Compare commits

..
4 Commits
4 changed files with 39 additions and 14 deletions
+30 -7
View File
@@ -6,6 +6,9 @@ name: Mirror version tag
# pointing to the same object, so both forms exist. # pointing to the same object, so both forms exist.
# No retrigger loop: the tag filter never matches a "v"-prefixed tag, and # No retrigger loop: the tag filter never matches a "v"-prefixed tag, and
# refs created with GITHUB_TOKEN do not fire workflows anyway. # refs created with GITHUB_TOKEN do not fire workflows anyway.
# The job mirrors first and then fails when the pushed tag is lightweight,
# which is what the release form produces: that tag can never carry a
# signature, so the failure has to be loud.
on: on:
push: push:
@@ -26,19 +29,39 @@ jobs:
REPO: ${{ github.repository }} REPO: ${{ github.repository }}
TAG: ${{ github.ref_name }} TAG: ${{ github.ref_name }}
run: | run: |
if gh api "repos/$REPO/git/ref/tags/v$TAG" >/dev/null 2>&1; then
echo "Tag v$TAG already exists, nothing to do."
exit 0
fi
# Mirror the object the pushed tag actually points at: the commit # Mirror the object the pushed tag actually points at: the commit
# for a lightweight tag, the tag object itself for an annotated or # for a lightweight tag, the tag object itself for an annotated or
# signed one. Pointing the mirror at the commit would strip the # signed one. Pointing the mirror at the commit would strip the
# signature, so "git verify-tag v3.1.3" would fail while # signature, so "git verify-tag v3.1.3" would fail while
# "git verify-tag 3.1.3" succeeds. # "git verify-tag 3.1.3" succeeds.
sha="$(gh api "repos/$REPO/git/ref/tags/$TAG" --jq .object.sha)" _ref="$(gh api "repos/$REPO/git/ref/tags/$TAG" --jq '.object.sha + " " + .object.type')"
sha="${_ref%% *}"
objtype="${_ref##* }"
if [ -z "$sha" ] || [ "$sha" = "null" ]; then if [ -z "$sha" ] || [ "$sha" = "null" ]; then
echo "Could not resolve refs/tags/$TAG" echo "Could not resolve refs/tags/$TAG"
exit 1 exit 1
fi fi
gh api "repos/$REPO/git/refs" -f ref="refs/tags/v$TAG" -f sha="$sha" if gh api "repos/$REPO/git/ref/tags/v$TAG" >/dev/null 2>&1; then
echo "Created tag v$TAG -> $sha" echo "Tag v$TAG already exists, nothing to do."
else
gh api "repos/$REPO/git/refs" -f ref="refs/tags/v$TAG" -f sha="$sha"
echo "Created tag v$TAG -> $sha"
fi
- name: Check that the tag is signable
env:
GH_TOKEN: ${{ github.token }}
REPO: ${{ github.repository }}
TAG: ${{ github.ref_name }}
run: |
# A release published from the GitHub UI creates the tag server-side
# as a lightweight ref, which points straight at a commit and can
# never carry a signature (3.1.5 shipped that way, see issue 7273).
# The tag has to be created locally with "git tag -s" and pushed
# BEFORE the release is published, then selected on the release form.
objtype="$(gh api "repos/$REPO/git/ref/tags/$TAG" --jq .object.type)"
if [ "$objtype" != "tag" ]; then
echo "::error::refs/tags/$TAG points at a $objtype, not a tag object. It is a lightweight tag and carries no signature. Recreate it locally with 'git tag -s $TAG' and push it before publishing the release."
exit 1
fi
echo "refs/tags/$TAG is a tag object."
+4 -4
View File
@@ -233,7 +233,7 @@ acme.sh -h
#### 🔏 Verify a Release #### 🔏 Verify a Release
Release tags from `3.1.5` on are signed with the maintainer's SSH key. The Release tags from `3.1.6` on are signed with the maintainer's SSH key. The
signing happens on the maintainer's machine, so the private key is never signing happens on the maintainer's machine, so the private key is never
available to CI. The public half is [`allowed_signers`](allowed_signers) in available to CI. The public half is [`allowed_signers`](allowed_signers) in
this repository. From a clone: this repository. From a clone:
@@ -243,7 +243,7 @@ git config gpg.ssh.allowedSignersFile allowed_signers
``` ```
```bash ```bash
git verify-tag 3.1.5 git verify-tag 3.1.6
``` ```
The signature covers the tag object, which pins the commit and therefore the The signature covers the tag object, which pins the commit and therefore the
@@ -251,10 +251,10 @@ whole tree, so a good signature verifies every file at that release and no
separate tarball checksum is needed. Build a tarball from the verified tag: separate tarball checksum is needed. Build a tarball from the verified tag:
```bash ```bash
git archive --format=tar.gz --prefix=acme.sh-3.1.5/ 3.1.5 > acme.sh-3.1.5.tar.gz git archive --format=tar.gz --prefix=acme.sh-3.1.6/ 3.1.6 > acme.sh-3.1.6.tar.gz
``` ```
> ⚠️ Tags up to `3.1.4` predate the signing key and are unsigned. > ⚠️ Tags up to `3.1.5` are unsigned.
--- ---
+1 -1
View File
@@ -1,6 +1,6 @@
#!/usr/bin/env sh #!/usr/bin/env sh
VER=3.1.5 VER=3.1.6
PROJECT_NAME="acme.sh" PROJECT_NAME="acme.sh"
+4 -2
View File
@@ -4,17 +4,19 @@
# maintainer and is never available to CI, so a compromise of the build # maintainer and is never available to CI, so a compromise of the build
# pipeline cannot produce a tag that verifies against this file. # pipeline cannot produce a tag that verifies against this file.
# #
# Signing starts at 3.1.6; tags up to 3.1.5 are unsigned.
#
# Fingerprint: SHA256:M60qVafm/NUywQHXAkoQcj2v6KgkfrdSXv6mPejUUeE # Fingerprint: SHA256:M60qVafm/NUywQHXAkoQcj2v6KgkfrdSXv6mPejUUeE
# #
# To verify a release tag, from a clone of this repository: # To verify a release tag, from a clone of this repository:
# #
# git config gpg.ssh.allowedSignersFile allowed_signers # git config gpg.ssh.allowedSignersFile allowed_signers
# git verify-tag 3.1.5 # git verify-tag 3.1.6
# #
# A good signature covers the tag object, which pins the commit, which pins # A good signature covers the tag object, which pins the commit, which pins
# the whole tree -- so verifying the tag verifies every file at that # the whole tree -- so verifying the tag verifies every file at that
# release. Build a tarball from the verified tag with: # release. Build a tarball from the verified tag with:
# #
# git archive --format=tar.gz --prefix=acme.sh-3.1.5/ 3.1.5 > acme.sh-3.1.5.tar.gz # git archive --format=tar.gz --prefix=acme.sh-3.1.6/ 3.1.6 > acme.sh-3.1.6.tar.gz
# #
github@neilpang.com namespaces="git" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBTjI0HBJn3uhfT2DsNcFybfAZi3ADbIacMpz1BItKdB github@neilpang.com namespaces="git" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBTjI0HBJn3uhfT2DsNcFybfAZi3ADbIacMpz1BItKdB