Repository navigation
ci: verify the Qualcomm repository, and do not publish an unversioned build - #129
Open
Bjordis Collaku (bjordiscollaku) wants to merge 3 commits into
Open
Bjordis Collaku (bjordiscollaku) wants to merge 3 commits into
Bjordis Collaku (bjordiscollaku) wants to merge 3 commits into
Conversation
Bjordis Collaku (bjordiscollaku)
force-pushed
the
ci/phase2-repo-and-suffix
branch
from
October 7, 2026 23:12
911a7b4 to
7ce0eb8
Compare
The build added the Qualcomm repository by writing a sources line with trusted=yes, which disables signature verification for everything that repository serves, and hardcoded the suite as "resolute" regardless of BASE_SUITE. The pkg-builder image already ships what this needs: the signing key at /tmp/keyrings/qsc-deb-releases.asc and a sources file naming the matching suite with Signed-By pointing at it. Those exist because the image installs them into its sbuild chroot, which this build path does not use, so they were sitting unused in an image this build already runs. Install them instead. Signatures are verified, and the suite comes from the image rather than a literal, so a noble build stops pointing at the resolute repository. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
apply-local-version-suffix.sh appends +qcom<N>.<sha> to the changelog for resolute-qcom-devel builds carrying commits past the last sync tag, so they outrank a plain rebuild of that tag. Its failure was downgraded to a warning and the build continued, which published a package named after the released upload while containing something else. The script also degrades to the same unmodified version on several internal conditions, each of which only emits a warning. Record whether the suffix was applied and gate the S3 upload on it. A failure is now an error annotation and the packages stay on the runner, so the build is still available for inspection but cannot be mistaken for the upload it would otherwise have overwritten. This is a stopgap. The underlying coupling, deriving the suffix from the GitHub API because the checkout is shallow, is what makes the step fallible at all, and is better addressed by deriving it from the tags themselves. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
Bjordis Collaku (bjordiscollaku)
force-pushed
the
ci/phase1-docs-and-pinning
branch
from
October 8, 2026 17:28
900bfb6 to
24f98de
Compare
Bjordis Collaku (bjordiscollaku)
force-pushed
the
ci/phase2-repo-and-suffix
branch
from
October 8, 2026 17:28
7ce0eb8 to
a91e58a
Compare
This was referenced Oct 8, 2026
The previous commit withholds the upload when apply-local-version-suffix.sh exits non-zero, but every path in the script exited 0, including the seven where a resolute-qcom-devel build could not be versioned: missing host tools, tags that cannot be listed or are absent, no ancestor tag, an unresolvable DEBIAN directory or changelog, and an unexpected HEAD SHA. The gate therefore only caught crashes, and a build with gh missing, the case #133 describes, was still published under the released version of the tag it sits on. Route those seven paths through a fail helper that reports ::error:: and exits 1. The two legitimate skips, a build that is not resolute-qcom-devel and a HEAD that is exactly a sync tag, still exit 0. Checked by driving the paths with a stub gh: six of the seven failures now exit 1, where before they exited 0, and the three non-failure paths still exit 0. The unexpected-SHA path cannot be produced through git rev-parse. Devel PR checks are unaffected: they build the PR merge ref, which the Compare API resolves, so the suffix still applies and the packages still upload. Builds using devel_prs merge locally, so the API never sees an ancestor tag; they now withhold their packages instead of publishing them unsuffixed. #137 removes that limitation. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
Bjordis Collaku (bjordiscollaku)
force-pushed
the
ci/phase2-repo-and-suffix
branch
from
October 9, 2026 18:35
ad131fa to
f11a415
Compare
Bjordis Collaku (bjordiscollaku)
marked this pull request as ready for review
October 9, 2026 18:37
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #132, closes #133.
Stacked on #128. That PR should be reviewed first; the diff here is only the three commits on this branch.
Repository signatures. The build added the Qualcomm repository with
trusted=yes, disabling signature verification for everything it serves, and hardcoded the suite asresoluteregardless ofBASE_SUITE. The pkg-builder image already ships the signing key and a suite-matched sources file withSigned-Bypointing at it, installed for its sbuild chroot, which this path does not use. Installing them verifies signatures and takes the suite from the image, so a noble build stops reading the resolute repository.Exercised in run 37965472447 from the top of the stack: the repository was installed from the image's keyring,
kgsl-dkmsdownloaded from it with signatures verified, and the build completed.Unversioned builds. A failed version suffix was downgraded to a warning and the build continued, uploading packages named after the released upload while containing something else. The upload is now gated on the suffix step, and the script now actually reports failure: previously all nine of its exit paths returned 0, including the seven where a devel build could not be versioned, so a gate on its exit code could never fire. It now exits 1 on those seven and 0 only for the two legitimate skips, a build that is not
resolute-qcom-develand a HEAD exactly on a sync tag. A failure is an error annotation and the packages stay on the runner, so the build remains inspectable but cannot be mistaken for the upload it would have overwritten.Driving the paths with a stub
ghconfirms it: withghmissing, the case #133 describes, the old script exits 0 and the build publishes; the new one exits 1 and withholds it. Devel PR checks are unaffected, since the Compare API resolves their merge ref and the suffix still applies (#151's check:+qcom93.b632b297def4, uploaded).One consequence: builds using
devel_prsmerge locally, so the API never sees an ancestor tag, and they now withhold their packages instead of publishing them unsuffixed.The gate is still a stopgap. The coupling that makes the step fallible, and the
devel_prslimitation, are tracked in #137.