From 95cb19f1a4c07612a77b35e7faad37b5877749b5 Mon Sep 17 00:00:00 2001 From: merefield Date: Mon, 24 Aug 2026 12:42:47 +0100 Subject: [PATCH 1/2] FIX: harden cross-platform release validation --- .github/workflows/release.yml | 12 ++++++++++++ test/install-release.ps1 | 9 ++++++--- 2 files changed, 18 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2059852..3bc50e5 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -77,6 +77,16 @@ jobs: with: fetch-depth: 0 ref: ${{ needs.validate.outputs.tag }} + - name: Verify validated commit + shell: bash + env: + EXPECTED_COMMIT: ${{ needs.validate.outputs.commit }} + run: | + actual_commit=$(git rev-parse HEAD) + if [[ "$actual_commit" != "$EXPECTED_COMMIT" ]]; then + echo "Release tag changed after validation." + exit 1 + fi - uses: actions/setup-go@v7 with: go-version: 1.26.6 @@ -98,6 +108,8 @@ jobs: run: go vet ./... - name: Test run: go test -race ./... + - name: Build + run: go build -buildvcs=false -trimpath ./cmd/clai - name: Test Unix release installer if: runner.os == 'Linux' run: bats test diff --git a/test/install-release.ps1 b/test/install-release.ps1 index f23b9c9..558bd52 100644 --- a/test/install-release.ps1 +++ b/test/install-release.ps1 @@ -53,12 +53,15 @@ with open(sys.argv[2], "w", encoding="ascii") as port_file: server.serve_forever() '@ $serverProcess = Start-Process -FilePath $python.Source -ArgumentList @($serverScript, $serverRoot, $portFile) -PassThru - for ($attempt = 0; $attempt -lt 50 -and -not (Test-Path -LiteralPath $portFile); $attempt++) { + $port = "" + for ($attempt = 0; $attempt -lt 50; $attempt++) { if ($serverProcess.HasExited) { throw "fixture HTTP server exited before reporting its port" } + if (Test-Path -LiteralPath $portFile) { + $port = ([string](Get-Content -LiteralPath $portFile -Raw)).Trim() + if ($port -match '^\d+$') { break } + } Start-Sleep -Milliseconds 100 } - if (-not (Test-Path -LiteralPath $portFile)) { throw "fixture HTTP server did not report its port" } - $port = (Get-Content -LiteralPath $portFile -Raw).Trim() if ($port -notmatch '^\d+$') { throw "fixture HTTP server reported an invalid port: $port" } $baseUrl = "http://127.0.0.1:$port" $webRequestArgs = @{} From 4dfb8ab0c1de4d52aec97ebc370d62f4a689e20a Mon Sep 17 00:00:00 2001 From: merefield Date: Mon, 24 Aug 2026 14:48:50 +0100 Subject: [PATCH 2/2] FIX: improve release commit diagnostics --- .github/workflows/release.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 3bc50e5..7cb40de 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -84,7 +84,8 @@ jobs: run: | actual_commit=$(git rev-parse HEAD) if [[ "$actual_commit" != "$EXPECTED_COMMIT" ]]; then - echo "Release tag changed after validation." + printf 'Release tag changed after validation (expected %s, got %s).\n' \ + "$EXPECTED_COMMIT" "$actual_commit" >&2 exit 1 fi - uses: actions/setup-go@v7