From 4c25e95170aefeafadb4f5206b9dedaa42050f46 Mon Sep 17 00:00:00 2001 From: flant-team-sysdev Date: Sat, 19 Sep 2026 14:21:16 +0300 Subject: [PATCH 1/2] chore: release 1.1.0 --- CHANGELOG.md | 41 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 77bdc70..9df2884 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,46 @@ # Changelog +## [1.1.0](https://www.github.com/flant/trx/compare/v1.0.0...v1.1.0) (2026-09-19) + + +### ⚠ BREAKING CHANGES + +* **quorum:** The existing cases all run with NumberOfKeys: 1, so they cover a mixed key list rather than a quorum: the second signature of a quorum lives in the git-signatures note, not in the tag object. Add a 2-of-2 case with an EdDSA tag signature and an RSA note signature, plus the negative case where only one of the two signing keys is trusted. + +### Bug Fixes + +* **command:** fail on an unknown template variable ([f6b265e](https://www.github.com/flant/trx/commit/f6b265ebe89a9a60c2991d2b8ccd544fca64a86d)) +* **command:** render commands with text/template ([4f4543b](https://www.github.com/flant/trx/commit/4f4543b034237027da7c17252cc6d2c6ee45d203)) +* **command:** signal the whole process group, keep hooks alive ([11e8e8e](https://www.github.com/flant/trx/commit/11e8e8e728ff4d722d6f47d1679fe3777fec70ed)) +* **command:** upper-case env names in one place, let the operator win ([6c32151](https://www.github.com/flant/trx/commit/6c32151d330792d6e8e9a6b345a1616e3134e4a5)) +* **config:** keep accepting initial_last_published_git_commit ([5b8f75a](https://www.github.com/flant/trx/commit/5b8f75a5a2a93e09383e0885ec1120b346d6a5c3)) +* **git:** bound clone and fetch, and repair a broken clone ([7e9f572](https://www.github.com/flant/trx/commit/7e9f572122910dd393e7cb0d15dca1843fb8093e)) +* **git:** clean the worktree when checking out the target tag ([6101d8c](https://www.github.com/flant/trx/commit/6101d8c6111ac10d478b65c9a9535cfd726faaaa)) +* **git:** deploy the newest tag again, pre-release or not ([469e8c2](https://www.github.com/flant/trx/commit/469e8c2186b9141364768775ce2604704a927fc7)) +* **git:** do not deploy a pre-release as a release ([6969ea1](https://www.github.com/flant/trx/commit/6969ea1732ed8fccc4583bc489f93870d4f60415)) +* **git:** resolve an annotated tag to its commit ([3ec414f](https://www.github.com/flant/trx/commit/3ec414f4b67afb990eeb79b6dec751483579d050)) +* **lock:** skip locking with --disable-lock and fail on a lost race ([#34](https://www.github.com/flant/trx/issues/34)) ([418047c](https://www.github.com/flant/trx/commit/418047c0c0c7957536c58e650747d28d86758143)) +* print hook errors, name the right hooks, drop dead code ([4256e98](https://www.github.com/flant/trx/commit/4256e984018a159914fc1f409111dd9b4f2e3b05)) +* **quorum:** do not panic on a quorum without a name ([1dc7384](https://www.github.com/flant/trx/commit/1dc738423066449e20b8b7ceb24b48e1759d2ab5)) +* **quorum:** support EdDSA (Ed25519) GPG keys in signature verification ([b32caf4](https://www.github.com/flant/trx/commit/b32caf4a053170c505c8e39f6e4644d0599a1afb)) +* **quorum:** support EdDSA (Ed25519) GPG keys in signature verification ([d8ee7a4](https://www.github.com/flant/trx/commit/d8ee7a4f25d036053d1522570034890ed30a332d)) +* **quorum:** support EdDSA (Ed25519) GPG keys in signature verification ([#12](https://www.github.com/flant/trx/issues/12)) ([b32caf4](https://www.github.com/flant/trx/commit/b32caf4a053170c505c8e39f6e4644d0599a1afb)) +* **quorum:** warn about a duplicate GPG key instead of refusing to start ([f454712](https://www.github.com/flant/trx/commit/f45471206a22ba6963847e28ac32ea8c214c97f4)) +* report the locker and ssh key errors instead of ignoring them ([6caa0b8](https://www.github.com/flant/trx/commit/6caa0b86f514e8fbe54bba20b70d51b51c8b7c57)) +* **run:** retry a tag that failed again ([e23b5a9](https://www.github.com/flant/trx/commit/e23b5a9965cdeaeba86be75a363032e264cb8056)) +* **storage:** write the state atomically ([b39a881](https://www.github.com/flant/trx/commit/b39a881d2092e5791b7cffe2ba3d103f2ec65db1)) +* the blocking findings of the main audit ([#37](https://www.github.com/flant/trx/issues/37)) ([c8c3cd9](https://www.github.com/flant/trx/commit/c8c3cd974b473dd0cac0b28a9a30fbc3dfb10f44)) + + +### Tests + +* **quorum:** cover a real two-signature quorum, generate the test key ([ad9f231](https://www.github.com/flant/trx/commit/ad9f23118e37c57458c3c6f3d5eee0050eeb2e60)) + + +### Miscellaneous Chores + +* release the audit fixes as 1.1.0 ([9b5d0bc](https://www.github.com/flant/trx/commit/9b5d0bc7beac70c304f03bf8f8e56a4351a00d39)) + ## 1.0.0 (2025-03-21) From b36679175b96cb5fac2eea34df75a62453e4b017 Mon Sep 17 00:00:00 2001 From: Aleksei Igrychev Date: Sat, 19 Sep 2026 13:01:11 +0100 Subject: [PATCH 2/2] docs(changelog): drop the false breaking change, list the real ones The BREAKING CHANGE trailer of ad9f231 claimed that verification stops accepting DSA and ElGamal keys and SHA-1 signatures. That rejection policy is only applied by the openpgp/v2 API and trdl uses v1, so nothing of the sort happens; tags signed with such keys still verify. The section is replaced by the behaviour changes this release does carry. The pre-release skip and the failed-tag skip cancel out within the release and are dropped from the list, and the three identical EdDSA entries are collapsed into one. Signed-off-by: Aleksei Igrychev --- CHANGELOG.md | 21 ++++++++++++++------- 1 file changed, 14 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9df2884..f396665 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,9 +3,21 @@ ## [1.1.0](https://www.github.com/flant/trx/compare/v1.0.0...v1.1.0) (2026-09-19) -### ⚠ BREAKING CHANGES +### Notable Changes -* **quorum:** The existing cases all run with NumberOfKeys: 1, so they cover a mixed key list rather than a quorum: the second signature of a quorum lives in the git-signatures note, not in the tag object. Add a 2-of-2 case with an EdDSA tag signature and an RSA note signature, plus the negative case where only one of the two signing keys is trusted. +No breaking change: the `BREAKING CHANGE` trailer of ad9f231 described a +rejection of DSA and ElGamal keys and of SHA-1 signatures that the verification +path never applies, since that policy belongs to the `openpgp/v2` API and trdl +uses v1. Tags signed with such keys keep passing verification. + +These do change behaviour, without breaking a working configuration: + +* `onQuorumFailure` and `onCommandSkipped` run in the working directory trx was started in, not in the checkout, so that a hook reporting a failed verification cannot execute unverified repository content. A relative path such as `./notify.sh` stops resolving inside the repository. +* The operator `env` overrides the repository one, as the README documents, and env names coming from a repository `trx.yaml` are upper-cased. +* An unknown template variable fails the run instead of being rendered as the literal ``. +* Checking out the target tag removes untracked files left in the clone. +* `--disable-lock` skips locking outright, and an instance that loses the lock race fails instead of deploying concurrently. +* A quorum that lists the same GPG key twice keeps loading, with a warning, but the duplicate no longer counts towards `minNumberOfKeys`: such a quorum now fails verification through `onQuorumFailure`. ### Bug Fixes @@ -16,18 +28,13 @@ * **config:** keep accepting initial_last_published_git_commit ([5b8f75a](https://www.github.com/flant/trx/commit/5b8f75a5a2a93e09383e0885ec1120b346d6a5c3)) * **git:** bound clone and fetch, and repair a broken clone ([7e9f572](https://www.github.com/flant/trx/commit/7e9f572122910dd393e7cb0d15dca1843fb8093e)) * **git:** clean the worktree when checking out the target tag ([6101d8c](https://www.github.com/flant/trx/commit/6101d8c6111ac10d478b65c9a9535cfd726faaaa)) -* **git:** deploy the newest tag again, pre-release or not ([469e8c2](https://www.github.com/flant/trx/commit/469e8c2186b9141364768775ce2604704a927fc7)) -* **git:** do not deploy a pre-release as a release ([6969ea1](https://www.github.com/flant/trx/commit/6969ea1732ed8fccc4583bc489f93870d4f60415)) * **git:** resolve an annotated tag to its commit ([3ec414f](https://www.github.com/flant/trx/commit/3ec414f4b67afb990eeb79b6dec751483579d050)) * **lock:** skip locking with --disable-lock and fail on a lost race ([#34](https://www.github.com/flant/trx/issues/34)) ([418047c](https://www.github.com/flant/trx/commit/418047c0c0c7957536c58e650747d28d86758143)) * print hook errors, name the right hooks, drop dead code ([4256e98](https://www.github.com/flant/trx/commit/4256e984018a159914fc1f409111dd9b4f2e3b05)) * **quorum:** do not panic on a quorum without a name ([1dc7384](https://www.github.com/flant/trx/commit/1dc738423066449e20b8b7ceb24b48e1759d2ab5)) -* **quorum:** support EdDSA (Ed25519) GPG keys in signature verification ([b32caf4](https://www.github.com/flant/trx/commit/b32caf4a053170c505c8e39f6e4644d0599a1afb)) -* **quorum:** support EdDSA (Ed25519) GPG keys in signature verification ([d8ee7a4](https://www.github.com/flant/trx/commit/d8ee7a4f25d036053d1522570034890ed30a332d)) * **quorum:** support EdDSA (Ed25519) GPG keys in signature verification ([#12](https://www.github.com/flant/trx/issues/12)) ([b32caf4](https://www.github.com/flant/trx/commit/b32caf4a053170c505c8e39f6e4644d0599a1afb)) * **quorum:** warn about a duplicate GPG key instead of refusing to start ([f454712](https://www.github.com/flant/trx/commit/f45471206a22ba6963847e28ac32ea8c214c97f4)) * report the locker and ssh key errors instead of ignoring them ([6caa0b8](https://www.github.com/flant/trx/commit/6caa0b86f514e8fbe54bba20b70d51b51c8b7c57)) -* **run:** retry a tag that failed again ([e23b5a9](https://www.github.com/flant/trx/commit/e23b5a9965cdeaeba86be75a363032e264cb8056)) * **storage:** write the state atomically ([b39a881](https://www.github.com/flant/trx/commit/b39a881d2092e5791b7cffe2ba3d103f2ec65db1)) * the blocking findings of the main audit ([#37](https://www.github.com/flant/trx/issues/37)) ([c8c3cd9](https://www.github.com/flant/trx/commit/c8c3cd974b473dd0cac0b28a9a30fbc3dfb10f44))