This is an automated email from the ASF dual-hosted git repository.

tisonkun pushed a commit to branch codex/fix-release-guide
in repository https://gitbox.apache.org/repos/asf/datasketches-rust.git

commit 6b2954c2d0f3fd01b29eb1de919aec76bddeb272
Author: tison <[email protected]>
AuthorDate: Thu Aug 13 21:18:29 2026 +0800

    docs: correct release verification workflow
---
 CHANGELOG.md |  2 ++
 RELEASE.md   | 15 +++++++++++----
 2 files changed, 13 insertions(+), 4 deletions(-)

diff --git a/CHANGELOG.md b/CHANGELOG.md
index 77e062f..77a55ce 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -2,6 +2,8 @@
 
 All significant changes to this project will be documented in this file.
 
+## Unreleased
+
 ## v0.4.0
 
 ### Breaking changes
diff --git a/RELEASE.md b/RELEASE.md
index 1d8e664..ed37b12 100644
--- a/RELEASE.md
+++ b/RELEASE.md
@@ -82,6 +82,9 @@ printf '%s\n' \
   "signing_key_fingerprint=$signing_key_fingerprint"
 
 gpg --list-secret-keys "$signing_key_fingerprint"
+gpg --batch --with-colons --list-secret-keys "$signing_key_fingerprint" |
+  awk -F: '$1 == "uid" && $10 ~ /@apache\.org/ { found = 1 }
+    END { exit !found }'
 ```
 
 Run this block again if a later step starts in another shell. Increment 
`rc_version` and recompute the derived values when preparing another candidate.
@@ -101,7 +104,7 @@ CI does not run on every push to `main` or on release tags. 
Complete the local r
 ## Prerequisites
 
 1. **crates.io access**: Run `cargo login` with an account authorized to 
publish `datasketches`.
-2. **GPG setup**: Use an Apache code-signing key that is present in the 
DataSketches `KEYS` file.
+2. **GPG setup**: Use an Apache code-signing key that is present in the 
DataSketches `KEYS` file and has a user ID containing an `@apache.org` email 
address.
 3. **SVN access**: Confirm that the release manager can write to `dist/dev` 
and that a PMC member can write to `dist/release`.
 4. **Release tools**: Install Git, GPG, SVN, `unzip`, and the tools required 
by `cargo x lint`.
 5. **Clean checkout**: Start from a current checkout of `main` with no local 
changes.
@@ -111,7 +114,7 @@ CI does not run on every push to `main` or on release tags. 
Complete the local r
 Create a release-preparation pull request that:
 
 1. Changes the `datasketches` package version in `datasketches/Cargo.toml` and 
`Cargo.lock` to the value of `release_version`.
-2. Changes the `Unreleased` heading in `CHANGELOG.md` to `v${release_version}` 
without a date and finalizes its user-facing entries.
+2. Adds a `v${release_version}` section without a date immediately below 
`Unreleased` in `CHANGELOG.md` and finalizes its user-facing entries.
 3. Passes the complete local release checks:
 
 ```bash
@@ -292,6 +295,10 @@ mkdir -m 700 "$verify_gnupg_home"
     gpg --with-colons --fingerprint "$signing_key_fingerprint" |
     awk -F: '$1 ~ /^f[p]r$/ { print $10 }' |
     grep -Fx -- "$signing_key_fingerprint"
+  GNUPGHOME="$verify_gnupg_home" \
+    gpg --with-colons --list-keys "$signing_key_fingerprint" |
+    awk -F: '$1 == "uid" && $10 ~ /@apache\.org/ { found = 1 }
+      END { exit !found }'
 
   gpg_status="$(
     GNUPGHOME="$verify_gnupg_home" \
@@ -301,7 +308,7 @@ mkdir -m 700 "$verify_gnupg_home"
   signature_fingerprint="$(
     printf '%s\n' "$gpg_status" |
       awk '$1 == "[GNUPG:]" && $2 == "VALIDSIG" {
-        print NF >= 12 && $12 != "" ? $12 : $3
+        if (NF >= 12 && $12 != "") print $12; else print $3
       }'
   )"
   test "$signature_fingerprint" = "$signing_key_fingerprint"
@@ -489,7 +496,7 @@ Do not describe GitHub-generated source archives as the 
official Apache source d
 4. Review the generated `_includes/downloadsInclude.txt`, submit the website 
change, and verify the download, signature, checksum, and `KEYS` links after it 
is published.
 5. Wait at least one hour after the release first appears on 
`downloads.apache.org` before announcing it.
 6. Send a plain-text announcement from an `@apache.org` address to 
`[email protected]` and `[email protected]`. Include a short 
project description and links to the project download page, changelog, 
crates.io, docs.rs, and GitHub release.
-7. Submit a post-release pull request that adds the actual release date to the 
`v${release_version}` changelog heading and adds a new empty `Unreleased` 
section above it, then close the release tracking issue.
+7. Submit a post-release pull request that adds the actual release date to the 
`v${release_version}` changelog heading, then close the release tracking issue.
 
 ## Troubleshooting
 


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to