Skip to content

ci: verify the Qualcomm repository, and do not publish an unversioned build - #129

Open
Bjordis Collaku (bjordiscollaku) wants to merge 3 commits into
ci/phase1-docs-and-pinningfrom
ci/phase2-repo-and-suffix
Open

Bjordis Collaku (bjordiscollaku) wants to merge 3 commits into
ci/phase1-docs-and-pinningfrom
ci/phase2-repo-and-suffix

Conversation

@bjordiscollaku

@bjordiscollaku Bjordis Collaku (bjordiscollaku) commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Closes #132, closes #133.

Stacked on #128. That PR should be reviewed first; the diff here is only the three commits on this branch.

Repository signatures. The build added the Qualcomm repository with trusted=yes, disabling signature verification for everything it serves, and hardcoded the suite as resolute regardless of BASE_SUITE. The pkg-builder image already ships the signing key and a suite-matched sources file with Signed-By pointing at it, installed for its sbuild chroot, which this path does not use. Installing them verifies signatures and takes the suite from the image, so a noble build stops reading the resolute repository.

Exercised in run 37965472447 from the top of the stack: the repository was installed from the image's keyring, kgsl-dkms downloaded from it with signatures verified, and the build completed.

Unversioned builds. A failed version suffix was downgraded to a warning and the build continued, uploading packages named after the released upload while containing something else. The upload is now gated on the suffix step, and the script now actually reports failure: previously all nine of its exit paths returned 0, including the seven where a devel build could not be versioned, so a gate on its exit code could never fire. It now exits 1 on those seven and 0 only for the two legitimate skips, a build that is not resolute-qcom-devel and a HEAD exactly on a sync tag. A failure is an error annotation and the packages stay on the runner, so the build remains inspectable but cannot be mistaken for the upload it would have overwritten.

Driving the paths with a stub gh confirms it: with gh missing, the case #133 describes, the old script exits 0 and the build publishes; the new one exits 1 and withholds it. Devel PR checks are unaffected, since the Compare API resolves their merge ref and the suffix still applies (#151's check: +qcom93.b632b297def4, uploaded).

One consequence: builds using devel_prs merge locally, so the API never sees an ancestor tag, and they now withhold their packages instead of publishing them unsuffixed.

The gate is still a stopgap. The coupling that makes the step fallible, and the devel_prs limitation, are tracked in #137.

@bjordiscollaku Bjordis Collaku (bjordiscollaku) changed the title ci: verify the Qualcomm repository, and stop publishing an unversioned build ci: verify the Qualcomm repository, and do not publish an unversioned build Oct 7, 2026
The build added the Qualcomm repository by writing a sources line with
trusted=yes, which disables signature verification for everything that
repository serves, and hardcoded the suite as "resolute" regardless of
BASE_SUITE.

The pkg-builder image already ships what this needs: the signing key at
/tmp/keyrings/qsc-deb-releases.asc and a sources file naming the matching
suite with Signed-By pointing at it. Those exist because the image installs
them into its sbuild chroot, which this build path does not use, so they
were sitting unused in an image this build already runs.

Install them instead. Signatures are verified, and the suite comes from the
image rather than a literal, so a noble build stops pointing at the
resolute repository.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
apply-local-version-suffix.sh appends +qcom<N>.<sha> to the changelog for
resolute-qcom-devel builds carrying commits past the last sync tag, so they
outrank a plain rebuild of that tag. Its failure was downgraded to a
warning and the build continued, which published a package named after the
released upload while containing something else. The script also degrades
to the same unmodified version on several internal conditions, each of
which only emits a warning.

Record whether the suffix was applied and gate the S3 upload on it. A
failure is now an error annotation and the packages stay on the runner, so
the build is still available for inspection but cannot be mistaken for the
upload it would otherwise have overwritten.

This is a stopgap. The underlying coupling, deriving the suffix from the
GitHub API because the checkout is shallow, is what makes the step fallible
at all, and is better addressed by deriving it from the tags themselves.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
The previous commit withholds the upload when
apply-local-version-suffix.sh exits non-zero, but every path in the
script exited 0, including the seven where a resolute-qcom-devel build
could not be versioned: missing host tools, tags that cannot be listed
or are absent, no ancestor tag, an unresolvable DEBIAN directory or
changelog, and an unexpected HEAD SHA. The gate therefore only caught
crashes, and a build with gh missing, the case #133 describes, was
still published under the released version of the tag it sits on.

Route those seven paths through a fail helper that reports ::error::
and exits 1. The two legitimate skips, a build that is not
resolute-qcom-devel and a HEAD that is exactly a sync tag, still exit 0.

Checked by driving the paths with a stub gh: six of the seven failures
now exit 1, where before they exited 0, and the three non-failure
paths still exit 0. The unexpected-SHA path cannot be produced through
git rev-parse. Devel PR checks are unaffected: they build the PR merge
ref, which the Compare API resolves, so the suffix still applies and
the packages still upload.

Builds using devel_prs merge locally, so the API never sees an ancestor
tag; they now withhold their packages instead of publishing them
unsuffixed. #137 removes that limitation.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
@bjordiscollaku
Bjordis Collaku (bjordiscollaku) marked this pull request as ready for review October 9, 2026 18:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant