This commit is contained in:
@@ -187,7 +187,20 @@ KAIDI_PURGER_SHA256=$PURGER_SHA256
|
||||
EOF
|
||||
BOOTSTRAP_SHA256=$(sha256_file "$OUTPUT_DIR/bootstrap-checksums.txt")
|
||||
|
||||
RELEASE_NOTES_VALUE=${KAIDI_RELEASE_NOTES:-"Kaidi Finance Preview $VERSION"}
|
||||
RELEASE_NOTES_FILE=${KAIDI_RELEASE_NOTES_FILE:-$ROOT/release-notes/$VERSION.md}
|
||||
if [ -n "${KAIDI_RELEASE_NOTES+x}" ]; then
|
||||
RELEASE_NOTES_VALUE=$KAIDI_RELEASE_NOTES
|
||||
elif [ -f "$RELEASE_NOTES_FILE" ] && [ ! -L "$RELEASE_NOTES_FILE" ]; then
|
||||
RELEASE_NOTES_VALUE=$(sed 's/\r$//' "$RELEASE_NOTES_FILE")
|
||||
elif [ "$SOURCE_REF" != local ] || [ "${KAIDI_REQUIRE_RELEASE_NOTES:-false}" = true ]; then
|
||||
printf 'Release notes file is missing: %s\n' "$RELEASE_NOTES_FILE" >&2
|
||||
exit 1
|
||||
else
|
||||
RELEASE_NOTES_VALUE="Kaidi Finance Preview $VERSION"
|
||||
fi
|
||||
RELEASE_NOTES_BYTES=$(printf '%s' "$RELEASE_NOTES_VALUE" | wc -c | tr -d '[:space:]')
|
||||
[ "$RELEASE_NOTES_BYTES" -gt 0 ] && [ "$RELEASE_NOTES_BYTES" -le 4000 ] \
|
||||
|| { printf 'Release notes must contain 1 to 4000 bytes\n' >&2; exit 1; }
|
||||
VERSION="$VERSION" ARTIFACT="$ARTIFACT" SHA256="$SHA256" ARTIFACT_SIZE_BYTES="$ARTIFACT_SIZE_BYTES" \
|
||||
RELEASE_NOTES="$RELEASE_NOTES_VALUE" \
|
||||
BACKEND_SBOM_SHA256="$BACKEND_SBOM_SHA256" FRONTEND_SBOM_SHA256="$FRONTEND_SBOM_SHA256" \
|
||||
|
||||
@@ -10,9 +10,7 @@ SOURCE_SHA=${GITEA_SHA:-}
|
||||
TOKEN=${GITEA_TOKEN:-}
|
||||
RELEASE_DIR=${KAIDI_RELEASE_DIR:-dist/release}
|
||||
RELEASE_NAME=${KAIDI_RELEASE_NAME:-Kaidi Finance $TAG}
|
||||
RELEASE_BODY=${KAIDI_RELEASE_BODY:-Kaidi Finance $TAG
|
||||
|
||||
Source: $SOURCE_SHA}
|
||||
RELEASE_BODY=${KAIDI_RELEASE_BODY-}
|
||||
WORK=$(mktemp -d)
|
||||
AUTH_HEADER=$WORK/gitea-auth-header
|
||||
|
||||
@@ -38,6 +36,15 @@ esac
|
||||
|| fail 'GITEA_TOKEN is invalid'
|
||||
[ -d "$RELEASE_DIR" ] || fail 'release directory is missing'
|
||||
|
||||
if [ -z "${KAIDI_RELEASE_BODY+x}" ]; then
|
||||
RELEASE_NOTES=$(jq -er '.releaseNotes | strings | select(length > 0 and length <= 4000)' \
|
||||
"$RELEASE_DIR/release-manifest.json") \
|
||||
|| fail 'release manifest notes are missing or invalid'
|
||||
RELEASE_BODY="$RELEASE_NOTES
|
||||
|
||||
Source: $SOURCE_SHA"
|
||||
fi
|
||||
|
||||
printf 'Authorization: token %s\nAccept: application/json\n' "$TOKEN" > "$AUTH_HEADER"
|
||||
chmod 0600 "$AUTH_HEADER"
|
||||
|
||||
|
||||
@@ -29,6 +29,7 @@ for name in \
|
||||
SHA256SUMS; do
|
||||
printf 'fixture asset %s\n' "$name" > "$RELEASE_DIR/$name"
|
||||
done
|
||||
printf '%s\n' '{"releaseNotes":"Fixture release notes"}' > "$RELEASE_DIR/release-manifest.json"
|
||||
|
||||
cat > "$MOCK_BIN/curl" <<'SH'
|
||||
#!/usr/bin/env bash
|
||||
|
||||
@@ -315,6 +315,10 @@ download_and_prepare_install() {
|
||||
[ "$(jq -r '.requestId' "$fixture/state/status.json")" = 01M00000000000000000000091 ] \
|
||||
&& [ "$(jq -r '.action' "$fixture/state/status.json")" = DOWNLOAD ] \
|
||||
|| fail 'download phase did not preserve request correlation'
|
||||
[ "$(jq -r '.releaseNotes' "$fixture/state/status.json")" = fixture ] \
|
||||
|| fail 'download phase did not persist the signed release notes'
|
||||
[ "$(jq -r '.publishedAt' "$fixture/state/status.json")" = 2026-08-16T00:00:00Z ] \
|
||||
|| fail 'download phase did not persist the signed release publish time'
|
||||
[ "$(readlink "$fixture/app/current")" = "$fixture/app/releases/1.0.0-preview.1" ] \
|
||||
|| fail 'download phase changed the active application'
|
||||
[ -s "$fixture/state/cache/$version/release.tar.gz" ] \
|
||||
@@ -456,6 +460,8 @@ assert_success_case() {
|
||||
[ "$(jq -r '.requestId' "$fixture/state/status.json")" = 01M00000000000000000000092 ] \
|
||||
&& [ "$(jq -r '.action' "$fixture/state/status.json")" = INSTALL ] \
|
||||
|| fail 'success case did not preserve install request correlation'
|
||||
[ "$(jq -r '.releaseNotes' "$fixture/state/status.json")" = fixture ] \
|
||||
|| fail 'success case did not retain the signed release notes'
|
||||
[ ! -e "$fixture/state/processing/request.json" ] \
|
||||
|| fail 'success case left a claimed request behind'
|
||||
grep -qx 'daemon-reload' "$fixture/systemctl.log" || fail 'systemd units were not reloaded'
|
||||
|
||||
@@ -30,6 +30,11 @@ openssl dgst -sha256 -verify release-public.pem \
|
||||
VERSION=$(jq -er '.version | strings | select(length > 0)' release-manifest.json)
|
||||
"$ROOT/scripts/check-semver.sh" "$VERSION" \
|
||||
|| { printf 'Release version is not valid SemVer\n' >&2; exit 1; }
|
||||
RELEASE_NOTES=$(jq -er '.releaseNotes | strings | select(length > 0 and length <= 4000)' release-manifest.json) \
|
||||
|| { printf 'Release manifest must contain 1 to 4000 bytes of release notes\n' >&2; exit 1; }
|
||||
RELEASE_NOTES_BYTES=$(printf '%s' "$RELEASE_NOTES" | wc -c | tr -d '[:space:]')
|
||||
[ "$RELEASE_NOTES_BYTES" -le 4000 ] \
|
||||
|| { printf 'Release manifest release notes exceed 4000 bytes\n' >&2; exit 1; }
|
||||
ARTIFACT=$(jq -er '.artifact | strings | select(length > 0)' release-manifest.json)
|
||||
[ -s "$ARTIFACT" ] || { printf 'Release artifact is missing\n' >&2; exit 1; }
|
||||
[ "$ARTIFACT" = "kaidi-finance-$VERSION.tar.gz" ] \
|
||||
|
||||
Reference in New Issue
Block a user