fix(release): judge RPM extraction by payload; unblock macOS finalize - #27
Merged
Merged
Conversation
Seal run 36164026957 failed twice: 1. Both musl managed-package lanes hard-failed in inspect_rpm because rpm 4.17's rpm2cpio exits nonzero on valid nFPM 2.47 RPMs while writing a complete, correct payload. verify_rpm's host branch already judged by extracted payload; inspect_rpm (host and docker branches) and verify_rpm's docker branch still trusted the pipeline status. All three now print a NOTE with the cpio log and let the payload-presence and SHA-256 checks stay fail-closed. Reproduced locally against a real nFPM 2.47 aarch64 RPM on rpm 4.17: complete payload with nonzero status now passes; a truncated stream fails closed. docker_rpm_tool verified against fedora:latest in Docker. 2. "Finalize all macOS bytes" never started: the tsm-production-release environment rejected the v1.21.16 tag deployment (branch policy allows main only), and the job hard-requires OP_SERVICE_ACCOUNT_TOKEN for op read, which has never been provisioned. The lane now prefers the 1Password service account and, when absent, falls back to the identical credentials already held by the tsm-production-release environment (the same source finalize-prebuilt-release.yml uses), with unchanged masking and validation. Dispatching from main (same commit the tag points at) satisfies the environment policy. Refs #337
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix(release): judge RPM extraction by payload; unblock macOS finalize
Seal run 36164026957 failed twice:
Both musl managed-package lanes hard-failed in inspect_rpm because
rpm 4.17's rpm2cpio exits nonzero on valid nFPM 2.47 RPMs while
writing a complete, correct payload. verify_rpm's host branch already
judged by extracted payload; inspect_rpm (host and docker branches)
and verify_rpm's docker branch still trusted the pipeline status.
All three now print a NOTE with the cpio log and let the
payload-presence and SHA-256 checks stay fail-closed. Reproduced
locally against a real nFPM 2.47 aarch64 RPM on rpm 4.17: complete
payload with nonzero status now passes; a truncated stream fails
closed. docker_rpm_tool verified against fedora:latest in Docker.
"Finalize all macOS bytes" never started: the tsm-production-release
environment rejected the v1.21.16 tag deployment (branch policy
allows main only), and the job hard-requires OP_SERVICE_ACCOUNT_TOKEN
for op read, which has never been provisioned. The lane now prefers
the 1Password service account and, when absent, falls back to the
identical credentials already held by the tsm-production-release
environment (the same source finalize-prebuilt-release.yml uses),
with unchanged masking and validation. Dispatching from main (same
commit the tag points at) satisfies the environment policy.
Refs #337