Skip to content

release(main): carry verified checksum and signature repair - #5546

Merged
lidge-jun merged 1 commit into
mainfrom
codex/main-release-verification
Sep 22, 2026
Merged

lidge-jun merged 1 commit into
mainfrom
codex/main-release-verification

Conversation

@lidge-jun

Copy link
Copy Markdown
Owner

Summary

  • Repair the two producer/verifier mismatches blocking desktop publication. Standalone checksum filenames now retain the archive extension. The updater verifier now decodes Tauri's outer-base64 minisign box and verifies its ED/BLAKE2b-512 signature plus the trusted-comment signature against the pinned key.
  • Add an independent, attributed minisign 0.7.3 vector and rejection cases for altered payloads, signatures, comments, keys and malformed envelopes. Preserve asset counts, checksums, signature requirements and publication ordering.
  • Ten independent Sol reviewers inspect only this release-verification issue. Unrelated regression work is excluded. This is the owner-authorized main promotion of merged dev PR fix(release): align checksum and Tauri signature verification #5544 (2b8b007). Channel versions are unchanged. The owner explicitly requested immediate integration and verification on main/preview only; dev CI is cancelled.

Verification

  • Hosted evidence: https://github.com/lidge-jun/opencodex/actions/runs/35721661559. All eight packaging jobs passed, including Apple notarization Accepted and bundle signature verification. Final verification failed on five checksum names.
  • Inspection of that run's actual MSI signature confirmed Tauri's four-line outer-base64 ED format. Pinned Tauri CLI 2.11.1 and minisign 0.7.3 source establish the prehash and global signature protocol.
  • Independent upstream test vector comes from jedisct1/rust-minisign commit 068d25a2fffd3d9da96e43f3844c830d8176d5a0 with its license retained.
  • Local tests, builds, typechecks and cryptographic execution: NOT RUN by owner instruction. Commit/push use --no-verify. Exact-head hosted tests and real artifact verification remain required; no source review is represented as an executed test.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 22, 2026 12:21
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 42820567-5262-4513-9415-ab612ac86603

📥 Commits

Reviewing files that changed from the base of the PR and between b007d33 and 82644fd.

📒 Files selected for processing (7)
  • .github/workflows/release.yml
  • desktop/scripts/verify-release-assets.ts
  • structure/desktop-shell.md
  • tests/ci-workflows/release-desktop-scripts.test.ts
  • tests/ci-workflows/release-pipeline-contract.test.ts
  • tests/fixtures/minisign/LICENSE
  • tests/fixtures/minisign/prehashed-vector.json
 _____________________________________________________________________________________________________________________________________________________________________________________________________
< Don't think outside the box - find the box. When faced with an impossible problem, identify the real constraints. Ask yourself: 'Does it have to be done this way? Does it have to be done at all?' >
 -----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the bug Something isn't working label Sep 22, 2026
@lidge-jun
lidge-jun merged commit b1ae178 into main Sep 22, 2026
11 of 35 checks passed
@lidge-jun
lidge-jun deleted the codex/main-release-verification branch September 22, 2026 12:21
lidge-jun added a commit that referenced this pull request Oct 7, 2026
…6711)

* release: v2.33.0-preview.20260825

* release: v2.34.0-preview.20260827

* release: v2.36.0-preview.20260829

* fix(release): pass the bump job's permissions through the reusable-workflow call (#3262)

Both v2.40.0 release dispatches (33615174183 preview, 33615177849 main) died
at startup_failure: a workflow_call cannot grant its callee more than the
calling job holds, and dev-version-bump.yml's job declares contents+pull-
requests write. #3129 wired the call but never dispatched a release, so this
is its first live run. The caller job now declares exactly the callee's two
permissions; no other job in release.yml gains anything.

Co-authored-by: jun <jun@lidge.dev>
(cherry picked from commit 7ce0ba5)

* release: set preview channel version 2.48.0-preview.20260908

* release: set main channel version 2.48.0

* chore(release): promote 2.55.0-preview.20260914 to preview

Promotes the dev product snapshot 62f0222 to the preview train.

The 2.55.0 line carries the #4546 cost-guard work: one send budget per logical request with a
shared final-recovery reserve, zero-is-zero refusals with a typed error rather than a synthetic
502, compact and the Kiro inner retries admitted against that budget, a finite send ceiling per
root workflow with an interactive reserve a fan-out cannot take, and a healthy detour promoted on
transient-hold expiry instead of released cold.

The previous preview tip 2.54.0-preview.20260914 is already tagged and published and is outranked
by v2.54.0, so it could not be re-released; this is a new candidate rather than a re-cut.

* chore(release): promote the verified 2.55.0 product tree to main

Same product tree as preview 7bdd1b2 / 2.55.0-preview.20260914, which published successfully with its registry smoke green. Only package.json version differs.

* ci(release): expose Linux bundler diagnostics for stable artifacts

* fix(release): prepare stable platform bundles

* fix(desktop): carry native sidecar packaging repair to main (#5532)

* chore(ci): refresh main release verification (#5534)

* fix(release): carry lipo argument fix to main (#5537)

* fix(release): carry checksum and signature repair to main (#5546)

* fix(release): carry Windows checksum record support to main (#5552)

* fix(release): publish the GitHub release only after its verified assets attach (#5555) (#5558)

GitHub freezes a release when it is published, so the attach step's upload
came back HTTP 422 "Cannot upload assets to an immutable release". Every
release from v2.55.0 to v2.60.0 therefore shipped with zero assets and the
desktop updater had nothing to download.

Create the release as a draft and flip it to published in attach-release,
after the verified bundle is uploaded. Release notes still come from the
validated notes file written at creation.

* release: prepare 2.63.0 version metadata (#5612)

* release: prepare 2.69.0 version metadata

* fix(release): sign the packaged macOS keyring addons before notarization (#6271)

* fix(release): sign the packaged macOS keyring addons before notarization

Notarization rejected the 2.73.0 preview app: Resources/keyring/*.node, bundled
since #6161, were unsigned or ad-hoc and had no secure timestamp, and Tauri does
not sign files under Resources. Sign each darwin addon in place with the
Developer ID identity, hardened runtime and timestamp after the certificate
import and before tauri build, verify the result, and fail a real release that
lacks signing material.

* fix(release): match keyring signature fields without a pipe

(cherry picked from commit 11782ee)

* chore(release): 2.74.0

* fix: demote developer to user for OrcaSAQ-2 leading-system template

The OrcaSAQ-2-Cyber-27B GGUF pins the same chat-template contract as
Qwen3.8-27B — a non-leading `system` raises and `developer` is
unsupported — so translated requests carrying a mid-conversation
developer reminder failed upstream with a 500 template error. Widen
the leading-system matcher to the OrcaSAQ family (org prefix optional,
quant tag optional) so the reminder keeps its slot as `user`.

---------

Co-authored-by: JUN <bitkyc08@gmail.com>
Co-authored-by: jun <jun@junui-MacBookPro.local>
Co-authored-by: jun <jun@lidge.dev>
Co-authored-by: lidge-jun <243035832+lidge-jun@users.noreply.github.com>
Co-authored-by: t <a@b.com>
Co-authored-by: JUN <jun@lidgeai.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant