Skip to content

fix(rsync): fetch the file a re-signed sha512 names - #13

Merged
jshvn merged 1 commit into
mainfrom
josh/tl-resigned-sha512
Oct 1, 2026
Merged

jshvn merged 1 commit into
mainfrom
josh/tl-resigned-sha512

Conversation

@jshvn

@jshvn jshvn commented Oct 1, 2026

Copy link
Copy Markdown
Member

Why

Every ctan run since 2026-10-01 03:42 UTC fails in verify (run 36811718838):

shasum: install-tl-iso-windows.exe: No such file or directory
install-tl-iso-windows.exe: FAILED open or read

TeX Live's tl-update-install-pkg copies the prebuilt install-tl-iso-windows.exe without changes (its mtime is still its 2026-09-28 commit), then writes its .sha512 and signature again every night. The sha512 bytes stay the same; only its mtime and the .asc change. The delta held x.sha512 and x.sha512.asc but not x, so shasum -c found no file in staging. The failed batch never checkpoints, so every hourly run repeats it. tlnet uses the same engine and TL.

What

  • diff adds the file each changed signed sha512 names (verify's pattern: TL/*.sha512 and the tlpdb's) from upstream's listing, then re-sorts. verify checks the exe against the new sum; publish uploads the same 2 MB again each night.
  • merge drops a batch's paths before adding its lines, so the re-fetched file is listed once in the state.
  • The split comment and the README diff row say the same.

The next patch release, v2.2.1. Moving v2 reaches ctan and tlnet without a consumer change; each gets a render.txt PR for the one new line.

Test plan

  • examples/rsync: task run -- task offline failed on the new run-resign case before the fix (changed.txt held only the sha512 and asc) and passes after; every other case still passes.
  • examples/rsync: task check, render.txt gains exactly the one diff line.
  • After the tag moves v2: the next ctan run passes verify and uploads install-tl-iso-windows.exe.

TeX Live's nightly build copies the prebuilt install-tl-iso-windows.exe
unchanged, then writes its sha512 and signature again. The delta held the
sha512 and asc but not the exe, so verify's shasum -c found no file in
staging and every ctan run from 2026-10-01 03:42 UTC failed there.

diff now adds the file each changed signed sha512 names, by verify's own
pattern, so verify checks it against the new sum. merge drops a batch's
paths before adding its lines, so the re-fetched file is listed once.
@jshvn
jshvn merged commit f7b2a87 into main Oct 1, 2026
2 checks passed
jshvn added a commit to katoptra/tlnet that referenced this pull request Oct 1, 2026
## Why

lib v2.2.1 (katoptra/lib#13) fixes the ctan `verify` failure from
2026-10-01 03:42 UTC. TeX Live's nightly build writes
`install-tl-iso-windows.exe.sha512` and its signature again without
touching the exe, so the batch carried the sha512 but not the file it
names, and `shasum -c` found nothing in staging.

## What

- `render.txt` gains one `diff` line: the file each changed signed
sha512 names joins the delta, so `verify` checks it against the new sum.

## Test plan

- [x] `render.txt` rendered against the lib branch before release;
exactly the one line differs. The `check` job re-renders it against the
released `v2`.
jshvn added a commit to katoptra/ctan that referenced this pull request Oct 1, 2026
## Why

lib v2.2.1 (katoptra/lib#13) fixes the ctan `verify` failure from
2026-10-01 03:42 UTC. TeX Live's nightly build writes
`install-tl-iso-windows.exe.sha512` and its signature again without
touching the exe, so the batch carried the sha512 but not the file it
names, and `shasum -c` found nothing in staging.

## What

- `render.txt` gains one `diff` line: the file each changed signed
sha512 names joins the delta, so `verify` checks it against the new sum.

## Test plan

- [x] `render.txt` rendered against the lib branch before release;
exactly the one line differs. The `check` job re-renders it against the
released `v2`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant