Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 3 additions & 5 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -221,7 +221,8 @@ jobs:
cd artifacts
for file in ./*; do
[ -f "$file" ] || continue
sha256sum "$file" | sed "s|.*/||" > "${file}.sha256"
sha256sum "$file" > "${file}.sha256"
sha256sum --check "${file}.sha256"
done
cat -- ./*.sha256

Expand Down Expand Up @@ -257,13 +258,10 @@ jobs:
- name: Verify remote tag after publication
env:
ATTEST_BIN: ${{ steps.attest.outputs.binary }}
GITHUB_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ needs.provenance.outputs.tag }}
RELEASE_COMMIT: ${{ needs.provenance.outputs.commit }}
run: |
authorization="$(printf 'x-access-token:%s' "$GITHUB_TOKEN" | base64)"
git -c "http.https://github.com/.extraheader=AUTHORIZATION: basic ${authorization}" \
fetch --force origin \
git fetch --force origin \
"refs/tags/${RELEASE_TAG}:refs/tags/${RELEASE_TAG}"
./Scripts/release-provenance-gate.sh \
"$RELEASE_TAG" "$RELEASE_COMMIT"
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,13 @@
"timestamp": 1785303960,
"digest": "88f806418c29a76c109b528f669ea49b8ecef20b3bfab2d16fb8a15626339ff3",
"note": "Refreshed after adding the provenance regression contract to affected paths."
},
{
"gate": "definition",
"actor": "codex",
"timestamp": 1785331046,
"digest": "bcc2722fe679c60135b60195f92a084146a758b34a1a1d38cebe7bebfb02d439",
"note": "Refreshed after expanding the release recovery contract to validate checksum sidecars."
}
],
"reopenings": []
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,8 @@ Fix release workflow fetch authentication so signed tags and attest notes can be

## Acceptance Criteria

- Release fetches use one checkout-managed credential, the release distribution contract rejects manual duplicate Authorization headers, and a v1.1.0 workflow dispatch passes provenance.
- Release fetches use one checkout-managed credential, the release distribution contract rejects manual duplicate Authorization headers, generated checksum sidecars begin with valid SHA-256 digests, and a v1.1.0 workflow dispatch passes through publication.

## No-spec Rationale

This repairs CI authentication plumbing without changing the aps CLI contract or release artifact semantics.
This repairs CI authentication and checksum-generation plumbing without changing the aps CLI contract or release artifact semantics.
Original file line number Diff line number Diff line change
Expand Up @@ -19,9 +19,9 @@
".specsync/change-sequence.json"
],
"no_spec_change": true,
"no_spec_change_rationale": "This repairs CI authentication plumbing without changing the aps CLI contract or release artifact semantics.",
"no_spec_change_rationale": "This repairs CI authentication and checksum-generation plumbing without changing the aps CLI contract or release artifact semantics.",
"acceptance_criteria": [
"Release fetches use one checkout-managed credential, the release distribution contract rejects manual duplicate Authorization headers, and a v1.1.0 workflow dispatch passes provenance."
"Release fetches use one checkout-managed credential, the release distribution contract rejects manual duplicate Authorization headers, generated checksum sidecars begin with valid SHA-256 digests, and a v1.1.0 workflow dispatch passes through publication."
],
"selected_artifacts": [
"context",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@ artifact: tasks

- [x] Replace manual Authorization headers with checkout-managed credentials.
- [x] Add a regression contract for the release authentication configuration.
- [x] Generate and validate complete SHA-256 sidecars for release assets.
- [x] Run the local verification lane.
- [ ] Merge the repair and dispatch the existing v1.1.0 tag.
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,9 @@ artifact: testing
# Testing

- `Scripts/test-release-distribution.sh` asserts both release checkouts persist
their job credential and rejects manual Authorization-header construction.
their job credential, rejects manual Authorization-header construction, and
exercises the checksum sidecar format consumed by the formula updater.
- `fledge lanes run verify` exercises the release distribution contract.
- A `workflow_dispatch` run for `v1.1.0` proves tag, default-branch, and attest
note fetches succeed on the GitHub-hosted runner.
note fetches succeed on the GitHub-hosted runner and replaces the release
assets with verified checksum sidecars.
17 changes: 16 additions & 1 deletion Scripts/test-release-distribution.sh
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,22 @@ grep -Fq 'APS_VERSION="${RELEASE_TAG#v}"' "$workflow"
grep -Fq 'test "$RELEASE_TAG" = "v$(cat VERSION)"' "$workflow"
grep -Fq 'test "$("$BIN_DIR/aps" --version)" = "${RELEASE_TAG#v}"' "$workflow"
test "$(grep -c 'persist-credentials: true' "$workflow")" -eq 2
! grep -Fq 'authorization="$(printf' "$workflow"
if grep -Fq 'authorization="$(printf' "$workflow"; then
echo "release workflow constructs a manual Authorization header" >&2
exit 1
fi
grep -Fq 'sha256sum "$file" > "${file}.sha256"' "$workflow"
grep -Fq 'sha256sum --check "${file}.sha256"' "$workflow"

checksum_fixture="$fixture_root/checksum-fixture"
printf 'aps release fixture\n' > "$checksum_fixture"
sha256sum "$checksum_fixture" > "$checksum_fixture.sha256"
sha256sum --check "$checksum_fixture.sha256"
checksum_value="$(awk '{print $1}' "$checksum_fixture.sha256")"
if [[ ! "$checksum_value" =~ ^[0-9a-f]{64}$ ]]; then
echo "release checksum sidecar does not begin with a SHA-256 digest" >&2
exit 1
fi
grep -Fq 'fetch aps-linux-x86_64-portable.tar.gz' "$formula_workflow"
grep -Fq 'Scripts/render-homebrew-formula.py' "$formula_workflow"
grep -Fq 'Homebrew formula updates require a stable SemVer tag' "$formula_workflow"
Expand Down
14 changes: 8 additions & 6 deletions Scripts/test-release-provenance.sh
Original file line number Diff line number Diff line change
Expand Up @@ -284,15 +284,17 @@ grep -Fq 'needs: [provenance, test]' "$workflow"
grep -Fq "environment: release" "$workflow"
grep -Fq "git merge-base --is-ancestor" "$workflow"
grep -Fq "Verify remote tag after publication" "$workflow"
token_env_count="$(grep -Fc 'GITHUB_TOKEN: ${{ github.token }}' "$workflow")"
if [[ "$token_env_count" -ne 1 ]]; then
echo "release provenance contract: only remote tag verification needs an explicit job token" >&2
token_env_count="$(grep -Fc 'GITHUB_TOKEN: ${{ github.token }}' "$workflow" || true)"
if [[ "$token_env_count" -ne 0 ]]; then
echo "release provenance contract: checkout-managed credentials must authenticate all release fetches" >&2
exit 1
fi
# shellcheck disable=SC2016
authenticated_fetch_count="$(grep -Fc 'http.https://github.com/.extraheader=AUTHORIZATION: basic ${authorization}' "$workflow")"
if [[ "$authenticated_fetch_count" -ne 1 ]]; then
echo "release provenance contract: only post-publication verification uses command-scoped authentication" >&2
authenticated_fetch_count="$(
grep -Fc 'http.https://github.com/.extraheader=AUTHORIZATION: basic ${authorization}' "$workflow" || true
)"
if [[ "$authenticated_fetch_count" -ne 0 ]]; then
echo "release provenance contract: release fetches must not construct command-scoped authentication" >&2
exit 1
fi
# shellcheck disable=SC2016
Expand Down
Loading