fix(rsync): fetch the file a re-signed sha512 names - #13
Merged
Merged
Conversation
TeX Live's nightly build copies the prebuilt install-tl-iso-windows.exe unchanged, then writes its sha512 and signature again. The delta held the sha512 and asc but not the exe, so verify's shasum -c found no file in staging and every ctan run from 2026-10-01 03:42 UTC failed there. diff now adds the file each changed signed sha512 names, by verify's own pattern, so verify checks it against the new sum. merge drops a batch's paths before adding its lines, so the re-fetched file is listed once.
This was referenced Oct 1, 2026
jshvn
added a commit
to katoptra/tlnet
that referenced
this pull request
Oct 1, 2026
## Why lib v2.2.1 (katoptra/lib#13) fixes the ctan `verify` failure from 2026-10-01 03:42 UTC. TeX Live's nightly build writes `install-tl-iso-windows.exe.sha512` and its signature again without touching the exe, so the batch carried the sha512 but not the file it names, and `shasum -c` found nothing in staging. ## What - `render.txt` gains one `diff` line: the file each changed signed sha512 names joins the delta, so `verify` checks it against the new sum. ## Test plan - [x] `render.txt` rendered against the lib branch before release; exactly the one line differs. The `check` job re-renders it against the released `v2`.
jshvn
added a commit
to katoptra/ctan
that referenced
this pull request
Oct 1, 2026
## Why lib v2.2.1 (katoptra/lib#13) fixes the ctan `verify` failure from 2026-10-01 03:42 UTC. TeX Live's nightly build writes `install-tl-iso-windows.exe.sha512` and its signature again without touching the exe, so the batch carried the sha512 but not the file it names, and `shasum -c` found nothing in staging. ## What - `render.txt` gains one `diff` line: the file each changed signed sha512 names joins the delta, so `verify` checks it against the new sum. ## Test plan - [x] `render.txt` rendered against the lib branch before release; exactly the one line differs. The `check` job re-renders it against the released `v2`.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Every ctan run since 2026-10-01 03:42 UTC fails in
verify(run 36811718838):TeX Live's
tl-update-install-pkgcopies the prebuiltinstall-tl-iso-windows.exewithout changes (its mtime is still its 2026-09-28 commit), then writes its.sha512and signature again every night. The sha512 bytes stay the same; only its mtime and the.ascchange. The delta heldx.sha512andx.sha512.ascbut notx, soshasum -cfound no file in staging. The failed batch never checkpoints, so every hourly run repeats it. tlnet uses the same engine andTL.What
diffadds the file each changed signed sha512 names (verify's pattern:TL/*.sha512and the tlpdb's) from upstream's listing, then re-sorts. verify checks the exe against the new sum; publish uploads the same 2 MB again each night.mergedrops a batch's paths before adding its lines, so the re-fetched file is listed once in the state.diffrow say the same.The next patch release, v2.2.1. Moving
v2reaches ctan and tlnet without a consumer change; each gets a render.txt PR for the one new line.Test plan
examples/rsync:task run -- task offlinefailed on the newrun-resigncase before the fix (changed.txt held only the sha512 and asc) and passes after; every other case still passes.examples/rsync:task check, render.txt gains exactly the onediffline.v2: the next ctan run passesverifyand uploadsinstall-tl-iso-windows.exe.