fix(release): sign v1.7.122 with the OLD root — the rotation moved the checks a release early
Demo images / Build & push demo images (push) Successful in 4m12s

The rotation commit pointed create-release.sh and publish-release-assets.sh
at the NEW root in the same commit that pins it in the binary. But the
release CARRYING the rotation must be signed with the OLD root: every node
is still running the previous binary, which pins the old key. So the
tooling would have rejected the only signature the fleet can accept, and
the signature it demanded would have ended OTA fleet-wide.

Both checks now expect the old DID for this cycle, with the flip to the new
one called out for v1.7.123+. sign-manifest.sh documents the
ARCHY_RELEASE_ROOT_PUBKEY override needed because the signer built from
this tree already pins the new anchor and would fail to verify its own
correct output.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
archipelago
2026-08-05 07:48:51 -04:00
co-authored by Claude Fable 5
parent c35e33d0a7
commit b92e16abc0
3 changed files with 31 additions and 2 deletions
+13 -1
View File
@@ -240,7 +240,19 @@ install -m 0644 "$FRONTEND_ARCHIVE" "$VERSION_DIR/archipelago-frontend-${VERSION
# warning and falls through — and the commit then happened anyway. A release
# commit carrying a manifest no node will accept has no valid use, so refuse
# to create one rather than leave a tag that has to be re-cut.
EXPECTED_DID="did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT"
# ⚠ ROTATION IN FLIGHT (v1.7.122-alpha) — this is the OLD root, deliberately.
#
# The trust anchor in the binary already pins the NEW root
# (z6Mkfu5LT…DLWT), because this release is what installs that pin. But the
# manifest THIS release ships must be signed with the OLD root
# (z6Mkkid…q7ur): every node is still running the previous binary, which
# pins the old key and would reject anything else. Signing this one with the
# new key ends OTA fleet-wide and needs hands-on recovery per node.
#
# ➜ NEXT RELEASE (v1.7.123+): change this to the new DID, and the same line
# in publish-release-assets.sh. By then every node runs a binary pinning
# the new root, and an old-key signature is the one that gets rejected.
EXPECTED_DID="did:key:z6MkkidEnEpo6qHMCNSZoNKWtvQvxq3whnaME9wGgEFhq7ur"
if ! grep -q '"signature":' "$PROJECT_ROOT/releases/manifest.json" \
|| ! grep -q "\"signed_by\": \"$EXPECTED_DID\"" "$PROJECT_ROOT/releases/manifest.json"; then
echo "" >&2