From 4c5fc3c991dbdc556c9b0c75d3aeb099dae0187e Mon Sep 17 00:00:00 2001 From: Chris Date: Mon, 28 Sep 2026 00:18:41 +0800 Subject: [PATCH] Use pinned release catalogs for Connect CPU acceptance (#8166) --- .../connect-profile-cpu-acceptance.yml | 20 ++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) diff --git a/.github/workflows/connect-profile-cpu-acceptance.yml b/.github/workflows/connect-profile-cpu-acceptance.yml index 27bd509ea..bfdec9c26 100644 --- a/.github/workflows/connect-profile-cpu-acceptance.yml +++ b/.github/workflows/connect-profile-cpu-acceptance.yml @@ -37,6 +37,10 @@ on: description: Expected rustfs binary SHA-256 required: true type: string + catalog_sha256: + description: Independently reviewed release CPU catalog SHA-256 + required: true + type: string connect_sha: description: Exact 40-character RustFS Connect harness commit required: true @@ -76,7 +80,7 @@ jobs: - name: Set up Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: - node-version: 22.22.2 + node-version: 25.8.1 cache: npm cache-dependency-path: connect-harness/web/package-lock.json @@ -129,24 +133,32 @@ jobs: run-id: ${{ inputs.build_run_id }} github-token: ${{ github.token }} - - name: Extract exact RustFS binary + - name: Extract exact RustFS binary and reviewed catalog shell: bash env: BINARY_SHA256: ${{ inputs.binary_sha256 }} + CATALOG_SHA256: ${{ inputs.catalog_sha256 }} SOURCE_SHA: ${{ inputs.source_sha }} run: | set -euo pipefail + [[ "$BINARY_SHA256" =~ ^[0-9a-f]{64}$ ]] + [[ "$CATALOG_SHA256" =~ ^[0-9a-f]{64}$ ]] short_sha=${SOURCE_SHA:0:7} package=$(find artifact -type f -name "rustfs-linux-x86_64-gnu-dev-${short_sha}.zip" -print -quit) [[ -n "$package" ]] mkdir -p binary - unzip -qq "$package" rustfs -d binary + unzip -qq "$package" rustfs rustfs.cpu-symbol-catalog.json rustfs.cpu-symbol-catalog.sha256 -d binary chmod +x binary/rustfs printf '%s %s\n' "$BINARY_SHA256" binary/rustfs | sha256sum --check --strict + # The packaged digest is corroboration, never the independent trust input. + [[ $(cat binary/rustfs.cpu-symbol-catalog.sha256) == "$CATALOG_SHA256" ]] + printf '%s %s\n' "$CATALOG_SHA256" binary/rustfs.cpu-symbol-catalog.json | sha256sum --check --strict + chmod 0444 binary/rustfs.cpu-symbol-catalog.json - name: Run signed service job acceptance shell: bash env: + CATALOG_SHA256: ${{ inputs.catalog_sha256 }} SOURCE_SHA: ${{ inputs.source_sha }} run: | set -euo pipefail @@ -156,6 +168,8 @@ jobs: make -C connect-harness e2e-connected-dispatch-check RUSTFS_BINARY="$GITHUB_WORKSPACE/binary/rustfs" \ RUSTFS_WORKTREE="$GITHUB_WORKSPACE/rustfs-source" \ + CONNECT_E2E_CPU_CATALOG="$GITHUB_WORKSPACE/binary/rustfs.cpu-symbol-catalog.json" \ + CONNECT_E2E_CPU_CATALOG_SHA256="$CATALOG_SHA256" \ CONNECT_E2E_PROFILE_EVIDENCE="$GITHUB_WORKSPACE/profile-service-job-evidence.json" \ make -C connect-harness e2e-connected E2E_SCENARIO=profile