Compare commits

..
Author SHA1 Message Date
修雨 cce9b798d5 Merge remote-tracking branch 'origin/main' into codex/fix-release-version-verifier 2026-07-21 17:51:46 +08:00
修雨 bfa3a1bf33 Merge pull request #729 from sczheng189/feat/relax-stable-promotion-contract
feat(release): allow stable promotion with commits after the beta baseline
2026-07-21 17:47:53 +08:00
修雨 e154b4ecde fix(release): validate packaged version at runtime 2026-07-21 17:47:02 +08:00
zhengyubai f83c305749 feat(release): allow stable promotion with commits after the beta baseline
Stable releases previously required a byte-identical tree with the
promoted beta (only CHANGELOG.md could differ) and local releases had
to run exactly at the origin/main tip with an atomic main+tag push.
Together these froze main for the whole beta-to-stable window.

Relax both gates while keeping the beta soak mandatory:
- stable still requires an explicit delivered, non-withdrawn beta whose
  commit is an ancestor of the sealed release commit; the tree-identity
  drift check is removed
- local releases accept any clean sealed commit contained in
  origin/main history (any branch or detached HEAD) and push only the
  release tag; command-compatibility checks compare the sealed HEAD,
  matching CI
2026-07-21 18:35:59 +09:00
修雨 b898f5c987 Merge pull request #723 from DingTalk-Real-AI/codex/retry-npm-channel-verification
fix(release): wait for npm channel propagation
2026-07-21 15:56:48 +08:00
修雨 20750df20b fix(release): wait for npm channel propagation 2026-07-21 15:46:19 +08:00
修雨 749149b94a Merge pull request #721 from DingTalk-Real-AI/codex/release-v1.0.53
chore(release): prepare v1.0.53
2026-07-21 15:35:50 +08:00
修雨 e5c8ff9acd chore(release): prepare v1.0.53 2026-07-21 15:27:38 +08:00
9 changed files with 374 additions and 58 deletions
+33 -13
View File
@@ -1047,7 +1047,9 @@ jobs:
rm -f "$RUNNER_TEMP/dws-developer-id-password"
- name: Verify final release artifacts
run: ./scripts/release/verify-release-artifacts.sh "$RELEASE_VERSION"
run: |
DWS_PACKAGE_DIST_DIR="$GITHUB_WORKSPACE/dist" \
"$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/verify-release-artifacts.sh" "$RELEASE_VERSION"
- name: Verify npm package before sealing GitHub Release
run: ./scripts/release/verify-package-managers.sh --npm-only --expected-version "$RELEASE_VERSION"
@@ -1172,7 +1174,9 @@ jobs:
path: dist
- name: Verify finalized release artifacts before publication
run: ./scripts/release/verify-release-artifacts.sh "$RELEASE_VERSION"
run: |
DWS_PACKAGE_DIST_DIR="$GITHUB_WORKSPACE/dist" \
"$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/verify-release-artifacts.sh" "$RELEASE_VERSION"
- name: Verify npm package before sealing GitHub Release
run: ./scripts/release/verify-package-managers.sh --npm-only --expected-version "$RELEASE_VERSION"
@@ -1268,7 +1272,7 @@ jobs:
"$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/download-github-release-assets.sh" \
"$RELEASE_VERSION" "$published_dir"
DWS_PACKAGE_DIST_DIR="$published_dir" \
./scripts/release/verify-release-artifacts.sh "$RELEASE_VERSION"
"$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/verify-release-artifacts.sh" "$RELEASE_VERSION"
for asset in "$published_dir"/dws-* "$published_dir"/checksums.txt; do
if [ "$IS_RECOVERY" = "true" ] && ! cmp -s "$asset" "dist/$(basename "$asset")"; then
echo "Public recovery asset differs from this run's sealed artifact: $(basename "$asset")" >&2
@@ -1374,7 +1378,7 @@ jobs:
"$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/download-github-release-assets.sh" \
"$RELEASE_VERSION" "$sealed_upload"
DWS_PACKAGE_DIST_DIR="$sealed_upload" \
./scripts/release/verify-release-artifacts.sh "$RELEASE_VERSION"
"$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/verify-release-artifacts.sh" "$RELEASE_VERSION"
for remote_asset in "$sealed_upload"/dws-* "$sealed_upload"/checksums.txt; do
local_asset="dist/$(basename "$remote_asset")"
cmp -s "$local_asset" "$remote_asset" || {
@@ -1444,7 +1448,7 @@ jobs:
"$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/download-github-release-assets.sh" \
"$RELEASE_VERSION" "$immutable_dir"
DWS_PACKAGE_DIST_DIR="$immutable_dir" \
./scripts/release/verify-release-artifacts.sh "$RELEASE_VERSION"
"$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/verify-release-artifacts.sh" "$RELEASE_VERSION"
for immutable_asset in "$immutable_dir"/dws-* "$immutable_dir"/checksums.txt; do
sealed_asset="dist/$(basename "$immutable_asset")"
cmp -s "$sealed_asset" "$immutable_asset" || {
@@ -1566,7 +1570,8 @@ jobs:
--pattern 'dws-*' \
--pattern 'checksums.txt' \
--clobber
./scripts/release/verify-release-artifacts.sh "$RELEASE_VERSION"
DWS_PACKAGE_DIST_DIR="$GITHUB_WORKSPACE/dist" \
"$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/verify-release-artifacts.sh" "$RELEASE_VERSION"
DWS_PACKAGE_SOURCE_ROOT="$GITHUB_WORKSPACE" \
DWS_PACKAGE_DIST_DIR="$GITHUB_WORKSPACE/dist" \
./scripts/release/stage-npm-package.sh "$RELEASE_VERSION"
@@ -1694,13 +1699,28 @@ jobs:
run: |
set -eu
. ./scripts/release/release-lib.sh
delivered="$(npm view dingtalk-workspace-cli "dist-tags.$NPM_TAG")"
if [ "$delivered" = "$SEMVER" ]; then exit 0; fi
release_version_is_greater "v$delivered" "v$SEMVER" || {
echo "npm $NPM_TAG=$delivered does not deliver or supersede v$SEMVER" >&2
exit 1
}
echo "npm $NPM_TAG already supersedes this historical rerun at v$delivered."
attempt=1
max_attempts=12
while :; do
delivered="$(npm view dingtalk-workspace-cli "dist-tags.$NPM_TAG" \
--registry=https://registry.npmjs.org --prefer-online)"
if [ "$delivered" = "$SEMVER" ]; then exit 0; fi
if release_version_is_greater "v$delivered" "v$SEMVER"; then
echo "npm $NPM_TAG already supersedes this historical rerun at v$delivered."
exit 0
fi
release_version_is_greater "v$SEMVER" "v$delivered" || {
echo "npm $NPM_TAG=$delivered cannot be reconciled with v$SEMVER" >&2
exit 1
}
if [ "$attempt" -ge "$max_attempts" ]; then
echo "npm $NPM_TAG still reports older v$delivered after $attempt attempts; expected v$SEMVER" >&2
exit 1
fi
echo "npm $NPM_TAG still reports older v$delivered; waiting for registry propagation ($attempt/$max_attempts)."
sleep 5
attempt=$((attempt + 1))
done
- name: Sync release artifacts to China OSS mirror
if: ${{ needs.release-contract.outputs.oss_mirror == 'enabled' }}
+34
View File
@@ -6,6 +6,40 @@ The format is inspired by [Keep a Changelog](https://keepachangelog.com/) and th
## [Unreleased]
### Changed
- **Relaxed stable promotion contract** — a stable release still requires a delivered, non-withdrawn beta baseline in its commit history, but no longer requires a byte-identical tree with that beta; reviewed commits merged to `main` after the beta can now ship in the stable release. Local releases now accept any sealed commit contained in `main` history and push only the release tag, so `main` is never frozen during the beta-to-stable window.
## [1.0.53] - 2026-07-21
This release promotes the sealed `v1.0.53-beta.7` contents to stable. It adds enterprise onboarding, declarative shortcuts, Sheet/Aitable writes, multi-account profiles, and broader personal IM events, while hardening authentication and the guarded release path.
### Added
- **Enterprise and office command coverage** — adds enterprise creation, employee invitation, and account provisioning commands; 366 declarative service shortcuts; Sheet import commands; and Aitable workflow create/update support with reviewed Schema contracts.
- **Multiple accounts in one DingTalk organization** — profiles can distinguish accounts by organization and user, select them explicitly, and log out one account or an entire organization without overwriting another account's credentials.
- **Expanded personal IM event subscriptions** (#651) — adds read-receipt, recall, and reaction events for one-to-one and group chats, plus specified-sender subscriptions by staff ID or OpenDingTalk ID.
- **Official multi-platform Homebrew channel** — ships separate stable and keg-only beta Formulae for macOS and Linux across amd64 and arm64, with isolated update PRs.
### Changed
- **Personal event output contract** (#651) — `event consume` now emits event-specific top-level structured fields; scripts that consumed the former transport envelope must use the flat fields or select `-f raw`, while `--debug-raw-events` retains the diagnostic envelope.
- **Guarded release lifecycle** — beta/stable publication now uses explicit promotion, immutable delivery proofs, protected recovery, and tag-bound optional OSS policy; an unprovisioned OSS mirror is sealed as `deferred` so GitHub, npm, and Homebrew are not blocked.
### Fixed
- **Authentication and credential reliability** — organization-policy denials stop before mutation or polling, long-running clients reload and refresh access tokens consistently, concurrent credential writes are atomic, and Windows portable-auth commands fail before reading or writing unsupported credential bundles.
- **Command validation and compatibility** — invalid Sheet/task targets fail locally, IM shortcuts preserve AI-tag and alias compatibility, and Aitable import uploads require and forward a positive file size.
- **Release publication reliability** — GitHub draft publication is bound to one verified release ID and exact assets, preflight uses isolated installer worktrees, guarded local tags remain compatible, cloud planning fingerprints the actual allocated release refs, and npm channel verification waits for bounded registry propagation without moving tags.
## [1.0.53-beta.7] - 2026-07-21
This beta validates bounded npm channel verification after registry publication.
### Fixed
- **npm dist-tag eventual consistency** — Release delivery now tolerates a briefly stale `latest` or `beta` read after publishing by retrying only when npm reports a valid older version. Registry errors, invalid or incomparable tags, and channels that never converge still fail closed without moving any tag during verification.
## [1.0.53-beta.6] - 2026-07-21
This beta validates guarded local release compatibility and tag-bound OSS deferral so an unprovisioned mirror cannot block the primary release channels.
+4 -4
View File
@@ -69,11 +69,11 @@ dws-release config --remote origin
```text
main 上的候选代码 + beta CHANGELOG
→ vX.Y.Z-beta.N(预发验证)
→ 只允许补正式 CHANGELOG,源码不得再变化
→ vX.Y.Z(正式发布)
→ 补正式 CHANGELOG;允许继续通过 PR 合入新 commit
→ vX.Y.Z(正式发布,封板提交必须包含该 beta 提交)
```
云端入口自动选择本次最新、已交付且未撤回的 beta;本地入口必须显式指定。流水线会比较两者:除 `CHANGELOG.md` 外只要有任何文件变化,就拒绝正式发布。这样预发测过的代码、命令树和正式发布的代码是同一份。
云端入口自动选择本次最新、已交付且未撤回的 beta;本地入口必须显式指定。流水线要求该 beta 已成功交付、未撤回,且 beta 提交必须位于正式发布封板提交的历史中——不能跳过 beta 直接发正式版,但允许在 beta 之后把经过 review 合入 `main` 的 commit 一起发布。
## 预发发布
@@ -131,7 +131,7 @@ dws-release v1.2.3 --from-beta v1.2.3-beta.1 --publish
## CI/CD 保证
- 只接受 `vX.Y.Z-beta.N` 和 `vX.Y.Z`,且新版本必须高于上一正式版。这里的“上一正式版”必须同时具备公开非草稿 GitHub Release 和同 tag/commit 的成功 Release workflow;只有 tag、没有交付成功的孤儿版本会阻断后续发布,要求走受保护恢复补齐。云端 tag 会固定 `Release-Run`、requester、commit 和版本分配指纹,交付验证按该精确 run/attempt 及完整 job graph 取证,不接受任意 `workflow_dispatch`。历史版本若曾通过专用 recovery workflow 完成交付,只能使用仓库内 `delivered-stable-recoveries.json` 中精确到 tag、commit、run、workflow SHA 与 attempt 的 reviewed 证据。
- tag 必须是 annotated tag;本地脚本在推送前重新确认 HEAD 与远端 `main` 完全一致,CI 允许其后 `main` 前进,但要求封板提交仍位于 `main` 历史中。
- tag 必须是 annotated tag;本地脚本要求封板提交已通过 PR 合入并包含在远端 `main` 历史中,发布只推送 tag。CI 允许其后 `main` 继续前进,但始终要求封板提交位于 `main` 历史中。
- 日常 CI 和发布前都会对比“最新已交付正式版”的完整命令树;若长时间预检期间该 baseline 发生变化,会针对新的 baseline 重新比较。
- GoReleaser 只构建;Darwin 重签、checksums 重算和 npm 安装验证通过后,才统一上传 GitHub Release 的最终产物。
- 六个平台归档会逐个解包并核验二进制内嵌版本;公开资产集合、checksums 集合和 npm tarball integrity 都必须精确一致。npm tarball 固定由 npm `10.9.2` 打包,避免重跑时因 runner 自带 npm 漂移产生不同字节。
+9 -6
View File
@@ -128,13 +128,8 @@ require_remote() {
}
sync_main_if_safe() {
current_branch="$(git symbolic-ref --quiet --short HEAD 2>/dev/null || true)"
[ "$current_branch" = "main" ] || {
printf 'release validation must run from the main worktree (current: %s)\n' "${current_branch:-detached HEAD}" >&2
exit 1
}
[ -z "$(git status --porcelain --untracked-files=all)" ] || {
printf '%s\n' 'release main worktree must be clean before synchronization' >&2
printf '%s\n' 'release worktree must be clean before synchronization' >&2
exit 1
}
@@ -146,6 +141,14 @@ sync_main_if_safe() {
if [ "$head_commit" = "$remote_commit" ]; then
return 0
fi
current_branch="$(git symbolic-ref --quiet --short HEAD 2>/dev/null || true)"
if [ "$current_branch" != "main" ]; then
if git merge-base --is-ancestor HEAD "$remote_main"; then
return 0
fi
printf 'HEAD is not contained in %s/main history; merge it through a reviewed PR before release\n' "$REMOTE" >&2
exit 1
fi
if git merge-base --is-ancestor HEAD "$remote_main"; then
git merge --ff-only "$remote_main"
return 0
+2 -13
View File
@@ -71,20 +71,14 @@ git rev-parse --verify --quiet "$remote_main^{commit}" >/dev/null || {
printf 'release branch is not available locally: %s/%s\n' "$REMOTE" "$BRANCH" >&2
exit 1
}
remote_main_commit="$(git rev-parse "$remote_main^{commit}")"
if [ "$CONTEXT" = "local" ]; then
[ -z "$(git status --porcelain --untracked-files=all)" ] || {
printf 'release worktree must be clean (staged, unstaged, and untracked files are blocked)\n' >&2
exit 1
}
current_branch="$(git symbolic-ref --quiet --short HEAD 2>/dev/null || true)"
[ "$current_branch" = "$BRANCH" ] || {
printf 'local release must run from branch %s (current: %s)\n' "$BRANCH" "${current_branch:-detached HEAD}" >&2
exit 1
}
[ "$head_commit" = "$remote_main_commit" ] || {
printf 'HEAD must exactly match %s/%s before release\n' "$REMOTE" "$BRANCH" >&2
git merge-base --is-ancestor HEAD "$remote_main" || {
printf 'HEAD must be contained in %s/%s history before release\n' "$REMOTE" "$BRANCH" >&2
exit 1
}
if git rev-parse --verify --quiet "refs/tags/$VERSION" >/dev/null; then
@@ -227,11 +221,6 @@ else
printf 'stable beta baseline is not an ancestor of HEAD: %s\n' "$FROM_BETA" >&2
exit 1
}
if ! git diff --quiet "$FROM_BETA^{commit}" HEAD -- . ':(exclude)CHANGELOG.md'; then
printf 'stable source drifted from %s; only CHANGELOG.md may differ\n' "$FROM_BETA" >&2
git diff --name-only "$FROM_BETA^{commit}" HEAD -- . ':(exclude)CHANGELOG.md' >&2
exit 1
fi
fi
semver="$(release_semver "$VERSION")"
+6 -7
View File
@@ -351,7 +351,7 @@ else
if [ -n "$previous_stable" ]; then
printf '==> Comparing command tree with %s\n' "$previous_stable"
"$ROOT/scripts/policy/check-command-compatibility.sh" \
--base-ref "$REMOTE/$BRANCH" \
--base-ref HEAD \
--stable-ref "$previous_stable"
fi
@@ -405,7 +405,7 @@ if [ "$previous_stable" != "$previous_stable_before_refresh" ]; then
printf '==> Stable authority advanced from %s to %s; rechecking command compatibility\n' \
"${previous_stable_before_refresh:-none}" "$previous_stable"
"$ROOT/scripts/policy/check-command-compatibility.sh" \
--base-ref "$REMOTE/$BRANCH" \
--base-ref HEAD \
--stable-ref "$previous_stable"
fi
@@ -416,9 +416,9 @@ fi
# Delivery, compatibility, and publication checks above may take long enough
# for main or stable authority to move. This last refresh must be followed only
# by local proof/tag creation. The atomic push advertises main with the tag, so
# an already-advanced remote main rejects the whole transaction; a later main
# advance is safe because the sealed commit remains in protected main history.
# by local proof/tag creation. Only the tag is pushed: the sealed commit is
# already contained in protected main history, so a later main advance never
# invalidates the release.
printf '==> Settling final %s/%s and stable authority\n' "$REMOTE" "$BRANCH"
git fetch --force "$REMOTE" "+refs/heads/$BRANCH:refs/remotes/$REMOTE/$BRANCH"
fetch_release_tags
@@ -447,8 +447,7 @@ else
git tag -a "$VERSION" -m "Release $VERSION" -m 'Channel: prerelease'
fi
if ! git push --atomic "$push_url" \
"HEAD:refs/heads/$BRANCH" "refs/tags/$VERSION"; then
if ! git push "$push_url" "refs/tags/$VERSION"; then
set +e
remote_refs="$(git ls-remote --tags "$push_url" "refs/tags/$VERSION" "refs/tags/$VERSION^{}")"
query_status=$?
+42 -4
View File
@@ -72,7 +72,7 @@ else
exit 1
fi
verify_binary_version() {
verify_binary_archive() {
asset="$1"
extract_dir="$tmp/extract-${asset}"
mkdir -p "$extract_dir"
@@ -94,14 +94,52 @@ verify_binary_version() {
printf '%s does not contain the expected dws binary\n' "$asset" >&2
return 1
}
strings "$binary" | grep -Fqx "v$SEMVER" || {
printf '%s binary does not embed expected version v%s\n' "$asset" "$SEMVER" >&2
LC_ALL=C grep -aFq "v$SEMVER" "$binary" || {
printf '%s binary does not contain expected version marker v%s\n' \
"$asset" "$SEMVER" >&2
return 1
}
# Execute one native artifact and validate the CLI's public version contract.
# `strings` output has no symbol boundaries, so requiring the injected version
# to appear on an exact line can reject a correct Go binary when adjacent
# printable bytes are coalesced into the same output line.
if [ "$asset" = dws-linux-amd64.tar.gz ]; then
command -v python3 >/dev/null 2>&1 || {
printf 'python3 is required to validate the release binary version\n' >&2
return 1
}
version_json="$extract_dir/version.json"
isolated_home="$extract_dir/home"
mkdir -p "$isolated_home"
if ! env -i HOME="$isolated_home" PATH=/usr/bin:/bin LANG=C.UTF-8 \
"$binary" version --format json >"$version_json"; then
printf '%s binary could not report its version\n' "$asset" >&2
return 1
fi
reported_version="$(python3 -c '
import json
import sys
with open(sys.argv[1], encoding="utf-8") as handle:
payload = json.load(handle)
version = payload.get("version")
if not isinstance(version, str) or not version:
raise SystemExit(1)
print(version)
' "$version_json")" || {
printf '%s binary returned an invalid version payload\n' "$asset" >&2
return 1
}
[ "$reported_version" = "v$SEMVER" ] || {
printf '%s binary reports version %s, expected v%s\n' \
"$asset" "$reported_version" "$SEMVER" >&2
return 1
}
fi
}
for asset in $EXPECTED_PLATFORM_ASSETS; do
verify_binary_version "$asset"
verify_binary_archive "$asset"
done
printf 'Release artifacts verified for v%s.\n' "$SEMVER"
+171
View File
@@ -637,6 +637,33 @@ func releaseWorkflowSection(t *testing.T, workflow, startMarker, endMarker strin
return workflow[start : start+len(startMarker)+end]
}
func releaseWorkflowRunScript(t *testing.T, workflow, stepName, nextStepName string) string {
t.Helper()
section := releaseWorkflowSection(
t,
workflow,
" - name: "+stepName+"\n",
"\n - name: "+nextStepName+"\n",
)
const runMarker = " run: |\n"
start := strings.Index(section, runMarker)
if start == -1 {
t.Fatalf("release workflow step %q is missing a run block", stepName)
}
lines := strings.Split(section[start+len(runMarker):], "\n")
for i, line := range lines {
if line == "" {
continue
}
if !strings.HasPrefix(line, " ") {
t.Fatalf("release workflow step %q has an unexpected run indentation: %q", stepName, line)
}
lines[i] = strings.TrimPrefix(line, " ")
}
return strings.Join(lines, "\n")
}
func TestReleaseWorkflowUsesDedicatedGovernanceIdentity(t *testing.T) {
t.Parallel()
workflow := readReleaseWorkflow(t)
@@ -1794,6 +1821,150 @@ func TestReleaseWorkflowOpensVersionedHomebrewPRForBetaTags(t *testing.T) {
}
}
func TestReleaseWorkflowWaitsForNPMDistTagPropagation(t *testing.T) {
workflow := readReleaseWorkflow(t)
script := releaseWorkflowRunScript(
t,
workflow,
"Verify npm channel delivery",
"Sync release artifacts to China OSS mirror",
)
tests := []struct {
name string
sequence string
wantSuccess bool
wantCalls int
wantSleeps int
wantOutput string
}{
{
name: "stale beta converges to target",
sequence: "1.0.53-beta.6\n1.0.53-beta.6\n1.0.53-beta.7\n",
wantSuccess: true,
wantCalls: 3,
wantSleeps: 2,
},
{
name: "stale beta never converges",
sequence: "1.0.53-beta.6\n",
wantCalls: 12,
wantSleeps: 11,
wantOutput: "still reports older v1.0.53-beta.6 after 12 attempts",
},
{
name: "permanent registry error fails immediately",
sequence: "__NPM_ERROR__\n",
wantCalls: 1,
wantSleeps: 0,
wantOutput: "permanent npm registry error",
},
}
for _, test := range tests {
t.Run(test.name, func(t *testing.T) {
root := t.TempDir()
fakeBin := filepath.Join(root, "bin")
if err := os.MkdirAll(fakeBin, 0o755); err != nil {
t.Fatalf("MkdirAll(%s) error = %v", fakeBin, err)
}
sequencePath := filepath.Join(root, "sequence")
statePath := filepath.Join(root, "state")
npmLogPath := filepath.Join(root, "npm.log")
sleepLogPath := filepath.Join(root, "sleep.log")
mustWriteFile(t, sequencePath, []byte(test.sequence), 0o644)
mustWriteFile(t, filepath.Join(fakeBin, "npm"), []byte(`#!/bin/sh
set -eu
printf '%s\n' "$*" >> "$NPM_CALL_LOG"
test "$*" = "view dingtalk-workspace-cli dist-tags.beta --registry=https://registry.npmjs.org --prefer-online" || {
echo "unexpected npm mutation: $*" >&2
exit 97
}
call=0
if test -f "$NPM_STATE"; then call="$(cat "$NPM_STATE")"; fi
call=$((call + 1))
printf '%s\n' "$call" > "$NPM_STATE"
value="$(sed -n "${call}p" "$NPM_SEQUENCE")"
if test -z "$value"; then value="$(tail -n 1 "$NPM_SEQUENCE")"; fi
if test "$value" = "__NPM_ERROR__"; then
echo "permanent npm registry error" >&2
exit 42
fi
printf '%s\n' "$value"
`), 0o755)
mustWriteFile(t, filepath.Join(fakeBin, "sleep"), []byte(`#!/bin/sh
set -eu
printf '%s\n' "$*" >> "$SLEEP_CALL_LOG"
`), 0o755)
repoRoot, err := filepath.Abs(filepath.Join("..", ".."))
if err != nil {
t.Fatalf("Abs(repository root) error = %v", err)
}
cmd := exec.Command("sh", "-c", script)
cmd.Dir = repoRoot
cmd.Env = append(os.Environ(),
"PATH="+fakeBin+string(os.PathListSeparator)+os.Getenv("PATH"),
"NPM_TAG=beta",
"SEMVER=1.0.53-beta.7",
"NPM_SEQUENCE="+sequencePath,
"NPM_STATE="+statePath,
"NPM_CALL_LOG="+npmLogPath,
"SLEEP_CALL_LOG="+sleepLogPath,
)
output, runErr := cmd.CombinedOutput()
if test.wantSuccess && runErr != nil {
t.Fatalf("npm delivery verification error = %v\noutput:\n%s", runErr, output)
}
if !test.wantSuccess && runErr == nil {
t.Fatalf("npm delivery verification unexpectedly succeeded\noutput:\n%s", output)
}
if test.wantOutput != "" && !strings.Contains(string(output), test.wantOutput) {
t.Errorf("npm delivery verification output is missing %q:\n%s", test.wantOutput, output)
}
npmLog, err := os.ReadFile(npmLogPath)
if err != nil {
t.Fatalf("ReadFile(%s) error = %v", npmLogPath, err)
}
npmCalls := strings.Split(strings.TrimSpace(string(npmLog)), "\n")
if got := len(npmCalls); got != test.wantCalls {
t.Errorf("npm view call count = %d, want %d; log:\n%s", got, test.wantCalls, npmLog)
}
if strings.Contains(string(npmLog), "dist-tag add") || strings.Contains(string(npmLog), "publish") {
t.Errorf("delivery verification must remain read-only; log:\n%s", npmLog)
}
sleepCalls := 0
if sleepLog, err := os.ReadFile(sleepLogPath); err == nil {
sleepCalls = len(strings.Fields(string(sleepLog)))
} else if !os.IsNotExist(err) {
t.Fatalf("ReadFile(%s) error = %v", sleepLogPath, err)
}
if sleepCalls != test.wantSleeps {
t.Errorf("sleep call count = %d, want %d", sleepCalls, test.wantSleeps)
}
})
}
}
func TestReleaseWorkflowUsesTrustedArtifactVerifierForRecovery(t *testing.T) {
t.Parallel()
workflow := readReleaseWorkflow(t)
trusted := `"$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/verify-release-artifacts.sh"`
if got := strings.Count(workflow, trusted); got != 6 {
t.Fatalf("trusted artifact verifier call count = %d, want 6", got)
}
workspaceDist := `DWS_PACKAGE_DIST_DIR="$GITHUB_WORKSPACE/dist" \` + "\n" +
` "$GITHUB_WORKSPACE/tmp/trusted-release-tooling/scripts/release/verify-release-artifacts.sh"`
if got := strings.Count(workflow, workspaceDist); got != 3 {
t.Fatalf("workspace dist-bound trusted verifier call count = %d, want 3", got)
}
if strings.Contains(workflow, "./scripts/release/verify-release-artifacts.sh") {
t.Fatal("release workflow still executes the sealed tag's artifact verifier")
}
}
func TestReleaseStaysDraftUntilFinalizedAssetDigestsMatch(t *testing.T) {
t.Parallel()
+73 -11
View File
@@ -30,7 +30,18 @@ func writeVersionedReleaseArchive(t *testing.T, dist, asset, version string) {
if strings.HasSuffix(asset, ".zip") {
binary = "dws.exe"
}
mustWriteFile(t, filepath.Join(stage, binary), []byte("fake release binary\n"+version+"\n"), 0o755)
content := []byte("fake release binary\n" + version + "\n")
if asset == "dws-linux-amd64.tar.gz" {
content = []byte(fmt.Sprintf(`#!/bin/sh
set -eu
if [ "$#" -ne 3 ] || [ "$1" != version ] || [ "$2" != --format ] || [ "$3" != json ]; then
printf 'unexpected version command\n' >&2
exit 2
fi
printf '{"version":"%s"}\n'
`, version))
}
mustWriteFile(t, filepath.Join(stage, binary), content, 0o755)
if strings.HasSuffix(asset, ".zip") {
mustRun(t, stage, "zip", "-q", filepath.Join(dist, asset), binary)
return
@@ -1494,12 +1505,12 @@ func TestReleaseContractRejectsDirtyOrUnsyncedMain(t *testing.T) {
"--version", "v1.0.1-beta.1",
"--remote", "origin",
)
if err == nil || !strings.Contains(output, "must exactly match origin/main") {
if err == nil || !strings.Contains(output, "must be contained in origin/main history") {
t.Fatalf("unsynced main was not blocked: err=%v\noutput:\n%s", err, output)
}
}
func TestReleaseContractStablePromotionAllowsOnlyChangelogDiff(t *testing.T) {
func TestReleaseContractStablePromotionRequiresBetaAncestry(t *testing.T) {
t.Run("sealed", func(t *testing.T) {
r := newReleaseTestRepo(t)
r.seedBeta(t)
@@ -1518,12 +1529,12 @@ func TestReleaseContractStablePromotionAllowsOnlyChangelogDiff(t *testing.T) {
}
})
t.Run("source drift", func(t *testing.T) {
t.Run("commits after beta", func(t *testing.T) {
r := newReleaseTestRepo(t)
r.seedBeta(t)
mustWriteFile(t, filepath.Join(r.root, "CHANGELOG.md"), []byte(releaseChangelog(stableSection(), betaSection())), 0o644)
mustWriteFile(t, filepath.Join(r.root, "drift.txt"), []byte("untested change\n"), 0o644)
r.commitAndPush(t, "drift after beta")
mustWriteFile(t, filepath.Join(r.root, "followup.txt"), []byte("merged after beta\n"), 0o644)
r.commitAndPush(t, "merge follow-up after beta")
output, err := runReleaseScript(t, r.root, r.contract,
"--repo-root", r.root,
@@ -1532,11 +1543,53 @@ func TestReleaseContractStablePromotionAllowsOnlyChangelogDiff(t *testing.T) {
"--from-beta", "v1.0.1-beta.1",
"--remote", "origin",
)
if err == nil {
t.Fatalf("drifted stable promotion unexpectedly passed:\n%s", output)
if err != nil {
t.Fatalf("stable promotion with commits after beta error = %v\noutput:\n%s", err, output)
}
if !strings.Contains(output, "only CHANGELOG.md may differ") || !strings.Contains(output, "drift.txt") {
t.Fatalf("drift output is not actionable:\n%s", output)
})
t.Run("beta outside HEAD history", func(t *testing.T) {
r := newReleaseTestRepo(t)
mustRun(t, r.root, "git", "checkout", "-b", "sidecar")
mustWriteFile(t, filepath.Join(r.root, "sidecar.txt"), []byte("never merged\n"), 0o644)
mustRun(t, r.root, "git", "add", ".")
mustRun(t, r.root, "git", "commit", "-m", "sidecar beta candidate")
mustRun(t, r.root, "git", "tag", "-a", "v1.0.1-beta.1", "-m", "Release v1.0.1-beta.1", "-m", "Channel: prerelease")
mustRun(t, r.root, "git", "checkout", "main")
mustWriteFile(t, filepath.Join(r.root, "CHANGELOG.md"), []byte(releaseChangelog(stableSection(), betaSection())), 0o644)
r.commitAndPush(t, "prepare stable changelog")
output, err := runReleaseScript(t, r.root, r.contract,
"--repo-root", r.root,
"--channel", "stable",
"--version", "v1.0.1",
"--from-beta", "v1.0.1-beta.1",
"--remote", "origin",
)
if err == nil || !strings.Contains(output, "not an ancestor of HEAD") {
t.Fatalf("beta outside HEAD history was promoted: err=%v\noutput:\n%s", err, output)
}
})
t.Run("older sealed commit after main advanced", func(t *testing.T) {
r := newReleaseTestRepo(t)
r.seedBeta(t)
mustWriteFile(t, filepath.Join(r.root, "CHANGELOG.md"), []byte(releaseChangelog(stableSection(), betaSection())), 0o644)
r.commitAndPush(t, "prepare stable changelog")
sealed := strings.TrimSpace(mustOutput(t, r.root, "git", "rev-parse", "HEAD"))
mustWriteFile(t, filepath.Join(r.root, "after.txt"), []byte("main advanced\n"), 0o644)
r.commitAndPush(t, "advance main after stable candidate")
mustRun(t, r.root, "git", "checkout", "--detach", sealed)
output, err := runReleaseScript(t, r.root, r.contract,
"--repo-root", r.root,
"--channel", "stable",
"--version", "v1.0.1",
"--from-beta", "v1.0.1-beta.1",
"--remote", "origin",
)
if err != nil {
t.Fatalf("older sealed commit in main history was rejected: %v\noutput:\n%s", err, output)
}
})
}
@@ -1906,9 +1959,18 @@ func TestReleaseArtifactVerificationRequiresEveryChecksum(t *testing.T) {
writeReleaseChecksums(t, dist, true)
cmd = exec.Command("sh", r.verify, "v1.2.3")
cmd.Env = append(os.Environ(), "DWS_PACKAGE_DIST_DIR="+dist)
if output, err := cmd.CombinedOutput(); err == nil || !strings.Contains(string(output), "dws-windows-arm64.zip binary") {
if output, err := cmd.CombinedOutput(); err == nil || !strings.Contains(string(output), "dws-windows-arm64.zip binary does not contain expected version marker v1.2.3") {
t.Fatalf("mixed-version archive was not rejected: err=%v\noutput:\n%s", err, output)
}
writeVersionedReleaseArchive(t, dist, "dws-windows-arm64.zip", "v1.2.3")
writeVersionedReleaseArchive(t, dist, "dws-linux-amd64.tar.gz", "v1.2.3-beta.1")
writeReleaseChecksums(t, dist, true)
cmd = exec.Command("sh", r.verify, "v1.2.3")
cmd.Env = append(os.Environ(), "DWS_PACKAGE_DIST_DIR="+dist)
if output, err := cmd.CombinedOutput(); err == nil || !strings.Contains(string(output), "dws-linux-amd64.tar.gz binary reports version v1.2.3-beta.1, expected v1.2.3") {
t.Fatalf("native prefixed version was not rejected: err=%v\noutput:\n%s", err, output)
}
}
func TestReleaseCommandValidatesThenPushesAnnotatedTag(t *testing.T) {