
Signature policyrequired or optional (PSPU §5.37)
PriorityA positive integer; lower is higher priority
Minimum index versionThe out-of-band freshness floor applied at first add
Maximum trusted ageHow long a repository's trust state stays usable without a refresh
Insecure transportWhether a non-HTTPS base URL is permitted for this repository

The default signature policy for a new repository is required. The default maximum trusted age is 30 days. The default priority is the same for every repository, including the official one, so the ordering the resolver applies is whatever the operator configured rather than something peipkg assumes.

An explicit maximum trusted age of zero is rejected rather than treated as "use the default", so that a mistyped value cannot silently disable the freshness check.

3.1.1 The local handle #

A repository has a name in the descriptor and a handle in the local configuration. They are conventionally the same. peipkg identifies a repository internally by the local handle, and compares an index's declared repository name against that handle — so a configuration whose handle differs from the descriptor's name produces a repository that adds successfully and is then skipped at every install, with a warning rather than an error.

3.1.2 Transport #

A base URL is HTTPS unless the repository's insecure-transport setting permits otherwise. The setting is per-repository; there is no global form.

file:// base URLs are accepted for local development. They are exempt from the transport check rather than gated by it, so a repository on removable or network-mounted media is added without the operator acknowledging the transport.

Changing the insecure-transport setting after a repository has been added means editing its configuration file. There is no verb for it, and so no prompt and no audit event accompanies the change.

Edit this page