Skip to content

release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request - #45336

Merged
sleepytanya merged 1 commit into
release/13.43.0from
runway-cherry-pick-13.43.0-1786151124
Aug 8, 2026
Merged

sleepytanya merged 1 commit into
release/13.43.0from
runway-cherry-pick-13.43.0-1786151124

Conversation

@runway-github

@runway-github runway-github Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

Description

The Runway release orchestrator
(runway-extension-release-and-submit.yml) fails at run creation,
before any job starts:

Error calling workflow '.../publish-release-from-release-head.yml@eab4097'.
The nested job 'publish-release' is requesting 'attestations: write',
but is only allowed 'attestations: none'.

A called workflow can never hold more permission than the job that calls
it. The orchestrator's calling jobs inherited only
contents/statuses/actions: read + id-token: write, but two callees
ask for attestation scopes:

Callee Needs Why
publish-release-from-release-head.yml attestations: write
actions/attest-build-provenance (INFRA-2665)
upload-extension-to-cws.yml attestations: read `gh attestation
verify` (INFRA-3661)

This grants those scopes on the calling jobs rather than workflow-wide,
so validate and the AMO phase keep the narrower set. Because a
job-level permissions: block replaces the workflow-level one, each
block lists the full union the callee needs.

Also removes a reference to a version input from the recovery text in
the orchestrator summary. There is no version input; the version is
derived from the release/X.Y.Z branch the workflow runs on.

Not addressed here: actionlint and zizmor lint one file at a time
and do not inspect the reusable-workflow call graph, so no linter
catches this class of error. It only surfaces on dispatch.

Changelog

CHANGELOG entry: null

Related issues

Fixes: INFRA-3735 follow-up (orchestrator was never dispatched
end-to-end before 13.43.0)

Manual testing steps

  1. Dispatch Runway extension release and store submit on a
    release/* branch with execute_store_phases=false (validation-only
    run).
  2. Confirm the run is created, i.e. no The workflow is not valid ... attestations: none error. On main today, run creation fails at this
    point.
  3. Confirm Phase 0 validation passes and Phases 1 to 3 are skipped.
  4. Open the orchestrator summary and confirm the recovery line reads
    "re-dispatch from the same release branch with the same release_sha".

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the
    app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described
    in the ticket it closes and includes the necessary testing evidence such
    as recordings and or screenshots.

Made with Cursor

Co-authored-by: Cursor cursoragent@cursor.com 0040e9f

…attestations permissions they request (#45330)

## **Description**

The Runway release orchestrator
(`runway-extension-release-and-submit.yml`) fails at run creation,
before any job starts:

```
Error calling workflow '.../publish-release-from-release-head.yml@eab4097'.
The nested job 'publish-release' is requesting 'attestations: write',
but is only allowed 'attestations: none'.
```

A called workflow can never hold more permission than the job that calls
it. The orchestrator's calling jobs inherited only
`contents/statuses/actions: read` + `id-token: write`, but two callees
ask for attestation scopes:

| Callee | Needs | Why |
| --- | --- | --- |
| `publish-release-from-release-head.yml` | `attestations: write` |
`actions/attest-build-provenance` (INFRA-2665) |
| `upload-extension-to-cws.yml` | `attestations: read` | `gh attestation
verify` (INFRA-3661) |

This grants those scopes on the calling jobs rather than workflow-wide,
so `validate` and the AMO phase keep the narrower set. Because a
job-level `permissions:` block replaces the workflow-level one, each
block lists the full union the callee needs.

Also removes a reference to a `version` input from the recovery text in
the orchestrator summary. There is no `version` input; the version is
derived from the `release/X.Y.Z` branch the workflow runs on.

Not addressed here: `actionlint` and `zizmor` lint one file at a time
and do not inspect the reusable-workflow call graph, so no linter
catches this class of error. It only surfaces on dispatch.

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Fixes: INFRA-3735 follow-up (orchestrator was never dispatched
end-to-end before 13.43.0)

## **Manual testing steps**

1. Dispatch **Runway extension release and store submit** on a
`release/*` branch with `execute_store_phases=false` (validation-only
run).
2. Confirm the run is created, i.e. no `The workflow is not valid ...
attestations: none` error. On `main` today, run creation fails at this
point.
3. Confirm Phase 0 validation passes and Phases 1 to 3 are skipped.
4. Open the orchestrator summary and confirm the recovery line reads
"re-dispatch from the same release branch with the same `release_sha`".

<!--
## **Screenshots/Recordings**

### **Before**

### **After**
-->

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [ ] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

Made with [Cursor](https://cursor.com)

Co-authored-by: Cursor <cursoragent@cursor.com>
@runway-github
runway-github Bot requested review from a team, HowardBraham and itsyoboieltr as code owners August 8, 2026 01:05
@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@metamask-ci metamask-ci Bot added the team-bots Bot team (for MetaMask Bot, Runway Bot, etc.) label Aug 8, 2026
@sleepytanya
sleepytanya enabled auto-merge (squash) August 8, 2026 01:17
@sonarqubecloud

sonarqubecloud Bot commented Aug 8, 2026

Copy link
Copy Markdown

@sleepytanya
sleepytanya merged commit dfc2567 into release/13.43.0 Aug 8, 2026
72 of 73 checks passed
@sleepytanya
sleepytanya deleted the runway-cherry-pick-13.43.0-1786151124 branch August 8, 2026 01:27
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 8, 2026
@metamaskbot metamaskbot added the release-13.43.0 Issue or pull request that will be included in release 13.43.0 label Aug 10, 2026
@gauthierpetetin

Copy link
Copy Markdown
Contributor

No release label on PR. Adding release label release-13.43.0 on PR, as PR was cherry-picked in branch 13.43.0.

This branch had an error being deployed

1 failed deployment
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

release-13.43.0 Issue or pull request that will be included in release 13.43.0 risk:low team-bots Bot team (for MetaMask Bot, Runway Bot, etc.)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants