Repository navigation
fix(release): count debug-symbols siblings separately in the SHA256SUMS guard - #6691
Conversation
…MS guard #6677 added four `librefang-<target>-debug-symbols.tar.gz.sha256` assets but left the sibling-count guard at `EXPECTED_PLATFORMS=12`. The guard is deliberately an equality so matrix drift stops a release loudly, so the new assets read as four extra platforms: v2026.7.31 — the first release cut after #6677 landed — failed with `expected exactly 12 .sha256 siblings, got 16`, after every artifact had already been built and published. Splits the list before counting. Platform binaries keep the strict `= 12`. Debug symbols get `2..4`, matching how they are produced: `cli_mac` fails when its .dSYM is missing so both macOS targets are guaranteed, while the cross-compiled `cli_linux` targets only warn when the .dwp is absent. Below 2 means the macOS hard-failure path did not hold and stops the release; 2 or 3 warns rather than failing over a diagnostic aid. The manifest is unchanged — the download loop and `ls *.sha256` still read the full list, so every hash including debug-symbols stays in SHA256SUMS and under the cosign signature. Verification: the guard was extracted from the workflow and run against the real v2026.7.31 asset list (16 → platform=12, symbols=4, PASS) plus three boundary cases: Linux symbols absent (14 → PASS with warning), all symbols absent (12 → FAIL), one platform target dropped (15 → FAIL). YAML parses.
|
Daily automated review pass — CLAUDE.md compliance only. Commit author identity: Not fixing this myself: correcting it requires producing a replacement commit, and this session's own git identity is the identical Everything else checked out clean:
_Generated by Claude Code Generated by Claude Code |
Sign Release Artifactsfailed on v2026.7.31 withexpected exactly 12 .sha256 siblings (one per matrix target across cli_* jobs), got 16— after every artifact had already been built and published. It will fail the same way on every subsequent release until this lands.Cause
#6677 ships debug symbols as their own release assets, adding four
librefang-<target>-debug-symbols.tar.gz.sha256files. The sibling-count guard insign_release_artifactsassumes one.sha256per platform target and is deliberately an equality — its comment says drift in either direction is a bug, and blocking releases is the intended loud failure. So the four new files read as four extra platforms.v2026.7.31 is the first release cut since #6677 landed, so this is a first exposure rather than a regression. The guard behaved exactly as designed; the constant simply was not updated alongside the new assets, and the two kinds of sibling are not the same kind of thing.
Fix
Split the list before counting.
= 12. A dropped or added matrix target still stops the release loudly, which is the whole point of the guard.2..4, matching how they are actually produced:cli_macfails outright when its.dSYMis missing (so both macOS targets are guaranteed), while the cross-compiledcli_linuxtargets only warn when the.dwpis absent — that asymmetry is deliberate per chore(release): ship debug symbols as a separate asset so crashes can be symbolized #6677, so a hard= 4would take a release down over a diagnostic aid. Below 2 means the macOS hard-failure path did not hold, which is worth stopping for; 2 or 3 emits a warning.The manifest itself is unchanged. The download loop and
ls *.sha256still read the full asset list, so every hash including the debug-symbols ones stays inSHA256SUMSand under the cosign signature — this touches only the count check.Verification
The step was extracted from the workflow and run against the real v2026.7.31 asset list plus three boundary cases:
YAML parses.
Note on scope
Found while verifying the v2026.7.31 release pipeline (#6688 / #6689 / #6690). Unrelated to those changes in cause, but it blocks every future release, so it is fixed here rather than deferred.
The other failing job on that release,
Mobile / iOS (ipa), also failed on v2026.7.27 and iscontinue-on-error: trueby design — left alone, as it needs Apple signing credentials rather than a code change.