# Can't upload signed artifacts compressed with LZMA

**URL:** <https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823>\
**Category:** General Discussions\
**Tags:** docker\
**Created:** [July 12, 2019, 3:51pm UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823 "2019-07-12T15:51:46Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ster](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ster/32/282_2.png) [@ster](https://hub.mender.io/u/ster)\
**Post date:** [July 12, 2019, 3:51pm UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/1 "2019-07-12T15:51:46Z")

</div>

I can’t upload signed artifacts via GUI.  
Integration is on V2.0.0 and `mender-artifact` is on v.3.0.1. Artifacts are created using mender-artifact from .ext4. I don’t use `--version` with mender-artifact, so it should use artifact V3 I suppose.

`mender-deplyments` container throws these errors:

> **logs from mender-deplyments**
>
> ```
> time="2019-07-12T14:51:22Z" level=error msg="reading artifact error: readHeaderV3: handleHeaderReads: readHeader: readNext: Failed to copy from tarReader to the writer: unexpected EOF: Cannot parse artifact file" file=images.go func="controller.(*SoftwareImagesController).NewImage" line=239 request_id=bd965f2e-eb8a-41cb-b0b9-564699d67c8f user_id=5ec43064-1fe1-49bd-92b2-c3a7ee220460
> time="2019-07-12T14:51:22Z" level=error msg="reading artifact error: readHeaderV3: handleHeaderReads: readHeader: readNext: Failed to copy from tarReader to the writer: unexpected EOF" file=view.go func="view.(*RESTView).RenderError" line=51 request_id=bd965f2e-eb8a-41cb-b0b9-564699d67c8f user_id=5ec43064-1fe1-49bd-92b2-c3a7ee220460
> 
> ```

The problem only exists with signed artifact. This problematic artifact passes `mender-artifact validate` successfully. If the same artifact is generated without `--key` argument, it can be uploaded without any issue.

I checked [docs about keys](https://docs.mender.io/2.0/administration/certificates-and-keys) and it doesn’t seem that I should somehow provide Server with any artifact keys. What have I missed?

Also, little UX flaw: when this error happens, GUI shows nothing, the upload progress bar just getting stuck at random between 4% and 10%. It should probably notify the user that something went wrong.

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [July 12, 2019, 4:07pm UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/2 "2019-07-12T16:07:45Z")

</div>

Can you share the commands you use to create the Mender Artifact.

I tried to reproduce but was not successful, it uploaded just fine. Though I was using Hosted Mender but should be equivalent to v2.0.0.

 ![Screenshot_2019-07-12_18-06-09](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/1X/09607c761140cb2e789ce2688c785f90a249f2c8.png)

---

<div class="post-metadata">

**Author:** ![ster](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ster/32/282_2.png) [@ster](https://hub.mender.io/u/ster)\
**Post date:** [July 12, 2019, 4:22pm UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/3 "2019-07-12T16:22:57Z")

</div>

Sure:

```
mender-artifact --compression "lzma" write rootfs-image
      --file "$releaseName-mender.ext4"
      --device-type "raspberrypi3" 
      --artifact-name "$releaseName-mender"
      --output-path "$releaseName-mender.mender"
      --script "$scriptsDir/ArtifactInstall_Enter_01_retain_wpa_supplicant"
      --key "$pathToSignKey"

```

The command to generate unsigned artifact is the same but without `--key`. I regenerated signed artifact once again and still have the issue.

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [July 12, 2019, 4:32pm UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/4 "2019-07-12T16:32:56Z")

</div>

Thanks, now I can see it as well. It seems to work if you remove `--compression "lzma"`. Can you confirm this as well?

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [July 12, 2019, 4:43pm UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/5 "2019-07-12T16:43:43Z")

</div>

I created an bug report,

[https://tracker.mender.io/browse/MEN-2645](https://tracker.mender.io/browse/MEN-2645)

---

<div class="post-metadata">

**Author:** ![ster](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ster/32/282_2.png) [@ster](https://hub.mender.io/u/ster)\
**Post date:** [July 13, 2019, 11:33am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/6 "2019-07-13T11:33:55Z")

</div>

> Thanks, now I can see it as well. It seems to work if you remove `--compression "lzma"` . Can you confirm this as well?

I confirm, everything works fine with `gzip`

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [July 16, 2019, 5:44am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/7 "2019-07-16T05:44:29Z")

</div>

@ster, could you give the version of `mender-artifact` that you are using?

---

<div class="post-metadata">

**Author:** ![ster](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ster/32/282_2.png) [@ster](https://hub.mender.io/u/ster)\
**Post date:** [July 16, 2019, 8:45am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/8 "2019-07-16T08:45:39Z")

</div>

As mentioned in the first message, I used `mender-artifact` **V3.0.1** , precompiled Linux binary downloaded from [here](https://d1b0l86ne08fsf.cloudfront.net/mender-artifact/3.0.1/mender-artifact)

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [July 16, 2019, 9:11am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/9 "2019-07-16T09:11:21Z")

</div>

Apologies! That was weak.

However, I am still not able to reproduce this. Downloaded the binary, and ran:

```auto
mender-artifact --compression "lzma" write rootfs-image
      --file test.img
      --device-type "raspberrypi3" 
      --artifact-name release-1
      --output-path test.mender
      --key ~/mendersoftware/integration/keys/deviceauth/private.key

```

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [July 16, 2019, 9:14am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/10 "2019-07-16T09:14:07Z")

</div>

That is with hosted mender, and the demo environment locally.  
I am not doubting that you are having issues, just to be clear, so bear over with me.  
I will have a look at the backend

---

<div class="post-metadata">

**Author:** ![ster](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ster/32/282_2.png) [@ster](https://hub.mender.io/u/ster)\
**Post date:** [July 16, 2019, 9:39am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/11 "2019-07-16T09:39:19Z")

</div>

Maybe the keys are the key? 🙂  
I use RSA with length of 3072 bits

---

<div class="post-metadata">

**Author:** ![ster](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ster/32/282_2.png) [@ster](https://hub.mender.io/u/ster)\
**Post date:** [July 16, 2019, 9:42am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/12 "2019-07-16T09:42:36Z")

</div>

> [@oleorhagen](#):
>
> mender-artifact --compression “lzma” write rootfs-image --file test.img

also I (as well as @mirzak) am generating artifact from .ext4 and not .img, just a note.

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [July 16, 2019, 11:09am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/13 "2019-07-16T11:09:20Z")

</div>

So is the key in the integration repo 😕  
I also, just to be sure, did convert the raw image to an ext4 image, to no avail.  
@kacf, perhaps you have some ideas here?

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [July 16, 2019, 12:10pm UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/14 "2019-07-16T12:10:32Z")

</div>

You are also missing a state script in your command, which the original command had to reproduce

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [July 16, 2019, 3:32pm UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/15 "2019-07-16T15:32:56Z")

</div>

I’ve tried both with and without scripts, still works.  
Tomorrow I will make a bash script to run the whole thing, so that we can standardize this 🙂

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [July 16, 2019, 4:29pm UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/16 "2019-07-16T16:29:30Z")

</div>

For additional reference, when I performed my test I downloaded this image,

[https://d1b0l86ne08fsf.cloudfront.net/2.0.1/raspberrypi3/raspberrypi3\_release\_1\_2.0.1.mender](https://d1b0l86ne08fsf.cloudfront.net/2.0.1/raspberrypi3/raspberrypi3_release_1_2.0.1.mender)

Unpacked it, and then created a Mender Artifact with the mentioned command using the files from the extracted Artifact

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [July 17, 2019, 8:41am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/17 "2019-07-17T08:41:34Z")

</div>

Alright, have a look at this, and if this is the proper workflow, see if it works at yours:  
[https://pastebin.com/rnmsYheZ](https://pastebin.com/rnmsYheZ)

---

<div class="post-metadata">

**Author:** ![ster](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ster/32/282_2.png) [@ster](https://hub.mender.io/u/ster)\
**Post date:** [July 17, 2019, 10:15am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/18 "2019-07-17T10:15:37Z")

</div>

@oleorhagen, I used your script with the only difference that I used GUI instead of `mender-cli` to upload the artifact and the issue is present, with the same logs from `mender-deployments`.

One additional thing is that I have relatively low upload speed with my ISP (1-2 Mbit/s), maybe this could play the role?

Here I uploaded `test.mender` (result of your script) I have issues with, can you try this file?  
[https://we.tl/t-78hBQlwY3b](https://we.tl/t-78hBQlwY3b)

And the key pair:

> **testkey.pub**
>
> ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDEQyJuskzajlaW3Bd8JSYFF6AjH1CgJvSsOugywQOz21nofi2jEm5qpa/rL9+0OUX+7Vw4rIw+3tGIltL43yNylm49TJCn32oWoMjUGXFMzReifD9/ixBb+9QKDC2s8e8MMqYUSM4R0VQbQZedfj+q3pBAxcEUJEdIL6r+nynxy90GCJm+LAQU+F/UQYtKMP8dKTl+0BcSVifKTy1zFVSs16PEjj/ahQTOSZ4tJAuUZ1k2Tq+gfCifAQ+Ke6xxHKK30NGB+G3VkmjvshiI7pQyipBw+9MisWOE9kjpJYLsAYj5mAXy8BuqfiTOzrOtxN1pAvzUTc0MLxxDOYOH3yhzKpQY4wUkTyBxDjpBqTEBDraXIzHUD1+8T4DTNyH8vkctqzHXuFrm8aDjoTNfWFYoRrZY+MuV2IFn1b92Hboz8vqtKgc9S0znnRboVykiX0LfGHe0jCbeZ0J1GN4EqhiFgzZcst52rflKRJqJhfwX1ijhFqj7689m7qcN5XM5EXU= ster@sterPC

> **testkey**
>
> -----BEGIN RSA PRIVATE KEY-----  
> MIIG5AIBAAKCAYEAxEMibrJM2o5WltwXfCUmBRegIx9QoCb0rDroMsEDs9tZ6H4t  
> oxJuaqWv6y/ftDlF/u1cOKyMPt7RiJbS+N8jcpZuPUyQp99qFqDI1BlxTM0Xonw/  
> f4sQW/vUCgwtrPHvDDKmFEjOEdFUG0GXnX4/qt6QQMXBFCRHSC+q/p8p8cvdBgiZ  
> viwEFPhf1EGLSjD/HSk5ftAXElYnyk8tcxVUrNejxI4/2oUEzkmeLSQLlGdZNk6v  
> oHwonwEPinuscRyit9DRgfht1ZJo77IYiO6UMoqQcPvTIrFjhPZI6SWC7AGI+ZgF  
> 8vAbqn4kzs6zrcTdaQL81E3NDC8cQzmDh98ocyqUGOMFJE8gcQ46QakxAQ62lyMx  
> 1A9fvE+A0zch/L5HLasx17ha5vGg46EzX1hWKEa2WPjLldiBZ9W/dh26M/L6rSoH  
> PUtM550W6FcpIl9C3xh3tIwm3mdCdRjeBKoYhYM2XLLedq35SkSaiYX8F9Yo4Rao  
> ++vPZu6nDeVzORF1AgMBAAECggGBAIJLo69j9fvfJYNQKNNFgmE9FxZaMtewJR22  
> mfMgCwo75QuhwUCS+vUYfJsiFFz87QhaorAJda5DlU4d+4A3+7uWPSe7Dgo1G6Rc  
> KBgPsBVxz3ATFsDhHQJERLhK74PytmYdtf6fexd/JlxWBocLis8wpQorf4yUrTIy  
> W05hcqJRWrInwZHsfOVDI7Oxs/yUXLoKZV5YXgjRY+c++4h8r9Nz8giK+79iMheV  
> 7ko/tORYXHTedmCQLROqy5t/kbMic4a5oHE/p6cB41M3KKM2OLYVx5xypc8uMpyG  
> Y6CP/1muaK2EyMiW2lOvG2Gqq5lHmHBiXtfHOHKi2XZYZSlJTH1FHlVLzW3ieu3+  
> YM6EkY83QIMbeOZlBrWpgh9/pdMzRmcu/2jzaUeAvT5sXWF+Gn5wIxmfJsKkL9yb  
> 09m9InoxRkJAvQfULbcPtn3Dla/z5zz2QoFD4pZGD+Ga1lW8HqG0LAIe2i23GDud  
> gZW2AI6DbyhoDai9qghacF+Z2X8koQKBwQDp9mTT/RADOcGjckFYHacjsRslgP/v  
> qsT0/79otapgekm0O8T7JD2fxMD7TDwtdK8wG7S0BjzZqHyOvMW6X52NDKo1UtXh  
> xqZaEbpF/Kd4iDvCrsgLouB3LFnKHnnJYSMuvtZl2r0Hk/BD1JFTzM75xgPG1oLX  
> 1/vsPIQq8jXrY+XDrv+njX8H05hsnjOdpugoEaygC9zp+GoBuUtFD6YXZgenXCm+  
> t+r2BrZ6Vxmx+6lF9ehUvz1lMuzogZeOix0CgcEA1r+p8WF2pcdnL9ni4rV++bY4  
> vi8Ioyp6CwGCdAGtaBdjKayXB1f2SrtfVpJmD9MmjkXwi1RrCrDGbOlED+OFqK+c  
> kqRYIYH1bhC60PSAhUFIFGT/XNgYJVV467/DFzcHBWSkl85FMRkpj0kkX3ynXnPK  
> hn6EWMJVB9R3qJN3G4sJbfePN0NsSg13ghUdb+fP8gPWO5XOlN6mOmndSxg/SfD5  
> FNEL/wNG+vrETw9/lmawUznmUpSKBDOltJJvGPg5AoHADyTFrfsJWEwavoucsylo  
> MiU6jpjk+Axjp0AOkaaAmrIPpzzfKSpVWswPebSbiI2u8Tw53BUzRxtixJJvcfrS  
> ZdjWA5GTCoQjLF1NY05RQLoAtD8/75DhWpViUnTaiTBiaJotonYgGid3O8y8g2IU  
> W5J3mB02ZuYyBj58h5MZ7lyO+LWRErVT7ZvCl/U9fgzZpg5O0CU0bWiI5AesWZID  
> vCv8fta2VQPuj3IryYttvFl/wWmDWkjunmhHcV1CBBX5AoHBANX0qY27rClpLQ6I  
> yDtV1sdWXNxnIfTm6icy/tUzoqA1xO+Na/++DL3SRx+KxrL3jc9sMUev+OHy1A9I  
> rS4jYlR5esbDhKcFwxBBDNAI+k9JhlYDdkT7a7sumEZRjT8A7TbbWf2BXoCXcEe4  
> +MtF977sIJi1TojcPTmK3xkOqzm+4cs1PfQycZ6qIipxfR20WQLn/bbp/6Nk3TsP  
> pJIf+1ZhBtlNmeUeT8bYt2OJrnWbpAuXgTk/ku6ywmLRDm1TSQKBwDfFl6DCNymt  
> 8oXQKoEvlKcTw74KDOkgwdHa/bmO7Pb7jQmEPvbpOFBF67CMI6IdYXxi6uD8Ash0  
> 7A5tloERvfsb9ik69neqVrydFYosppdfQqNSEiYQJC66fKRjBpuckrd1mjeSlfo7  
> bXQt35vtSqVQKc9YTKVWFObuqDhruImfQCfHAGANgHMzfx7PIguUR8co4OwOjgbM  
> isoBpdGFNhwbeqFhSdwSUGAzgaC5kqzvR2ooyiT8xxTjCd0GbN/PAA==  
> -----END RSA PRIVATE KEY-----

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [July 17, 2019, 10:44am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/19 "2019-07-17T10:44:17Z")

</div>

Hmm, that is interesting indeed, cause the artifact you linked uploaded just fine for me.  
I guess this calls for some knowledge from @0lmi

---

<div class="post-metadata">

**Author:** ![0lmi](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/0lmi/32/133_2.png) [@0lmi](https://hub.mender.io/u/0lmi)\
**Post date:** [July 17, 2019, 10:54am UTC](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823/20 "2019-07-17T10:54:59Z")

</div>

> I used your script with the only difference that I used GUI instead of `mender-cli` to upload the artifact

Did you try to use `mender-cli`? Does it work for you?

And how does you infrastructure look like?

[Next page](https://hub.mender.io/t/cant-upload-signed-artifacts-compressed-with-lzma/823.md?page=2)
