Repository navigation
perf(release-verify-rc): move the deterministic checks into tools/release-verify - #1511
Merged
Merged
Conversation
potiuk
added this pull request to stack #1513
October 4, 2026 23:06
…ease-verify verify-rc's artefact inventory, signature and KEYS classification, checksums, NOTICE/LICENSE presence, binary exclusion, symlink check, version consistency and verdict roll-up were procedures the model followed step by step. They now run in tools/release-verify, a read-only tool that imports KEYS into a temporary GNUPGHOME, never the user's keyring, and prints one JSON object per check. The skill keeps the invocation and how to read each status; RAT, the NOTICE/LICENSE materiality call, adopter validators and the report stay with the model. Rules settled by the maintainer while coding them: - an artefact is required unless the build template marks it optional; - only sha512 is required; md5 never fails alone (WARN); - a symlink must resolve inside the unpacked archive; - SKIP is neutral in the verdict, and skipped steps are listed. The eval cases for steps 2, 3, 5, 6 and 8 now feed the tool's JSON; the classification itself is covered by the tool's tests. Generated-by: Claude Opus 5
…stale signatures From a security review of the new tool: - Every value interpolated into a paste_recipe is now shell-quoted. Artefact names come from the staging area, so a crafted name such as x$(...).tar.gz ran on the voter's machine when pasted. - A signature made by a revoked or expired key, or an expired signature, is FAIL. gpg still exits 0 with VALIDSIG for those, so the tool reads REVKEYSIG / EXPKEYSIG / EXPSIG from the status output. - gpg messages copied into a result's detail no longer carry the temporary GNUPGHOME path, and a local --keys file appears in the recipe by name only; the report can be posted to the planning issue. Tests cover each case; the eval fixtures carry the quoted recipes. Generated-by: Claude Opus 5
Apache RAT flagged the OpenPGP keys, detached signatures and stand-in artefacts under tools/release-verify/tests/fixtures/gpg/. Key and signature data cannot carry a licence header; generate.py, which wrote them, does and stays scanned. Generated-by: Claude Opus 5
potiuk
force-pushed
the
perf/release-verify-tool
branch
from
October 4, 2026 23:38
f263624 to
53c5a69
Compare
This was referenced Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Second of three stacked PRs (#1345); based on the
release-configPR below it.Summary
New
tools/release-verify.release-verify-rc's deterministic checks now run in a read-only tool that prints one JSON object per check:KEYSclassification;KEYSis imported into a temporaryGNUPGHOME, never the user's keyring. RAT, the NOTICE/LICENSE materiality call, adopter validators and the report stay with the model. The JVM step from feat(tools): add maven-artifact-verify and wire JVM artefact checks into release-verify-rc #1415 feeds the same verdict.Rules settled by the maintainer:
From a review of the tool:
Evals: the cases for steps 2, 3, 5, 6 and 8 feed the tool's JSON. The classification itself is covered by the tool's tests.
Test plan
tools/release-verifypytest (61), mypy, ruffrelease-verify-rcevals, 22/22 at the top of the stack🤖 Generated with Claude Code