Skip to content

test(ci): derive the release-verify fixture's signed set from the updater table - #5425

Merged
lidge-jun merged 1 commit into
devfrom
codex/260921-verify-derive-signed-set
Sep 21, 2026
Merged

lidge-jun merged 1 commit into
devfrom
codex/260921-verify-derive-signed-set

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Summary

dev is red at the union of #5405 and #5391. Lane F made the deb a second Linux updater target (linux-x86_64-deb), so the pre-publication verifier's derived expected set correctly gained OpenCodex-<version>-linux-amd64.deb.sig — while the test's hand-written oracle still described the earlier world where only the AppImage was signed. Each branch was green alone; the merge was not. This is the union defect class AGENTS.md warns about: two branches each restated a set, and the merged truth outgrew one of the copies.

The fix is derivation, not list-keeping:

  • The fixture's signed set now comes straight from platformFiles — the table that decides which bundles carry the updater key — and its produced-payload list comes from the shared standalone target module and the bundle table. A future updater target or bundle changes both sides of the assertion by itself.
  • The derivation test keeps its concrete payload anchors (a renamed or dropped bundle should still fail for a human to review) but asserts the signature rule instead of the roster: a bundle's .sig is expected exactly when the updater table names it.
  • The manifest platform assertion also derives from platformFiles keys rather than a copied list — it would have failed next for the same reason.

Only the two test oracles changed. The verification ordering from #5405 (checksums, signatures and the manifest all verified before publication) is untouched, and no production code changes.

Security review: this PR touches the release-verification test surface only; the release automation itself is unchanged. No permissions, secrets, or publication ordering are modified. Noted explicitly because the file sits beside release automation that requires it.

Verification

Local execution checks: NOT RUN (lane policy — no local bun test, bun run test, bun run test:changed, bun run typecheck, builds, installs, or ocx execution; hosted CI at the exact head SHA is the gate and is reported separately).

Static verification performed instead:

  • Failure match, from the hosted CI log at ac3df52: the failing diff shows exactly + "OpenCodex-2.61.0-linux-amd64.deb.sig" in the verifier's derived set against the oracle — the oracle now derives that entry from platformFiles, which contains "linux-x86_64-deb": "linux-amd64.deb" since feat(desktop): dual Linux updater targets and the installed-artifact release gate #5391.
  • Full trace, by reading: the derived oracle now produces signatures for exactly the updater suffixes {macos.app.tar.gz, windows-x64.msi, linux-x86_64.AppImage, linux-amd64.deb}; expectedReleaseAssets with requireSignatures requires the same set from the same table; the fixture writes every signature the verifier will demand, so the full-flow test passes the expected-set, checksum, signature, manifest parse-back, and receipt stages. The manifest platform assertion compares against Object.keys(platformFiles).sort(), which is what parseBackManifest enforces — the five current platforms including linux-x86_64-deb.
  • Expected-red reasoning (not executed): revert any one derivation and the mismatch returns — e.g. removing the deb from platformFiles would drop deb.sig from both sides consistently, and a future sixth updater platform extends both sides together; conversely a verifier that stopped requiring a signature the table names would fail the rule assertion in the derivation test.
  • House-rule checks (static): one file changed, no new test files (nothing to register), no size-capped file touched, git merge-tree --write-tree origin/dev HEAD clean.

Checklist

  • Scope stays focused and avoids unrelated cleanup. (One test file; three hand-written sets replaced with derivations.)
  • Docs or release notes were updated when needed. (No behaviour change; the test comments record the derivation rule.)
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults. (Test-only change adjacent to release automation; nothing executable changed — see the note above.)

Summary by CodeRabbit

  • Tests
    • Updated release verification tests to derive expected assets and signing requirements from the current platform and bundle configuration.
    • Expanded coverage to validate all configured desktop targets and platform manifest entries.
    • Removed brittle hardcoded asset and platform expectations in favor of configuration-driven checks.

…ater table

dev went red at the union of #5405 and #5391: lane F made the deb a second
Linux updater target, so the verifier's derived expected set gained
OpenCodex-<version>-linux-amd64.deb.sig, while the test's hand-written
oracle still described the earlier world where only the AppImage was
signed. Each branch was green alone; the merge was not.

The fix is derivation, not list-keeping. The signed set and the manifest
platform list in the fixture now come straight from platformFiles — the
table that decides which bundles carry the updater key — and the produced
payload list comes from the shared standalone target module and the bundle
table. A future updater target changes both sides of the assertion by
itself. The derivation test keeps its concrete payload anchors (a renamed
or dropped bundle should still fail for a human to review) and asserts the
rule instead of the roster: a bundle's signature is expected exactly when
the updater table names it.

Only the two test oracles changed; the verification ordering (checksums,
signatures and the manifest all precede publication) is untouched.
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 21, 2026 07:39
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T07:42:44.516699Z 5164db9 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the chore Maintenance, CI, tests, refactors, or build changes (not a user-facing bug or feature). label Sep 21, 2026
@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

Understand this PR’s impact

Explore downstream dependencies and potential security impact with Blast Radius.

View blast radius →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 13e994a2-215e-4c76-9524-99b05ca48249

📥 Commits

Reviewing files that changed from the base of the PR and between ac3df52 and 5164db9.

📒 Files selected for processing (1)
  • tests/ci-workflows/release-desktop-scripts.test.ts

Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The release workflow tests now derive expected archives, signatures, and manifest platforms from producer tables instead of fixed fixtures. The test setup imports the tables and helpers used to build these expectations.

Changes

Release asset test contracts

Layer / File(s) Summary
Derived release asset contracts
tests/ci-workflows/release-desktop-scripts.test.ts
The tests derive bundle names from bundlesByTarget, standalone archive names from standaloneTargets and standaloneArchiveName, signature suffixes from platformFiles, and manifest platforms from Object.keys(platformFiles).sort(). The existing release matrix value is reused when calling expectedReleaseAssets.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: the release-verification fixture now derives its signed asset set from the updater table.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5164db952b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

`OpenCodex-${VERSION}-windows-x64.msi`,
`OpenCodex-${VERSION}-linux-x86_64.AppImage`,
`OpenCodex-${VERSION}-linux-amd64.deb`,
...standaloneTargets.map(target => standaloneArchiveName(VERSION, target)),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep the standalone fixture independent of the verifier helper

The package-standalone archive step in .github/workflows/release.yml:150-169 constructs .zip versus .tar.gz names independently from $RUNNER_OS; it does not call standaloneArchiveName. Using that helper here means both the fixture and expectedReleaseAssets now obtain standalone names from the same code, so an incorrect helper change—especially one affecting the currently unanchored Darwin x64 or Linux arm64 target—will leave this test green while the release workflow produces different files and verification fails after packaging. Keep an independent assertion against the workflow's naming convention, or make the workflow itself consume the shared helper before deriving the fixture from it.

AGENTS.md reference: AGENTS.md:L284-L287

Useful? React with 👍 / 👎.

@lidge-jun
lidge-jun merged commit 403b6b2 into dev Sep 21, 2026
30 of 33 checks passed
@lidge-jun
lidge-jun deleted the codex/260921-verify-derive-signed-set branch September 21, 2026 08:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Maintenance, CI, tests, refactors, or build changes (not a user-facing bug or feature).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant