Skip to content

fix(release): judge RPM extraction by payload; unblock macOS finalize - #27

Merged
AlexMikhalev merged 1 commit into
mainfrom
fix/v1.21.16-seal-fixes
Sep 25, 2026
Merged

AlexMikhalev merged 1 commit into
mainfrom
fix/v1.21.16-seal-fixes

Conversation

@AlexMikhalev

Copy link
Copy Markdown
Contributor

fix(release): judge RPM extraction by payload; unblock macOS finalize

Seal run 36164026957 failed twice:

  1. Both musl managed-package lanes hard-failed in inspect_rpm because
    rpm 4.17's rpm2cpio exits nonzero on valid nFPM 2.47 RPMs while
    writing a complete, correct payload. verify_rpm's host branch already
    judged by extracted payload; inspect_rpm (host and docker branches)
    and verify_rpm's docker branch still trusted the pipeline status.
    All three now print a NOTE with the cpio log and let the
    payload-presence and SHA-256 checks stay fail-closed. Reproduced
    locally against a real nFPM 2.47 aarch64 RPM on rpm 4.17: complete
    payload with nonzero status now passes; a truncated stream fails
    closed. docker_rpm_tool verified against fedora:latest in Docker.

  2. "Finalize all macOS bytes" never started: the tsm-production-release
    environment rejected the v1.21.16 tag deployment (branch policy
    allows main only), and the job hard-requires OP_SERVICE_ACCOUNT_TOKEN
    for op read, which has never been provisioned. The lane now prefers
    the 1Password service account and, when absent, falls back to the
    identical credentials already held by the tsm-production-release
    environment (the same source finalize-prebuilt-release.yml uses),
    with unchanged masking and validation. Dispatching from main (same
    commit the tag points at) satisfies the environment policy.

Refs #337

Seal run 36164026957 failed twice:

1. Both musl managed-package lanes hard-failed in inspect_rpm because
   rpm 4.17's rpm2cpio exits nonzero on valid nFPM 2.47 RPMs while
   writing a complete, correct payload. verify_rpm's host branch already
   judged by extracted payload; inspect_rpm (host and docker branches)
   and verify_rpm's docker branch still trusted the pipeline status.
   All three now print a NOTE with the cpio log and let the
   payload-presence and SHA-256 checks stay fail-closed. Reproduced
   locally against a real nFPM 2.47 aarch64 RPM on rpm 4.17: complete
   payload with nonzero status now passes; a truncated stream fails
   closed. docker_rpm_tool verified against fedora:latest in Docker.

2. "Finalize all macOS bytes" never started: the tsm-production-release
   environment rejected the v1.21.16 tag deployment (branch policy
   allows main only), and the job hard-requires OP_SERVICE_ACCOUNT_TOKEN
   for op read, which has never been provisioned. The lane now prefers
   the 1Password service account and, when absent, falls back to the
   identical credentials already held by the tsm-production-release
   environment (the same source finalize-prebuilt-release.yml uses),
   with unchanged masking and validation. Dispatching from main (same
   commit the tag points at) satisfies the environment policy.

Refs #337
@AlexMikhalev
AlexMikhalev merged commit ba182b5 into main Sep 25, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant