From fbd81513f98c1941a62621e4da48c4010d6e32d9 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 16:14:59 +0100 Subject: [PATCH] fix(ci): install Zig from a pinned, sha256-verified tarball instead of mlugg/setup-zig mlugg/setup-zig is not on this repo's Actions allow-list (GitHub-owned + verified creators only), so `ABI Contract` and `Cross-Platform Build & Test` ended in startup_failure on main and every PR with: The action mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 is not allowed in hyperpolymath/game-server-admin because all actions must be from a repository owned by hyperpolymath, created by GitHub, or verified in the GitHub Marketplace. No verified-creator Zig installer exists, so replace the action with scripts/install-zig.sh: it downloads the official Zig 0.15.2 x86_64-linux tarball from ziglang.org, checks it against a pinned sha256 (whose minisign signature was verified against the ZSF release key at pin time), and puts it on PATH. The Idris2 container job also installs curl + ca-certificates. actions.lock: hand-removed the three mlugg/setup-zig@v2.2.1 entries (two workflow lists, one dependency). `gh actions-lock --no-fix` reports valid. Refs #103 Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK --- .github/workflows/abi-contract.yml | 14 +++---- .github/workflows/actions.lock | 7 ---- .github/workflows/cross-platform.yml | 5 +-- docs/maintainer/CI-CD-GUIDE.adoc | 2 +- scripts/install-zig.sh | 61 ++++++++++++++++++++++++++++ 5 files changed, 70 insertions(+), 19 deletions(-) create mode 100755 scripts/install-zig.sh diff --git a/.github/workflows/abi-contract.yml b/.github/workflows/abi-contract.yml index cc6e4e0..09430e1 100644 --- a/.github/workflows/abi-contract.yml +++ b/.github/workflows/abi-contract.yml @@ -35,9 +35,8 @@ jobs: uses: actions/checkout@v4.2.2 - name: Install Zig 0.15.2 - uses: mlugg/setup-zig@v2.2.1 - with: - version: 0.15.2 + # Pinned + sha256-verified tarball; no third-party action (#103). + run: bash scripts/install-zig.sh - name: Regenerate expected tables from the Idris2 model run: | @@ -78,15 +77,14 @@ jobs: - name: Checkout uses: actions/checkout@v4.2.2 - - name: Install Zig archive prerequisite in the Idris image + - name: Install Zig download prerequisites in the Idris image run: | apt-get update - apt-get install --no-install-recommends -y xz-utils + apt-get install --no-install-recommends -y xz-utils curl ca-certificates - name: Install Zig 0.15.2 for the real shared-library boundary - uses: mlugg/setup-zig@v2.2.1 - with: - version: 0.15.2 + # Pinned + sha256-verified tarball; no third-party action (#103). + run: bash scripts/install-zig.sh - name: Type-check and execute Idris wrappers against libgsa run: bash scripts/test-idris-ffi.sh "$RUNNER_TEMP/gsa-abi-contract" diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index cb8a51d..d562bb6 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -5,7 +5,6 @@ version: 'v0.0.2' workflows: '.github/workflows/abi-contract.yml': - 'actions/checkout@v4.2.2' - - 'mlugg/setup-zig@v2.2.1' '.github/workflows/boj-build.yml': - 'actions/checkout@v4.1.7' '.github/workflows/casket-pages.yml': @@ -21,7 +20,6 @@ workflows: '.github/workflows/cross-platform.yml': - 'actions/cache@v4.2.0' - 'actions/checkout@v4.2.2' - - 'mlugg/setup-zig@v2.2.1' '.github/workflows/dogfood-gate.yml': - 'actions/checkout@v4.3.1' - 'hyperpolymath/deed-ecosystem@main' @@ -196,11 +194,6 @@ dependencies: commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' owner_id: 6759885 repo_id: 1352485172 - 'mlugg/setup-zig@v2.2.1': - ref: 'v2.2.1' - commit: 'sha1-d1434d08867e3ee9daa34448df10607b98908d29' - owner_id: 7289241 - repo_id: 812112570 'peter-evans/repository-dispatch@v4.0.1': ref: 'v4.0.1' commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' diff --git a/.github/workflows/cross-platform.yml b/.github/workflows/cross-platform.yml index 1faaa1f..40db85c 100644 --- a/.github/workflows/cross-platform.yml +++ b/.github/workflows/cross-platform.yml @@ -36,9 +36,8 @@ jobs: uses: actions/checkout@v4.2.2 - name: Install Zig 0.15.2 - uses: mlugg/setup-zig@v2.2.1 - with: - version: 0.15.2 + # Pinned + sha256-verified tarball; no third-party action (#103). + run: bash scripts/install-zig.sh - name: Cache Zig uses: actions/cache@v4.2.0 diff --git a/docs/maintainer/CI-CD-GUIDE.adoc b/docs/maintainer/CI-CD-GUIDE.adoc index 162ef37..38127a5 100644 --- a/docs/maintainer/CI-CD-GUIDE.adoc +++ b/docs/maintainer/CI-CD-GUIDE.adoc @@ -158,7 +158,7 @@ failure instead of a runtime surprise. It has two jobs. === Job `zig-contract` — "Zig ↔ Idris tables in sync" -Runs on `ubuntu-latest` with Zig 0.15.2 installed via `mlugg/setup-zig`. +Runs on `ubuntu-latest` with Zig 0.15.2 installed by `scripts/install-zig.sh` (pinned ziglang.org tarball, sha256-verified; no third-party action). Steps, in order: . **Regenerate expected tables from the Idris2 model** — diff --git a/scripts/install-zig.sh b/scripts/install-zig.sh new file mode 100755 index 0000000..008b9b8 --- /dev/null +++ b/scripts/install-zig.sh @@ -0,0 +1,61 @@ +#!/usr/bin/env bash +# SPDX-License-Identifier: MPL-2.0 +# +# Install a pinned, hash-verified Zig toolchain for CI — no third-party action. +# +# Why this exists: the repo's Actions policy admits only GitHub-owned and +# Marketplace-verified-creator actions. mlugg/setup-zig is neither, so every +# workflow that used it ended in startup_failure before running a single step +# (game-server-admin#103). This script needs no action at all. +# +# Trust chain: the tarball is fetched from ziglang.org over HTTPS and must +# match the sha256 pinned below, or the step fails. At pin time (2026-09-30) +# the tarball's minisign signature was verified against the Zig Software +# Foundation release key +# RWSGOq2NVecA2UPNdBUZykf1CCb147pkmdtYxgb3Ti+JO/wCYvhbAb/U +# (file signature and trusted-comment signature, timestamp:1760215991), and a +# one-byte-altered digest was rejected as a negative control. The committed +# sha256 carries that binding into CI. +# +# To bump: change ZIG_VERSION and ZIG_SHA256 together, taking the shasum from +# https://ziglang.org/download/index.json and re-verifying the .minisig. +# +# Usage: bash scripts/install-zig.sh +# Puts `zig` on PATH for subsequent steps via $GITHUB_PATH. + +set -euo pipefail + +ZIG_VERSION="0.15.2" +ZIG_SHA256_X86_64_LINUX="02aa270f183da276e5b5920b1dac44a63f1a49e55050ebde3aecc9eb82f93239" + +os="$(uname -s)" +arch="$(uname -m)" +if [ "$os" != "Linux" ] || [ "$arch" != "x86_64" ]; then + echo "::error::install-zig.sh pins only x86_64-linux; got ${os}/${arch}. Add a pinned sha256 for this platform." >&2 + exit 1 +fi + +tarball="zig-x86_64-linux-${ZIG_VERSION}.tar.xz" +url="https://ziglang.org/download/${ZIG_VERSION}/${tarball}" + +dest_root="${RUNNER_TEMP:?RUNNER_TEMP must be set (GitHub Actions)}" +work="${dest_root}/zig-download" +dest="${dest_root}/zig-${ZIG_VERSION}" +mkdir -p "$work" "$dest" + +curl --proto '=https' --tlsv1.2 -fsSL --retry 5 --retry-delay 5 \ + -o "${work}/${tarball}" "$url" + +echo "${ZIG_SHA256_X86_64_LINUX} ${work}/${tarball}" | sha256sum -c - + +tar -xJf "${work}/${tarball}" -C "$dest" --strip-components=1 +rm -rf "$work" + +got="$("${dest}/zig" version)" +if [ "$got" != "$ZIG_VERSION" ]; then + echo "::error::installed zig reports '${got}', expected '${ZIG_VERSION}'" >&2 + exit 1 +fi + +echo "$dest" >> "${GITHUB_PATH:?GITHUB_PATH must be set (GitHub Actions)}" +echo "Installed zig ${got} at ${dest}"