ludic/changes/per-artifact-checksums.md
Orkuncakilkaya 80da7e6275
Some checks failed
bootstrap / cfree-fixpoint (push) Successful in 24s
ci / build-and-test (push) Successful in 2m54s
commit-lint / conventional-commits (push) Failing after 1s
fix(release): per-artifact checksums so a release can span hosts
build_artifacts wrote a single dist/SHA256SUMS covering whatever that host
happened to build. But a release is assembled from more than one machine — the
Linux runner cannot produce the darwin-arm64 toolchain — and
forgejo_upload_assets deliberately skips an asset whose name is already
attached. So the first host to publish wrote SHA256SUMS, and every artifact
added later was silently left uncovered by it.

Emit one <artifact>.sha256 per tarball instead. The names are unique, so each
host's contribution stands on its own and nothing goes stale.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-05 14:14:00 +03:00

509 B

bump: patch type: fix Release checksums are one .sha256 file per artifact instead of a single SHA256SUMS. A release is assembled from more than one host — a Linux runner cannot build the macOS toolchain — and x publish never overwrites an asset that is already attached, so a shared SHA256SUMS was written by whichever host published first and then never covered anything added afterwards. Per-artifact names compose across hosts. Verify one with shasum -a 256 -c ludic-X.Y.Z-src.tar.gz.sha256.