feat(cli): stage Go release artifacts - #5
Merged
Merged
Conversation
Introduce release-cli and move the producer's bespoke bash validation into it. `release-cli stage --profile go --dist PATH` preserves PP-06/PP-07/PP-08 exactly: every checksums.txt payload is streamed through SHA-256, a non-empty signed checksum bundle is required, and exactly one Linux binary per amd64 and arm64 is selected, path-confined, and proven to be a regular executable. Path confinement uses os.OpenRoot so a symlink escaping the dist root is rejected, not just a lexical `..`. Failures are exit 1 with a diagnostic naming the offending artifact; usage and configuration errors are exit 2 through a single ErrUsage sentinel. Under --json each command emits exactly one `release.dev/result/v1` envelope on stdout. This also makes release-cli the repository's own released artifact, replacing the release-mvp exercise binary across GoReleaser, Melange, apko, Release Please, and moon. The new setup-release-cli composite action acquires the CLI either from the stamped release (verifying the archive checksum, then `gh attestation verify` with a derived --signer-workflow, then failing closed on a version or protocol mismatch) or from a caller-supplied cli-path, which warns instead of failing because the caller owns that pairing. Workflows and the action are one release unit with one consumer pin: there is deliberately no cli-version input. scripts/check-protocol-stamp.sh keeps the action's expected protocol, the Go constant, and the Release Please stamping markers in step. Reviewed over two rounds and audited against AGENTS.md. Viper was dropped under L1: six calls for three environment variables did not justify its dependency tree in a supply-chain tool, so flags and RELEASE_* now resolve in the command layer with flag-over-env precedence.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
First slice of the
release-cliprogram (architecture rev 3, plan §3 PR 1). Four production packages replace the producer's bespoke bash validation, and this repository's released artifact becomesrelease-cliinstead of therelease-mvpexercise binary.release-cli stage --profile go --dist PATH [--json]replaces the two validation steps formerly atgo-pre-publish.yml:88-119(inventory PP-06/PP-07/PP-08), about 32 lines of bash.release-cli version [--json]reports the linker-injected version and commit plus the protocol constant..github/actions/setup-release-cliacquires the CLI from the stamped release or from a caller-suppliedcli-path.scripts/check-protocol-stamp.shkeeps the action'sEXPECTED_PROTOCOL, the Gocli.Protocolconstant, and the Release Please stamping markers in step; wired intomoon run root:check.Behavior preserved
PP-06 verifies every
checksums.txtpayload hash and requires a non-empty regularchecksums.txt.sigstore.json. PP-07 requires exactly one LinuxBinaryrecord peramd64andarm64. PP-08 requires each selected path to be confined under the dist root, a regular file, and executable.Path confinement uses
os.OpenRoot, so a symlink escaping the dist root is rejected — not only a lexical... Theworkflow_callcontract and the PP-09/PP-10 upload steps are unchanged.Contract
0success,1contract/verification failure,2usage or configuration error. No exit 3, no generic safe-rerun promise.--json, stdout carries exactly onerelease.dev/result/v1envelope, including failures withok:false. If flag parsing itself fails there is deliberately no envelope: usage goes to stderr with exit 2.versionprints its data to stdout;stageprints nothing to stdout on success without--json.cli-versioninput.cli-pathis an unsupported escape hatch that warns rather than fails on stamp mismatch; the installed path fails closed.go-pre-publish.ymlloads the composite throughuses: $/.github/actions/setup-release-cli, because external consumers run that workflow against their own checkout.Verification
mise exec -- moon run root:checkgreen: format, lint (strict.golangci.yml), build, test, protocol stamp.versionandversion --json; bare invocation and unknown flag both exit 2 with empty stdout; unknown profile exits 2; env-only resolution throughRELEASE_PROFILE,RELEASE_DIST,RELEASE_JSON; flag-over-env precedence; a valid bundle under a non-distdirectory name exits 0.ok:false: bad checksum, missing architecture record, escaped path, cleared execute bit, symlink escaping the dist root, and missing signature bundle.$/) pin immunity under an external SHA-pinned caller,oras-gov2.6.2 GHCR parity, and Release Please stamping plus the protocol guard.Review
Two review rounds by a dedicated reviewer (verdict: go) and one
AGENTS.mdconformance audit.Fixed from those rounds:
github.action_repositoryis empty. It previously fell back to the consumer's repository, which collapsed the download source and the attestation trust root onto untrusted ground.--signer-workflowand--deny-self-hosted-runnersadded to the bootstrap attestation check, matching what the docs tell consumers to run.Follow-ups recorded in the journal, not in this PR
cmd/release-cli/main.gohas no CLI-level testscript coverage; testscript is deferred by the plan.Human acceptance requested. I have not merged.