Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions .github/actions/prepare/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ runs:
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0
with:
path: /mnt/kryptik/sources
key: sources-v2-${{ hashFiles('sources.lock') }}
key: sources-v3-${{ hashFiles('sources.lock') }}
# A changed lock restores the previous set and fetches only what is
# new; every file is still hashed against the lock.
restore-keys: ${{ inputs.sources == 'fetch' && 'sources-' || '' }}
Expand All @@ -55,11 +55,14 @@ runs:
run: |
make sources
./tools/prune-sources.sh
# The signatures too, so the set this job saves is the one CI's
# signature gate reads from disk; this pass is not the verdict.
./tools/verify-signatures.sh > /dev/null 2>&1 || true

# Saved as soon as the set is verified, not when the job ends: a job that
# fails later would otherwise fetch the lock's new files again next time.
- if: inputs.sources == 'fetch' && steps.sources.outputs.cache-hit != 'true'
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0
with:
path: /mnt/kryptik/sources
key: sources-v2-${{ hashFiles('sources.lock') }}
key: sources-v3-${{ hashFiles('sources.lock') }}
6 changes: 5 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -133,15 +133,19 @@ jobs:
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0
with:
path: /mnt/kryptik/sources
key: sources-v2-${{ hashFiles('sources.lock') }}
key: sources-v3-${{ hashFiles('sources.lock') }}
restore-keys: |
sources-

# The signatures are fetched here too, into the set the cache keeps:
# the gate below then reads them from disk instead of asking sixty
# hosts again on every run. What this pass says is not the verdict.
- name: Fetch and verify the sources
if: steps.sources.outputs.cache-hit != 'true'
run: |
make sources
./tools/prune-sources.sh
./tools/verify-signatures.sh > /dev/null 2>&1 || true

# Not from a pull request: its cache is scoped to its merge ref, so every
# one whose lock differs from main's would keep a whole copy of its own.
Expand Down
7 changes: 7 additions & 0 deletions tools/verify-signatures.sh
Original file line number Diff line number Diff line change
Expand Up @@ -714,6 +714,13 @@ verify_detached() {
report "$name" no-signature-upstream "no ${suffix} published beside the tarball"
return
fi
# A host can answer a busy runner with a page in place of the file: what
# came back is not kept, and the file is asked for once more.
if ! is_pgp_signature "$sig"; then
rm -f "$sig"
[[ "${KRYPTIK_SIGCHECK_SELFTEST:-0}" == "1" ]] || sleep 5
quiet_fetch "$sigurl" "$sig" || rm -f "$sig"
fi
if ! is_pgp_signature "$sig"; then
rm -f "$sig"
warn "${name}: the published ${suffix} is not an OpenPGP signature"
Expand Down
Loading