This is an automated email from the ASF dual-hosted git repository.
swebb2066 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/logging-log4cxx.git
The following commit(s) were added to refs/heads/master by this push:
new 6e30c68d Ensure apache-logging key is used to verify release signature
(#756)
6e30c68d is described below
commit 6e30c68d99f1147f0de9c780365cb92000e30dac
Author: Stephen Webb <[email protected]>
AuthorDate: Fri Sep 4 11:14:55 2026 +1000
Ensure apache-logging key is used to verify release signature (#756)
---
admin/release-review-instructions.md | 1 -
admin/validate-release.ps1 | 56 ++++++++++++++++++++++++------------
admin/validate-release.sh | 24 ++++++++++++++--
3 files changed, 58 insertions(+), 23 deletions(-)
diff --git a/admin/release-review-instructions.md
b/admin/release-review-instructions.md
index 5205372d..3caed583 100644
--- a/admin/release-review-instructions.md
+++ b/admin/release-review-instructions.md
@@ -11,7 +11,6 @@ Prerequisites
* A C++ compiler is available on your system
* cmake, APR-Util and the [GitHub CLI](https://cli.github.com/) are installed
on your system
* [GNU Privacy Guard](https://www.gnupg.org/) is installed on your system
-* You have imported the [Apache Logging KEYS
file](https://dist.apache.org/repos/dist/release/logging/KEYS)
Additional Prerequisites (Windows only)
----------
diff --git a/admin/validate-release.ps1 b/admin/validate-release.ps1
index 9d645002..f9547070 100644
--- a/admin/validate-release.ps1
+++ b/admin/validate-release.ps1
@@ -26,40 +26,57 @@ catch
Write-Error "The gpg program directory must be included the PATH environment
variable" -ErrorAction Stop
}
-
if (-not (Test-Path -Path "$TEST_DIRECTORY" -PathType Container))
{
- New-Item -ItemType Directory -Path "$TEST_DIRECTORY" -ErrorAction Stop
+ New-Item -ItemType Directory -Path "$TEST_DIRECTORY" -ErrorAction Stop |
Out-Null
}
-Set-Location -Path "$TEST_DIRECTORY"
+pushd "$TEST_DIRECTORY"
if ( $CheckProvenance )
{
try
{
gh --version | Out-Null
- $WORKFLOW="package_code"
- Write-Output "Downloading GitHub $WORKFLOW artifacts ..."
- if (Test-Path "release_files") { Remove-Item "release_files" -Recurse
-Force }
- # Get the latest Run ID
- $RUN_ID = (gh run list --repo apache/logging-log4cxx
--workflow="$WORKFLOW.yml" --limit 1 --json databaseId --jq '.[0].databaseId')
- if ( !$? ) { Write-Error "Failed to find a Github $WORKFLOW run id"
-ErrorAction Stop }
-
- # Download the GitHub artifacts
- gh run download --repo apache/logging-log4cxx "$RUN_ID"
- if ( !$? -or (-not (Test-Path "release_files")) )
- { Write-Error "Failed to download Github $WORKFLOW run $RUN_ID artifacts"
-ErrorAction Stop }
- if (-not (Test-Path "release_files\$ARCHIVE.tar.gz.sha512") )
- {
- Write-Error "$ARCHIVE.tar.gz.sha512 not found in GitHub $WORKFLOW run
$RUN_ID artifacts" -ErrorAction Stop
- }
}
catch
{
Write-Output "GitHub CLI program (gh) is not available - provenance checks
will be skipped"
+ $CheckProvenance=$false
+ }
+}
+if ( $CheckProvenance )
+{
+ $WORKFLOW="package_code"
+ Write-Output "Downloading GitHub $WORKFLOW artifacts ..."
+ if (Test-Path "release_files") { Remove-Item "release_files" -Recurse -Force
}
+ # Get the latest Run ID
+ $RUN_ID = (gh run list --repo apache/logging-log4cxx
--workflow="$WORKFLOW.yml" --limit 1 --json databaseId --jq '.[0].databaseId')
+ if ( !$? ) { Write-Error "Failed to find a Github $WORKFLOW run id"
-ErrorAction Stop }
+
+ # Download the GitHub artifacts
+ gh run download --repo apache/logging-log4cxx "$RUN_ID"
+ if ( !$? -or (-not (Test-Path "release_files")) )
+ { Write-Error "Failed to download Github $WORKFLOW run $RUN_ID artifacts"
-ErrorAction Stop }
+ if (-not (Test-Path "release_files\$ARCHIVE.tar.gz.sha512") )
+ {
+ Write-Error "$ARCHIVE.tar.gz.sha512 not found in GitHub $WORKFLOW run
$RUN_ID artifacts" -ErrorAction Stop
}
}
+# Create a temporary gpg home directory, so only the downloaded KEYS are used
to verify the signature.
+$PREVIOUS_GPG_HOME="${ENV:GNUPGHOME}"
+$GPG_HOME="$TEST_DIRECTORY/.gpg"
+$LOGGING_KEYS="$GPG_HOME/KEYS"
+${ENV:GNUPGHOME}="$GPG_HOME"
+trap { ${ENV:GNUPGHOME}="$PREVIOUS_GPG_HOME" }
+if (-not (Test-Path -Path "$GPG_HOME" -PathType Container))
+{
+ New-Item -ItemType Directory -Path "$GPG_HOME" -ErrorAction Stop | Out-Null
+ Invoke-WebRequest https://downloads.apache.org/logging/KEYS -OutFile
$LOGGING_KEYS -ErrorAction Stop
+ gpg --batch --quiet --import $LOGGING_KEYS
+ if (!$? ) { exit 1 }
+}
+
$FULL_DL="$BASE_DL/$VERSION/$ARCHIVE"
$ARCHIVE_TYPES = @("tar.gz", "zip")
foreach ($ARCHIVE_TYPE in $ARCHIVE_TYPES)
@@ -88,7 +105,7 @@ foreach ($ARCHIVE_TYPE in $ARCHIVE_TYPES)
}
}
Write-Output "Validating $ARCHIVE.$ARCHIVE_TYPE signature..."
- gpg --verify "$ARCHIVE.$ARCHIVE_TYPE.asc"
+ gpg --batch --verify "$ARCHIVE.$ARCHIVE_TYPE.asc" "$ARCHIVE.$ARCHIVE_TYPE"
if (!$? ) { exit 1 }
if ( Test-Path -Path "release_files\$ARCHIVE.$ARCHIVE_TYPE.sha512" )
@@ -104,6 +121,7 @@ foreach ($ARCHIVE_TYPE in $ARCHIVE_TYPES)
}
}
}
+${ENV:GNUPGHOME}="$PREVIOUS_GPG_HOME"
if (Test-Path "$ARCHIVE") { Remove-Item -Recurse "$ARCHIVE" }
if (Test-Path test-build) { Remove-Item -Recurse test-build }
diff --git a/admin/validate-release.sh b/admin/validate-release.sh
index ddc656d2..0903b477 100644
--- a/admin/validate-release.sh
+++ b/admin/validate-release.sh
@@ -10,7 +10,13 @@ fi
if [ -z "$STAGE" ] ; then
STAGE=dev # Alternatively release
fi
-CheckProvenance=$(( $STAGE == "dev" ? 1 : 0 ))
+if [ -z "$CheckProvenance" ] ; then
+ if [ $STAGE == "dev" ] ; then
+ CheckProvenance=1
+ else
+ CheckProvenance=0
+ fi
+fi
if [ -z "$BASE_DL" ] ; then
BASE_DL=https://dist.apache.org/repos/dist/$STAGE/logging/log4cxx
@@ -25,7 +31,7 @@ fi
test -d "$TEST_DIRECTORY" || mkdir "$TEST_DIRECTORY"
cd "$TEST_DIRECTORY"
-if $CheckProvenance ; then
+if (( $CheckProvenance )) ; then
if gh --version >> /dev/null ; then
WORKFLOW="package_code"
echo "Downloading $WORKFLOW artifacts ..."
@@ -51,6 +57,18 @@ if $CheckProvenance ; then
fi
fi
+# Create a temporary gpg home directory, so only the downloaded KEYS are used
to verify the signature.
+PREVIOUS_GPG_HOME="$GNUPGHOME"
+GPG_HOME="$TEST_DIRECTORY/.gpg"
+LOGGING_KEYS="$GPG_HOME/KEYS"
+GNUPGHOME="$GPG_HOME"
+export GNUPGHOME
+if [ ! -d "$GPG_HOME" ] ; then
+ mkdir "$GPG_HOME" && chmod 0700 "$GPG_HOME"
+ wget -O "$LOGGING_KEYS" "https://downloads.apache.org/logging/KEYS"
+ gpg --batch --quiet --import "$LOGGING_KEYS"
+fi
+
FULL_DL="$BASE_DL/$VERSION/$ARCHIVE"
for ARCHIVE_TYPE in "tar.gz" "zip" ; do
test -f "$ARCHIVE.$ARCHIVE_TYPE" && rm "$ARCHIVE.$ARCHIVE_TYPE"
@@ -64,7 +82,7 @@ for ARCHIVE_TYPE in "tar.gz" "zip" ; do
"${SUM}sum" --check "$ARCHIVE.$ARCHIVE_TYPE.$SUM" || exit $?
done
echo "Validating signature..."
- gpg --verify "$ARCHIVE.$ARCHIVE_TYPE.asc" || exit $?
+ gpg --batch --verify "$ARCHIVE.$ARCHIVE_TYPE.asc" "$ARCHIVE.$ARCHIVE_TYPE"
if [ -f release_files/$ARCHIVE.$ARCHIVE_TYPE.sha512 ] ; then
echo "Checking provenance ..."