Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 50 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,16 @@ env:
# Set the VOXCTRL_BUGREPORT_ENDPOINT repository secret to switch it on; see
# scripts/bug-report-relay/README.md.
VOXCTRL_BUGREPORT_ENDPOINT: ${{ secrets.VOXCTRL_BUGREPORT_ENDPOINT }}
# Public half of the update-signing key, baked into every release build so
# its updater refuses any download not signed by the publish job below
# (crates/voxctrl-update/src/signature.rs). Not a secret: it is a repository
# *variable*. Its secret half is the VOXCTRL_UPDATE_SIGNING_KEY secret.
#
# One-time setup (docs/release-signing.md):
# minisign -G -W -p voxctrl-update.pub -s voxctrl-update.key
# variable VOXCTRL_UPDATE_PUBKEY = second line of voxctrl-update.pub
# secret VOXCTRL_UPDATE_SIGNING_KEY = contents of voxctrl-update.key
VOXCTRL_UPDATE_PUBKEY: ${{ vars.VOXCTRL_UPDATE_PUBKEY }}

# ── Version consistency gate ───────────────────────────────────────────────────
# There is no single source of truth for the app version: it's declared
Expand Down Expand Up @@ -146,6 +156,17 @@ jobs:
steps:
- uses: actions/checkout@v4

# A release build without the key would have an updater that installs
# anything carrying a matching digest — the gap signing exists to close —
# and nothing about the build would look wrong. Stop here instead.
- name: Require the update-signing public key
shell: bash
run: |
if [[ -z "${VOXCTRL_UPDATE_PUBKEY// }" ]]; then
echo "::error::The VOXCTRL_UPDATE_PUBKEY repository variable is not set. See docs/release-signing.md."
exit 1
fi

# ── System deps (Linux) ─────────────────────────────────────────────────
# squashfs-tools (unsquashfs) is required for APPIMAGE_EXTRACT_AND_RUN=1
# which lets appimagetool/linuxdeploy run without FUSE on CI runners.
Expand Down Expand Up @@ -478,6 +499,35 @@ jobs:
- name: List release artifacts
run: ls -lh release-artifacts/

# Sign every asset, then check each signature against the public key the
# builds baked in — a secret and variable from different key pairs would
# otherwise publish a release that no installed copy can update to.
#
# The trusted comment is covered by the signature and names the file and
# the tag; the updater rejects a signature whose comment is not exactly
# this, so a signed file cannot be replayed under another name or release.
- name: Sign release artifacts
env:
SIGNING_KEY: ${{ secrets.VOXCTRL_UPDATE_SIGNING_KEY }}
TAG: ${{ steps.tag.outputs.name }}
run: |
if [[ -z "$SIGNING_KEY" ]]; then
echo "::error::The VOXCTRL_UPDATE_SIGNING_KEY secret is not set. See docs/release-signing.md."
exit 1
fi
sudo apt-get install -y -q minisign
pubkey=$(grep -v '^untrusted comment:' <<< "$VOXCTRL_UPDATE_PUBKEY" | grep -m1 .)
keyfile=$(mktemp)
trap 'rm -f "$keyfile"' EXIT
printf '%s\n' "$SIGNING_KEY" > "$keyfile"
for f in release-artifacts/*; do
[[ "$f" == *.minisig ]] && continue
name=$(basename "$f")
minisign -S -s "$keyfile" -m "$f" -t "voxctrl-update file:${name} tag:${TAG}"
minisign -V -P "$pubkey" -m "$f" -x "$f.minisig"
done
ls -l release-artifacts/*.minisig

- name: Create / update draft release
uses: softprops/action-gh-release@v2
with:
Expand Down
41 changes: 24 additions & 17 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 3 additions & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ members = [
resolver = "2"

[workspace.package]
version = "0.7.0"
version = "0.7.1"
edition = "2021"
authors = ["VoxCtrl Contributors"]
license = "MIT"
Expand Down Expand Up @@ -98,6 +98,8 @@ futures-util = "0.3"
hmac = "0.12"
sha2 = "0.10"
hex = "0.4"
# Release-signature verification for the self-updater (no dependencies of its own).
minisign-verify = "0.3"
base64 = "0.22"

# Archive / download helpers
Expand Down
1 change: 0 additions & 1 deletion crates/voxctrl-audio/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@ version.workspace = true
edition.workspace = true

[dependencies]
voxctrl-config = { workspace = true }
thiserror = { workspace = true }
anyhow = { workspace = true }
tokio = { workspace = true }
Expand Down
Loading
Loading