Skip to content

perf(release-verify-rc): move the deterministic checks into tools/release-verify - #1511

Merged
potiuk merged 3 commits into
perf/release-config-toolfrom
perf/release-verify-tool
Oct 4, 2026
Merged

potiuk merged 3 commits into
perf/release-config-toolfrom
perf/release-verify-tool

Conversation

@potiuk

@potiuk potiuk commented Oct 4, 2026

Copy link
Copy Markdown
Member

Second of three stacked PRs (#1345); based on the release-config PR below it.

Summary

  • New tools/release-verify. release-verify-rc's deterministic checks now run in a read-only tool that prints one JSON object per check:

    • inventory;
    • signature and KEYS classification;
    • checksums;
    • NOTICE/LICENSE presence;
    • binary exclusion;
    • symlinks;
    • version consistency;
    • the verdict roll-up.

    KEYS is imported into a temporary GNUPGHOME, never the user's keyring. RAT, the NOTICE/LICENSE materiality call, adopter validators and the report stay with the model. The JVM step from feat(tools): add maven-artifact-verify and wire JVM artefact checks into release-verify-rc #1415 feeds the same verdict.

  • Rules settled by the maintainer:

    • an artefact is required unless the build template marks it optional;
    • only sha512 is required, and md5 never fails alone;
    • a symlink must resolve inside the archive;
    • SKIP is neutral in the verdict, and skipped steps are listed.
  • From a review of the tool:

    • every value in a paste recipe is shell-quoted, because artefact names come from the staging area;
    • a signature by a revoked or expired key, or an expired signature, is FAIL (gpg still exits 0 for those);
    • local paths never reach a report that may be posted.
  • Evals: the cases for steps 2, 3, 5, 6 and 8 feed the tool's JSON. The classification itself is covered by the tool's tests.

Test plan

  • tools/release-verify pytest (61), mypy, ruff
  • release-verify-rc evals, 22/22 at the top of the stack

🤖 Generated with Claude Code

@potiuk
potiuk added this pull request to stack #1513 October 4, 2026 23:06
potiuk added 3 commits October 5, 2026 01:33
…ease-verify

verify-rc's artefact inventory, signature and KEYS classification,
checksums, NOTICE/LICENSE presence, binary exclusion, symlink check,
version consistency and verdict roll-up were procedures the model
followed step by step. They now run in tools/release-verify, a
read-only tool that imports KEYS into a temporary GNUPGHOME, never
the user's keyring, and prints one JSON object per check. The skill
keeps the invocation and how to read each status; RAT, the
NOTICE/LICENSE materiality call, adopter validators and the report
stay with the model.

Rules settled by the maintainer while coding them:
- an artefact is required unless the build template marks it
  optional;
- only sha512 is required; md5 never fails alone (WARN);
- a symlink must resolve inside the unpacked archive;
- SKIP is neutral in the verdict, and skipped steps are listed.

The eval cases for steps 2, 3, 5, 6 and 8 now feed the tool's JSON;
the classification itself is covered by the tool's tests.

Generated-by: Claude Opus 5
…stale signatures

From a security review of the new tool:

- Every value interpolated into a paste_recipe is now shell-quoted.
  Artefact names come from the staging area, so a crafted name such
  as x$(...).tar.gz ran on the voter's machine when pasted.
- A signature made by a revoked or expired key, or an expired
  signature, is FAIL. gpg still exits 0 with VALIDSIG for those, so
  the tool reads REVKEYSIG / EXPKEYSIG / EXPSIG from the status output.
- gpg messages copied into a result's detail no longer carry the
  temporary GNUPGHOME path, and a local --keys file appears in the
  recipe by name only; the report can be posted to the planning issue.

Tests cover each case; the eval fixtures carry the quoted recipes.

Generated-by: Claude Opus 5
Apache RAT flagged the OpenPGP keys, detached signatures and stand-in
artefacts under tools/release-verify/tests/fixtures/gpg/. Key and
signature data cannot carry a licence header; generate.py, which wrote
them, does and stays scanned.

Generated-by: Claude Opus 5
@potiuk
potiuk force-pushed the perf/release-verify-tool branch from f263624 to 53c5a69 Compare October 4, 2026 23:38
@potiuk
potiuk merged commit 20d1238 into main Oct 4, 2026
111 checks passed
@potiuk
potiuk deleted the perf/release-verify-tool branch October 4, 2026 23:44
@potiuk potiuk added capability:triage Sweep + classify + propose disposition family:ci .github workflows, prek, validators family:docs Docs, MISSION.md, READMEs family:release-management release-* skills family:setup setup-* skills family:tools tools/* substrate:release Tool substrate: release-artefact helpers (reproducible archive build, lint, comparison) labels Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

capability:triage Sweep + classify + propose disposition family:ci .github workflows, prek, validators family:docs Docs, MISSION.md, READMEs family:release-management release-* skills family:setup setup-* skills family:tools tools/* substrate:release Tool substrate: release-artefact helpers (reproducible archive build, lint, comparison)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant