Skip to content

bind a release to the commit it was built from - #330

Merged
FreeAndNil merged 1 commit into
masterfrom
Feature/330-release-from-one-commit
Sep 28, 2026
Merged

FreeAndNil merged 1 commit into
masterfrom
Feature/330-release-from-one-commit

Conversation

@FreeAndNil

@FreeAndNil FreeAndNil commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

build-release.ps1 built the binaries from the working tree but archived the
local master ref, so the signed source zip need not match the signed binaries.

  • Refuse a dirty tree, archive HEAD, and ship a signed .manifest recording the
    commit and the artifact set. No origin/master check: that needs the network
    and forbids cutting a release from a tag or a release branch.
  • Both verifiers check the commit against the zip archive comment and the
    listed set against the files present. The hash and signature loops only see
    the files that are there, so an artifact deleted with its .sha512 and .asc
    passed before.
  • Everything the release writes gets LF, asserted in the tests. Set-Content
    writes CRLF on Windows, where a trailing CR breaks sha512sum on macOS and
    makes every manifest name compare unequal. Includes the .sha512 fix.
  • sign-log4net-libraries.sh gains set -euo pipefail and shopt -s nullglob. An
    empty directory iterated the glob patterns and still exited 0.

audit da18b6f-f025

@FreeAndNil FreeAndNil added this to the 3.5.0 milestone Sep 27, 2026
build-release.ps1 built the binaries from the working tree but archived the
local master ref, so the signed source zip need not match the signed binaries.

* Refuse a dirty tree, archive HEAD, and ship a signed .manifest recording the
  commit and the artifact set. No origin/master check: that needs the network
  and forbids cutting a release from a tag or a release branch.
* Both verifiers check the commit against the zip archive comment and the
  listed set against the files present. The hash and signature loops only see
  the files that are there, so an artifact deleted with its .sha512 and .asc
  passed before.
* Everything the release writes gets LF, asserted in the tests. Set-Content
  writes CRLF on Windows, where a trailing CR breaks sha512sum on macOS and
  makes every manifest name compare unequal. Includes the .sha512 fix from
  #328; #328 gets rebased onto this.
* sign-log4net-libraries.sh gains set -euo pipefail and shopt -s nullglob. An
  empty directory iterated the glob patterns and still exited 0.

audit da18b6f-f025
@FreeAndNil
FreeAndNil force-pushed the Feature/330-release-from-one-commit branch from 7f7cd24 to 1ed2acb Compare September 27, 2026 20:14
FreeAndNil added a commit that referenced this pull request Sep 27, 2026
build-release.ps1 built the binaries from the working tree but archived the
local master ref, so the signed source zip need not match the signed binaries.

* Refuse a dirty tree, archive HEAD, and ship a signed .manifest recording the
  commit and the artifact set. No origin/master check: that needs the network
  and forbids cutting a release from a tag or a release branch.
* Both verifiers check the commit against the zip archive comment and the
  listed set against the files present. The hash and signature loops only see
  the files that are there, so an artifact deleted with its .sha512 and .asc
  passed before.
* Everything the release writes gets LF, asserted in the tests. Set-Content
  writes CRLF on Windows, where a trailing CR breaks sha512sum on macOS and
  makes every manifest name compare unequal. Includes the .sha512 fix from
  #328; #328 gets rebased onto this.
* sign-log4net-libraries.sh gains set -euo pipefail and shopt -s nullglob. An
  empty directory iterated the glob patterns and still exited 0.

audit da18b6f-f025
@FreeAndNil
FreeAndNil merged commit a457590 into master Sep 28, 2026
3 checks passed
@FreeAndNil
FreeAndNil deleted the Feature/330-release-from-one-commit branch September 28, 2026 06:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants