Commit c946ec1
ci: remove the release workflow from 4.2, it cannot sign for oc10 (#642)
Reverts the workflow added in #640. That was my mistake: this branch ships to
ownCloud 10, and the release pipeline cannot produce an artifact oc10 accepts.
oc10 and oc11 do not share a signing generation:
oc10 {hashes, signature, certificate} legacy G1, single root.crt
oc11 {v, alg, hashes, signature, certificates} G2, roots/ + intermediates/
`lib/private/IntegrityCheck/Checker.php` on 10.16 reads `certificate` in the
singular and verifies against the one `resources/codesigning/root.crt`. It has
no code path for a `v`/`certificates` envelope, nor for the ECDSA P-384
signature G2 uses. oc11's verifier accepts both generations, which is why the
same workflow is correct on master and wrong here.
The reusable release workflow signs with `ocsign`, overriding the Makefile's
`occ integrity:sign-app`. ocsign emits G2 only - its flags are --path --key
--cert --chain --core --allow-vcs --out --dry-run, with no legacy mode - and the
repository's signing secrets hold a G2 key. So a tag on this branch would have
published a tarball that fails `occ integrity:check-app` on every oc10 server,
with admins seeing a tamper warning.
Confirmed against the real artifacts rather than the docs: the marketplace
tarball for 4.2.3, which is what oc10 admins install, carries a legacy G1
envelope signed by a CN=richdocuments leaf issued by "ownCloud Code Signing
Intermediate Authority", while v4.3.0 and v4.3.1 carry G2.
Releases on this branch therefore stay manual, signed with the legacy G1 key by
whoever holds it, and uploaded to the marketplace - exactly how 4.2.1, 4.2.2 and
4.2.3 shipped. The version bump from #640 stands; only the workflow goes.
Signed-off-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com>
Co-authored-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent 8844ae0 commit c946ec1
1 file changed
Lines changed: 0 additions & 22 deletions
This file was deleted.
0 commit comments