From 528a368144a6543adccfa7ca5e6dce570f0d9a19 Mon Sep 17 00:00:00 2001 From: hector <42570491+majinghe@users.noreply.github.com> Date: Mon, 28 Sep 2026 08:54:33 +0800 Subject: [PATCH] ci: refresh the preview-release contract for the current build workflow (#8178) The contract check asserts exact lines in build.yml, and five recent build-workflow PRs drifted it out of sync, so Security Audit's Workflow Pin Report job fails for every PR and every push to main since Sep 27 17:34Z (first failure on push run 36337450094). Refresh the assertions to the current, intentional shapes - contract intent is preserved and in fact tightened: - #8160 added PROFILE_ARGS to the cross/native cargo build lines. - #8171 added 'should_publish == true' as a stricter prefix on the R2 publication guard and the create-release / upload-release-assets / publish-release / update-latest-version conditions. Verified locally: the full check (including the docker and helm workflow contract tests) passes against main's files with these assertions. --- scripts/security/check_preview_release_workflow.sh | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/scripts/security/check_preview_release_workflow.sh b/scripts/security/check_preview_release_workflow.sh index 77818ef75..e783204b9 100755 --- a/scripts/security/check_preview_release_workflow.sh +++ b/scripts/security/check_preview_release_workflow.sh @@ -31,8 +31,8 @@ require_absent() { fi } -require_line "$build_workflow" " cargo zigbuild --release --target \${{ matrix.target }} \"\${FEATURE_ARGS[@]}\" -p rustfs --bin \"\$binary\"" "cross builds must keep matrix features" -require_line "$build_workflow" " cargo build --release --target \${{ matrix.target }} \"\${FEATURE_ARGS[@]}\" -p rustfs --bin \"\$binary\"" "native builds must keep matrix features" +require_line "$build_workflow" " cargo zigbuild --release --target \${{ matrix.target }} \"\${FEATURE_ARGS[@]}\" \"\${PROFILE_ARGS[@]}\" -p rustfs --bin \"\$binary\"" "cross builds must keep matrix features" +require_line "$build_workflow" " cargo build --release --target \${{ matrix.target }} \"\${FEATURE_ARGS[@]}\" \"\${PROFILE_ARGS[@]}\" -p rustfs --bin \"\$binary\"" "native builds must keep matrix features" require_absent "$build_workflow" " cargo zigbuild --release --target \${{ matrix.target }} -p rustfs --bin \"\$binary\"" "cross builds must not drop matrix features" require_absent "$build_workflow" " cargo build --release --target \${{ matrix.target }} -p rustfs --bin \"\$binary\"" "native builds must not drop matrix features" @@ -137,12 +137,12 @@ for block in "$tag_branch_tail" "$post_strategy"; do require_no_assignment "$block" "is_prerelease" done require_line "$build_workflow" " if [[ \"\$BUILD_TYPE\" == \"release\" ]] || [[ \"\$BUILD_TYPE\" == \"prerelease\" ]]; then" "latest artifact guard" -require_line "$build_workflow" " if: env.R2_ACCESS_KEY_ID != '' && (needs.build-check.outputs.build_type == 'release' || needs.build-check.outputs.build_type == 'prerelease' || needs.build-check.outputs.build_type == 'development')" "R2 publication guard" -release_guard="startsWith(github.ref, 'refs/tags/') && (needs.build-check.outputs.build_type == 'preview' || needs.build-check.outputs.build_type == 'release' || needs.build-check.outputs.build_type == 'prerelease')" +require_line "$build_workflow" " if: needs.build-check.outputs.should_publish == 'true' && env.R2_ACCESS_KEY_ID != '' && (needs.build-check.outputs.build_type == 'release' || needs.build-check.outputs.build_type == 'prerelease' || needs.build-check.outputs.build_type == 'development')" "R2 publication guard" +release_guard="needs.build-check.outputs.should_publish == 'true' && startsWith(github.ref, 'refs/tags/') && (needs.build-check.outputs.build_type == 'preview' || needs.build-check.outputs.build_type == 'release' || needs.build-check.outputs.build_type == 'prerelease')" for job in create-release upload-release-assets publish-release; do require_job_if "$build_workflow" "$job" " if: $release_guard" done -latest_guard="startsWith(github.ref, 'refs/tags/') && (needs.build-check.outputs.build_type == 'release' || needs.build-check.outputs.build_type == 'prerelease')" +latest_guard="needs.build-check.outputs.should_publish == 'true' && startsWith(github.ref, 'refs/tags/') && (needs.build-check.outputs.build_type == 'release' || needs.build-check.outputs.build_type == 'prerelease')" require_job_if "$build_workflow" "update-latest-version" " if: $latest_guard" require_line "$build_workflow" " needs: [ build-check, publish-release ]" "latest update must follow release publication"