chore(trust): flip the signing checks to the new release root

v1.7.122-alpha was the last release signed with the old root — it is the
release that installed the new pin on every node. From v1.7.123 the new
root signs, and a node running .122+ rejects an old-key signature. The
ARCHY_RELEASE_ROOT_PUBKEY override is no longer needed either: the signer
built from this tree pins the same key we now sign with.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
archipelago
2026-08-05 09:31:28 -04:00
co-authored by Claude Fable 5
parent 27c1b151f8
commit cfd1b4c731
3 changed files with 11 additions and 30 deletions
+5 -13
View File
@@ -240,19 +240,11 @@ install -m 0644 "$FRONTEND_ARCHIVE" "$VERSION_DIR/archipelago-frontend-${VERSION
# warning and falls through — and the commit then happened anyway. A release
# commit carrying a manifest no node will accept has no valid use, so refuse
# to create one rather than leave a tag that has to be re-cut.
# ⚠ ROTATION IN FLIGHT (v1.7.122-alpha) — this is the OLD root, deliberately.
#
# The trust anchor in the binary already pins the NEW root
# (z6Mkfu5LT…DLWT), because this release is what installs that pin. But the
# manifest THIS release ships must be signed with the OLD root
# (z6Mkkid…q7ur): every node is still running the previous binary, which
# pins the old key and would reject anything else. Signing this one with the
# new key ends OTA fleet-wide and needs hands-on recovery per node.
#
# ➜ NEXT RELEASE (v1.7.123+): change this to the new DID, and the same line
# in publish-release-assets.sh. By then every node runs a binary pinning
# the new root, and an old-key signature is the one that gets rejected.
EXPECTED_DID="did:key:z6MkkidEnEpo6qHMCNSZoNKWtvQvxq3whnaME9wGgEFhq7ur"
# Release root ROTATED 2026-08-05. v1.7.122-alpha was the last release signed
# with the old root (z6Mkkid…q7ur) — it is the release that installed this
# pin on every node. From v1.7.123 onward the new root signs, and nodes
# running .122+ reject anything signed with the old key.
EXPECTED_DID="did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT"
if ! grep -q '"signature":' "$PROJECT_ROOT/releases/manifest.json" \
|| ! grep -q "\"signed_by\": \"$EXPECTED_DID\"" "$PROJECT_ROOT/releases/manifest.json"; then
echo "" >&2
+3 -5
View File
@@ -29,11 +29,9 @@ fail() { echo "Error: $*" >&2; exit 1; }
# with the pinned release-root anchor refuse to auto-apply unsigned manifests,
# and enforcement will tighten to hard-reject — an unsigned publish would
# strand them. Grep proves presence; ceremony verify proves the crypto.
# ⚠ ROTATION IN FLIGHT (v1.7.122-alpha) — OLD root on purpose; see the same
# block in create-release.sh. Nodes still run the previous binary and pin the
# old key, so the manifest this release publishes must carry an old-key
# signature. Flip both to z6Mkfu5LT…DLWT for v1.7.123+.
EXPECTED_DID="did:key:z6MkkidEnEpo6qHMCNSZoNKWtvQvxq3whnaME9wGgEFhq7ur"
# Release root ROTATED 2026-08-05; see create-release.sh. New root from
# v1.7.123 onward.
EXPECTED_DID="did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT"
grep -q '"signature":' "$PROJECT_ROOT/releases/manifest.json" \
&& grep -q "\"signed_by\": \"$EXPECTED_DID\"" "$PROJECT_ROOT/releases/manifest.json" \
|| fail "releases/manifest.json is not signed by the release root — run: bash scripts/sign-manifest.sh"
+3 -12
View File
@@ -12,18 +12,9 @@
# re-signing (e.g. a manifest edited after creation) or signing on a box where
# the release run was non-interactive.
#
# ⚠ ROTATION IN FLIGHT (v1.7.122-alpha). This release must be signed with the
# OLD release root, because every node still runs a binary pinning it — but
# the signer built from THIS tree already pins the NEW root, so its own
# verification would reject a correct old-key signature. Pin the old anchor
# for the duration of the ceremony so signing and verification agree:
#
# ARCHY_RELEASE_ROOT_PUBKEY=5d15cbee8a108f7dd288c02d29a1d9d71f198acc99186aad8008b4f28d469951 \
# bash scripts/sign-manifest.sh
#
# That hex is the OLD root's PUBLIC key (verified to derive to
# did:key:z6Mkkid…q7ur); it is not secret and pins verification only.
# From v1.7.123 the override is unnecessary — drop it and this block.
# The release root was rotated 2026-08-05. From v1.7.123 this signs with the
# NEW mnemonic and the signer's own anchor already pins that key, so no
# ARCHY_RELEASE_ROOT_PUBKEY override is needed (it was, for .122 only).
set -euo pipefail
REPO="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"