feat: show signed release changelog in update history
Release / release (push) Canceled after 0s

This commit is contained in:
Qiufeng
2026-08-19 08:27:08 +08:00
parent fae8225299
commit 6b04d8dd0a
15 changed files with 190 additions and 243 deletions
+14 -1
View File
@@ -187,7 +187,20 @@ KAIDI_PURGER_SHA256=$PURGER_SHA256
EOF
BOOTSTRAP_SHA256=$(sha256_file "$OUTPUT_DIR/bootstrap-checksums.txt")
RELEASE_NOTES_VALUE=${KAIDI_RELEASE_NOTES:-"Kaidi Finance Preview $VERSION"}
RELEASE_NOTES_FILE=${KAIDI_RELEASE_NOTES_FILE:-$ROOT/release-notes/$VERSION.md}
if [ -n "${KAIDI_RELEASE_NOTES+x}" ]; then
RELEASE_NOTES_VALUE=$KAIDI_RELEASE_NOTES
elif [ -f "$RELEASE_NOTES_FILE" ] && [ ! -L "$RELEASE_NOTES_FILE" ]; then
RELEASE_NOTES_VALUE=$(sed 's/\r$//' "$RELEASE_NOTES_FILE")
elif [ "$SOURCE_REF" != local ] || [ "${KAIDI_REQUIRE_RELEASE_NOTES:-false}" = true ]; then
printf 'Release notes file is missing: %s\n' "$RELEASE_NOTES_FILE" >&2
exit 1
else
RELEASE_NOTES_VALUE="Kaidi Finance Preview $VERSION"
fi
RELEASE_NOTES_BYTES=$(printf '%s' "$RELEASE_NOTES_VALUE" | wc -c | tr -d '[:space:]')
[ "$RELEASE_NOTES_BYTES" -gt 0 ] && [ "$RELEASE_NOTES_BYTES" -le 4000 ] \
|| { printf 'Release notes must contain 1 to 4000 bytes\n' >&2; exit 1; }
VERSION="$VERSION" ARTIFACT="$ARTIFACT" SHA256="$SHA256" ARTIFACT_SIZE_BYTES="$ARTIFACT_SIZE_BYTES" \
RELEASE_NOTES="$RELEASE_NOTES_VALUE" \
BACKEND_SBOM_SHA256="$BACKEND_SBOM_SHA256" FRONTEND_SBOM_SHA256="$FRONTEND_SBOM_SHA256" \
+10 -3
View File
@@ -10,9 +10,7 @@ SOURCE_SHA=${GITEA_SHA:-}
TOKEN=${GITEA_TOKEN:-}
RELEASE_DIR=${KAIDI_RELEASE_DIR:-dist/release}
RELEASE_NAME=${KAIDI_RELEASE_NAME:-Kaidi Finance $TAG}
RELEASE_BODY=${KAIDI_RELEASE_BODY:-Kaidi Finance $TAG
Source: $SOURCE_SHA}
RELEASE_BODY=${KAIDI_RELEASE_BODY-}
WORK=$(mktemp -d)
AUTH_HEADER=$WORK/gitea-auth-header
@@ -38,6 +36,15 @@ esac
|| fail 'GITEA_TOKEN is invalid'
[ -d "$RELEASE_DIR" ] || fail 'release directory is missing'
if [ -z "${KAIDI_RELEASE_BODY+x}" ]; then
RELEASE_NOTES=$(jq -er '.releaseNotes | strings | select(length > 0 and length <= 4000)' \
"$RELEASE_DIR/release-manifest.json") \
|| fail 'release manifest notes are missing or invalid'
RELEASE_BODY="$RELEASE_NOTES
Source: $SOURCE_SHA"
fi
printf 'Authorization: token %s\nAccept: application/json\n' "$TOKEN" > "$AUTH_HEADER"
chmod 0600 "$AUTH_HEADER"
+1
View File
@@ -29,6 +29,7 @@ for name in \
SHA256SUMS; do
printf 'fixture asset %s\n' "$name" > "$RELEASE_DIR/$name"
done
printf '%s\n' '{"releaseNotes":"Fixture release notes"}' > "$RELEASE_DIR/release-manifest.json"
cat > "$MOCK_BIN/curl" <<'SH'
#!/usr/bin/env bash
+6
View File
@@ -315,6 +315,10 @@ download_and_prepare_install() {
[ "$(jq -r '.requestId' "$fixture/state/status.json")" = 01M00000000000000000000091 ] \
&& [ "$(jq -r '.action' "$fixture/state/status.json")" = DOWNLOAD ] \
|| fail 'download phase did not preserve request correlation'
[ "$(jq -r '.releaseNotes' "$fixture/state/status.json")" = fixture ] \
|| fail 'download phase did not persist the signed release notes'
[ "$(jq -r '.publishedAt' "$fixture/state/status.json")" = 2026-08-16T00:00:00Z ] \
|| fail 'download phase did not persist the signed release publish time'
[ "$(readlink "$fixture/app/current")" = "$fixture/app/releases/1.0.0-preview.1" ] \
|| fail 'download phase changed the active application'
[ -s "$fixture/state/cache/$version/release.tar.gz" ] \
@@ -456,6 +460,8 @@ assert_success_case() {
[ "$(jq -r '.requestId' "$fixture/state/status.json")" = 01M00000000000000000000092 ] \
&& [ "$(jq -r '.action' "$fixture/state/status.json")" = INSTALL ] \
|| fail 'success case did not preserve install request correlation'
[ "$(jq -r '.releaseNotes' "$fixture/state/status.json")" = fixture ] \
|| fail 'success case did not retain the signed release notes'
[ ! -e "$fixture/state/processing/request.json" ] \
|| fail 'success case left a claimed request behind'
grep -qx 'daemon-reload' "$fixture/systemctl.log" || fail 'systemd units were not reloaded'
+5
View File
@@ -30,6 +30,11 @@ openssl dgst -sha256 -verify release-public.pem \
VERSION=$(jq -er '.version | strings | select(length > 0)' release-manifest.json)
"$ROOT/scripts/check-semver.sh" "$VERSION" \
|| { printf 'Release version is not valid SemVer\n' >&2; exit 1; }
RELEASE_NOTES=$(jq -er '.releaseNotes | strings | select(length > 0 and length <= 4000)' release-manifest.json) \
|| { printf 'Release manifest must contain 1 to 4000 bytes of release notes\n' >&2; exit 1; }
RELEASE_NOTES_BYTES=$(printf '%s' "$RELEASE_NOTES" | wc -c | tr -d '[:space:]')
[ "$RELEASE_NOTES_BYTES" -le 4000 ] \
|| { printf 'Release manifest release notes exceed 4000 bytes\n' >&2; exit 1; }
ARTIFACT=$(jq -er '.artifact | strings | select(length > 0)' release-manifest.json)
[ -s "$ARTIFACT" ] || { printf 'Release artifact is missing\n' >&2; exit 1; }
[ "$ARTIFACT" = "kaidi-finance-$VERSION.tar.gz" ] \