| 1 | #!/usr/bin/env bash |
| 2 | # One post-publication owner for fresh observations and durable evidence. |
| 3 | set -euo pipefail |
| 4 | script_dir="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)" |
| 5 | repository="${RELEASE_REPOSITORY:?}" |
| 6 | version="${RELEASE_VERSION:?}" |
| 7 | operation="${RELEASE_OPERATION:?}" |
| 8 | expected_sha="${RELEASE_EXPECTED_SHA:?}" |
| 9 | output="${RELEASE_LEDGER_OUTPUT:?}" |
| 10 | [[ "$version" =~ ^(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)$ ]] || exit 2 |
| 11 | [[ "$expected_sha" =~ ^[0-9a-f]{40}$ ]] || exit 2 |
| 12 | [[ "$operation" =~ ^(publish|recover)$ ]] || exit 2 |
| 13 | test "$repository" = esengine/DeepSeek-Reasonix || exit 2 |
| 14 | if [ "${GITHUB_ACTIONS:-}" = true ]; then |
| 15 | test "$GITHUB_REPOSITORY" = "$repository" |
| 16 | test "$GITHUB_REF" = refs/heads/main-v2 |
| 17 | test "$GITHUB_REF_PROTECTED" = true |
| 18 | fi |
| 19 | work="$(mktemp -d)" |
| 20 | mkdir -p "$(dirname "$output")" |
| 21 | state=verification-failed |
| 22 | stage=immutable |
| 23 | jq -n --arg version "$version" --arg sha "$expected_sha" --arg operation "$operation" \ |
| 24 | '{schema:1,version:$version,sourceSHA:$sha,operation:$operation,surfaces:{}}' > "$work/ledger.json" |
| 25 | finish() { |
| 26 | local status=$? |
| 27 | trap - EXIT |
| 28 | jq --arg state "$state" --arg stage "$stage" \ |
| 29 | --arg run "${GITHUB_RUN_ID:-local}" --arg attempt "${GITHUB_RUN_ATTEMPT:-1}" \ |
| 30 | --arg control "${GITHUB_SHA:-}" --argjson exitCode "$status" \ |
| 31 | '. + {observedAt:(now|todateiso8601),completionState:$state,verificationContext:{stage:$stage,exitCode:$exitCode,runId:$run,runAttempt:$attempt,controlSHA:$control}}' \ |
| 32 | "$work/ledger.json" > "$output" || status=1 |
| 33 | rm -rf -- "$work" |
| 34 | exit "$status" |
| 35 | } |
| 36 | trap finish EXIT |
| 37 | export CLI_TAG="v$version" DESKTOP_TAG="desktop-v$version" |
| 38 | RELEASE_LEDGER_OUTPUT="$work/verified.json" VERIFY_PUBLIC_POINTERS=true \ |
| 39 | bash "$script_dir/verify-stable-release-artifacts.sh" |
| 40 | cp "$work/verified.json" "$work/ledger.json" |
| 41 | state=release-event-pending |
| 42 | stage=release-event |
| 43 | node "$script_dir/release-event.mjs" generate --version "$version" --sha "$expected_sha" \ |
| 44 | --published-at "$(gh api "repos/$repository/releases/tags/v$version" --jq .published_at)" \ |
| 45 | --output "$work/release-event.json" |
| 46 | has_event="$(gh release view "v$version" --repo "$repository" --json assets --jq '[.assets[] | select(.name == "release-event.json")] | length')" |
| 47 | if [ "$has_event" = 1 ]; then |
| 48 | gh release download "v$version" --repo "$repository" --pattern release-event.json --output "$work/existing-event.json" |
| 49 | cmp -s "$work/release-event.json" "$work/existing-event.json" || { echo 'Published release event conflicts with the verified identity' >&2; exit 1; } |
| 50 | elif [ "$has_event" = 0 ]; then |
| 51 | gh release upload "v$version" --repo "$repository" "$work/release-event.json" |
| 52 | else |
| 53 | echo 'Release carries more than one release-event.json' >&2 |
| 54 | exit 1 |
| 55 | fi |
| 56 | if jq -e '.surfaces.stableManifest' "$work/ledger.json" >/dev/null; then |
| 57 | state=complete |
| 58 | else |
| 59 | state=immutable-complete-newer-pointer-preserved |
| 60 | fi |
| 61 | stage=complete |
| 62 |