|
| 1 | +#!/usr/bin/env bash |
| 2 | +# Add the legacy ui-* names to checksums.txt, carrying the canonical digest. |
| 3 | +# |
| 4 | +# publish-legacy-aliases.sh publishes byte-identical ui-*-named copies of the |
| 5 | +# release archives so already-released 0.9.x updaters stop 404ing (#1538). It |
| 6 | +# runs after verify, so those copies inherit the hash-bound VirusTotal verdicts |
| 7 | +# — and it therefore left them out of checksums.txt entirely, on the reasoning |
| 8 | +# that the file "covers the canonical names current installers request". |
| 9 | +# |
| 10 | +# That reasoning has a hole. The aliases exist ONLY for 0.9.x updaters, and |
| 11 | +# those verify the NAME they asked for. So the alias fixed the 404 and moved the |
| 12 | +# failure one step later: the updater downloads the archive, cannot find its name |
| 13 | +# in checksums.txt, and refuses to install it (#1134): |
| 14 | +# |
| 15 | +# warning: codebase-memory-mcp-ui-darwin-arm64.tar.gz not found in checksums.txt |
| 16 | +# error: refusing to install an unverified download |
| 17 | +# |
| 18 | +# An alias is a copy, so its sha256 is by construction the digest already |
| 19 | +# computed for the canonical archive. Emitting that digest under the legacy name |
| 20 | +# introduces no new bytes and no new scan surface. This runs BEFORE the |
| 21 | +# attestation step so the attested artifact covers both names. |
| 22 | +# |
| 23 | +# The alias rule MUST stay in step with publish-legacy-aliases.sh: .tar.gz and |
| 24 | +# .zip only, never an already-ui-* name. A name here with no published asset is |
| 25 | +# as broken as an asset with no name, so this fails closed when it matches |
| 26 | +# nothing. |
| 27 | +# |
| 28 | +# Usage: append-legacy-alias-checksums.sh <checksums-file> |
| 29 | +set -euo pipefail |
| 30 | + |
| 31 | +CHECKSUMS="${1:?usage: append-legacy-alias-checksums.sh <checksums-file>}" |
| 32 | + |
| 33 | +if [ ! -s "$CHECKSUMS" ]; then |
| 34 | + echo "error: $CHECKSUMS is missing or empty" >&2 |
| 35 | + exit 1 |
| 36 | +fi |
| 37 | + |
| 38 | +aliases="$(mktemp)" |
| 39 | +trap 'rm -f "$aliases"' EXIT |
| 40 | + |
| 41 | +awk ' |
| 42 | + $2 ~ /^codebase-memory-mcp-/ && |
| 43 | + $2 !~ /^codebase-memory-mcp-ui-/ && |
| 44 | + ($2 ~ /\.tar\.gz$/ || $2 ~ /\.zip$/) { |
| 45 | + alias = $2 |
| 46 | + sub(/^codebase-memory-mcp-/, "codebase-memory-mcp-ui-", alias) |
| 47 | + print $1 " " alias |
| 48 | + } |
| 49 | +' "$CHECKSUMS" > "$aliases" |
| 50 | + |
| 51 | +if [ ! -s "$aliases" ]; then |
| 52 | + echo "error: no canonical archives matched the ui-* alias rule in $CHECKSUMS;" >&2 |
| 53 | + echo " publish-legacy-aliases.sh would then publish assets that" >&2 |
| 54 | + echo " checksums.txt does not cover (#1134)." >&2 |
| 55 | + exit 1 |
| 56 | +fi |
| 57 | + |
| 58 | +cat "$aliases" >> "$CHECKSUMS" |
| 59 | +echo "added $(wc -l < "$aliases" | tr -d ' ') legacy alias checksum line(s); $CHECKSUMS now covers $(wc -l < "$CHECKSUMS" | tr -d ' ') names" |
0 commit comments