release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request - #45336
Merged
sleepytanya merged 1 commit intoAug 8, 2026
Conversation
…attestations permissions they request (#45330) ## **Description** The Runway release orchestrator (`runway-extension-release-and-submit.yml`) fails at run creation, before any job starts: ``` Error calling workflow '.../publish-release-from-release-head.yml@eab4097'. The nested job 'publish-release' is requesting 'attestations: write', but is only allowed 'attestations: none'. ``` A called workflow can never hold more permission than the job that calls it. The orchestrator's calling jobs inherited only `contents/statuses/actions: read` + `id-token: write`, but two callees ask for attestation scopes: | Callee | Needs | Why | | --- | --- | --- | | `publish-release-from-release-head.yml` | `attestations: write` | `actions/attest-build-provenance` (INFRA-2665) | | `upload-extension-to-cws.yml` | `attestations: read` | `gh attestation verify` (INFRA-3661) | This grants those scopes on the calling jobs rather than workflow-wide, so `validate` and the AMO phase keep the narrower set. Because a job-level `permissions:` block replaces the workflow-level one, each block lists the full union the callee needs. Also removes a reference to a `version` input from the recovery text in the orchestrator summary. There is no `version` input; the version is derived from the `release/X.Y.Z` branch the workflow runs on. Not addressed here: `actionlint` and `zizmor` lint one file at a time and do not inspect the reusable-workflow call graph, so no linter catches this class of error. It only surfaces on dispatch. ## **Changelog** CHANGELOG entry: null ## **Related issues** Fixes: INFRA-3735 follow-up (orchestrator was never dispatched end-to-end before 13.43.0) ## **Manual testing steps** 1. Dispatch **Runway extension release and store submit** on a `release/*` branch with `execute_store_phases=false` (validation-only run). 2. Confirm the run is created, i.e. no `The workflow is not valid ... attestations: none` error. On `main` today, run creation fails at this point. 3. Confirm Phase 0 validation passes and Phases 1 to 3 are skipped. 4. Open the orchestrator summary and confirm the recovery line reads "re-dispatch from the same release branch with the same `release_sha`". <!-- ## **Screenshots/Recordings** ### **Before** ### **After** --> ## **Pre-merge author checklist** - [x] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Extension Coding Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [x] I've completed the PR template to the best of my ability - [ ] I've included tests if applicable - [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [ ] I've applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. ## **Pre-merge reviewer checklist** - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots. Made with [Cursor](https://cursor.com) Co-authored-by: Cursor <cursoragent@cursor.com>
runway-github
Bot
requested review from
a team,
HowardBraham and
itsyoboieltr
as code owners
August 8, 2026 01:05
Contributor
|
CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes. |
sleepytanya
approved these changes
Aug 8, 2026
sleepytanya
enabled auto-merge (squash)
August 8, 2026 01:17
|
Contributor
|
No release label on PR. Adding release label release-13.43.0 on PR, as PR was cherry-picked in branch 13.43.0. |
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Description
The Runway release orchestrator
(
runway-extension-release-and-submit.yml) fails at run creation,before any job starts:
A called workflow can never hold more permission than the job that calls
it. The orchestrator's calling jobs inherited only
contents/statuses/actions: read+id-token: write, but two calleesask for attestation scopes:
publish-release-from-release-head.ymlattestations: writeactions/attest-build-provenance(INFRA-2665)upload-extension-to-cws.ymlattestations: readThis grants those scopes on the calling jobs rather than workflow-wide,
so
validateand the AMO phase keep the narrower set. Because ajob-level
permissions:block replaces the workflow-level one, eachblock lists the full union the callee needs.
Also removes a reference to a
versioninput from the recovery text inthe orchestrator summary. There is no
versioninput; the version isderived from the
release/X.Y.Zbranch the workflow runs on.Not addressed here:
actionlintandzizmorlint one file at a timeand do not inspect the reusable-workflow call graph, so no linter
catches this class of error. It only surfaces on dispatch.
Changelog
CHANGELOG entry: null
Related issues
Fixes: INFRA-3735 follow-up (orchestrator was never dispatched
end-to-end before 13.43.0)
Manual testing steps
release/*branch withexecute_store_phases=false(validation-onlyrun).
The workflow is not valid ... attestations: noneerror. Onmaintoday, run creation fails at thispoint.
"re-dispatch from the same release branch with the same
release_sha".Pre-merge author checklist
Docs and MetaMask
Extension Coding
Standards.
if applicable
guidelines).
Not required for external contributors.
Pre-merge reviewer checklist
app, test code being changed).
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
Made with Cursor
Co-authored-by: Cursor cursoragent@cursor.com 0040e9f