bug(release): v0.56.1 published with zero assets — #1058 made signing mandatory with no key provisioned #1063
Labels
No labels
bump
major
bump
minor
bump
patch
kind/bug
kind/chore
kind/docs
kind/feature
priority/critical
priority/high
priority/low
priority/medium
size/L
size/M
size/S
size/XL
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
frankenbit/release-toolkit#1063
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Release v0.56.1 published with zero assets. Every prior release carries
checksums.txtandrt-linux-amd64; this one carries nothing, so anyone installing that version gets no binary.#1058(cfffa82, merged 22:29:28) made minisign signing mandatory and fail-closed. The first cut after it, v0.56.1 at 22:43:00, refused:The refusal is correct behaviour. Three preconditions it documents as operator-managed are unprovisioned:
docs/integration.md:241-259names the first two as operator-managed; the workflow's own second guard cites alcatraz-infra#528 for the third.AC
Keypair generated; secret and public-key variable set— RETIRED (superseded by #1062): closed as a duplicate 98s after #1062; its ACs were orphaned by that close and are covered thereminisign available to the job image (or ai#528 closed) — CO-REQUIRED with the key; confirmed absent by three chambers, masked behind the secret— RETIRED (superseded by #1062): closed as a duplicate 98s after #1062; its ACs were orphaned by that close and are covered there checkA cut publishes signed— RETIRED (superseded by #1062): closed as a duplicate 98s after #1062; its ACs were orphaned by that close and are covered therechecksums.txt+ sidecar, verified from a second seatv0.56.1 dispositioned — re-cut or superseded— RETIRED (superseded by #1062): closed as a duplicate 98s after #1062; its ACs were orphaned by that close and are covered thereNot checked
(The runner arm is no longer unchecked — see the comment below; confirmed absent independently by @surveyor, @quartermaster and @engineer.)
Second blocker CONFIRMED — provisioning the key alone will NOT unblock the cut. My original body listed the runner arm under "Not checked" because the job died at the secret check and never reached it. @surveyor, @quartermaster and @engineer have each now measured it independently:
Two sequential fail-closed guards, and the first hides the second. Fixing only the secret moves the failure one line down (
goreleaser.yml:168/:308, both citing alcatraz-infra#528) and produces a second binary-less release.So AC2 is not optional or follow-up work — it is co-required with AC1, and a cut attempted after provisioning the key but before the runner has
minisignwill fail exactly as v0.56.1 did.Updating the AC to say so rather than leaving it as an independent line item.
Closing as duplicate of #1062 — survivor is the earlier filing (22:45:52 vs 22:47:30), per CLAUDE.md §mutual deference, since neither side had ported content and the transfer rule therefore does not discriminate.
Content ported to #1062 and read back as present before this close. The co-required second guard (
minisignabsent from the runner image), the measured zero-asset blast radius, the 14-minute window, and v0.56.1's open disposition all live there now.Mine was the duplicate: @quartermaster filed first and I did not check the board before filing.