diff --git a/.github/workflows/release-audit.yml b/.github/workflows/release-audit.yml index 8db6c4aa..e4ab0599 100644 --- a/.github/workflows/release-audit.yml +++ b/.github/workflows/release-audit.yml @@ -132,6 +132,14 @@ jobs: if: github.event_name == 'push' needs: check runs-on: ${{ matrix.os }} + # One Certum SimplySign account serves every signing job, and a TOTP code is single-use, so + # two logins that overlap make the loser read "invalid user name or token" — which the script + # can only see as a rejected credential. This group holds every signing job in the repository, + # across workflows, to one login at a time. Not `matrix`-scoped: job-level concurrency may use + # only the github, inputs and vars contexts, so the CLI's other legs queue here too. + concurrency: + group: certum-simplysign + cancel-in-progress: false strategy: fail-fast: false matrix: @@ -308,7 +316,7 @@ jobs: echo ' brew trust frodehus/elevate' echo ' brew install frodehus/elevate/elevate-audit' echo - echo 'Windows: `winget install Reothor.Elevate.Audit` (the manifest goes to winget-pkgs with each release and is published once Microsoft's checks pass, usually within a day or two), or download `elevate-audit-'"$VERSION"'-win-x64.zip` (or `-win-arm64.zip`) below and put `elevate-audit.exe` on your PATH.' + echo 'Windows: `winget install Reothor.Elevate.Audit` (the manifest goes to winget-pkgs with each release and is published once Microsoft'"'"'s checks pass, usually within a day or two), or download `elevate-audit-'"$VERSION"'-win-x64.zip` (or `-win-arm64.zip`) below and put `elevate-audit.exe` on your PATH.' echo echo 'Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with `sha256sum -c elevate-audit-'"$VERSION"'-checksums.txt`. See [docs/audit.md](https://github.com/'"${{ github.repository }}"'/blob/main/docs/audit.md).' echo diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 6919bafe..fe61e64a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -427,6 +427,14 @@ jobs: if: github.event_name == 'push' needs: check runs-on: windows-latest + # One Certum SimplySign account serves every signing job, and a TOTP code is single-use, so + # two logins that overlap make the loser read "invalid user name or token" — which the script + # can only see as a rejected credential. This group holds every signing job in the repository, + # across workflows, to one login at a time. Not `matrix`-scoped: job-level concurrency may use + # only the github, inputs and vars contexts, so the CLI's other legs queue here too. + concurrency: + group: certum-simplysign + cancel-in-progress: false env: TAG: ${{ github.ref_name }} outputs: @@ -522,6 +530,14 @@ jobs: if: github.event_name == 'push' needs: check runs-on: ${{ matrix.os }} + # One Certum SimplySign account serves every signing job, and a TOTP code is single-use, so + # two logins that overlap make the loser read "invalid user name or token" — which the script + # can only see as a rejected credential. This group holds every signing job in the repository, + # across workflows, to one login at a time. Not `matrix`-scoped: job-level concurrency may use + # only the github, inputs and vars contexts, so the CLI's other legs queue here too. + concurrency: + group: certum-simplysign + cancel-in-progress: false strategy: fail-fast: false matrix: @@ -759,7 +775,7 @@ jobs: echo echo ' brew install frodehus/elevate/elevate-cli' echo - echo 'Windows: `Elevate-'"$VERSION"'-x64.msi` (or `-arm64.msi`) installs `elevate.exe` in a `cli` folder under the app and adds that folder to your PATH. Standalone: `winget install Reothor.Elevate.CLI` (the manifest goes to winget-pkgs with each release and is published once Microsoft's checks pass, usually within a day or two), or download `elevate-cli-'"$VERSION"'-win-x64.zip` (or `-win-arm64.zip`) below and put `elevate.exe` on your PATH.' + echo 'Windows: `Elevate-'"$VERSION"'-x64.msi` (or `-arm64.msi`) installs `elevate.exe` in a `cli` folder under the app and adds that folder to your PATH. Standalone: `winget install Reothor.Elevate.CLI` (the manifest goes to winget-pkgs with each release and is published once Microsoft'"'"'s checks pass, usually within a day or two), or download `elevate-cli-'"$VERSION"'-win-x64.zip` (or `-win-arm64.zip`) below and put `elevate.exe` on your PATH.' echo echo 'Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with `sha256sum -c elevate-cli-'"$VERSION"'-checksums.txt`. See [cli/README.md](https://github.com/'"${{ github.repository }}"'/blob/main/cli/README.md).' if [ "$MAC_SIGNED" != "1" ]; then diff --git a/.github/workflows/signing-check.yml b/.github/workflows/signing-check.yml index 2b2e908f..903274e2 100644 --- a/.github/workflows/signing-check.yml +++ b/.github/workflows/signing-check.yml @@ -8,8 +8,9 @@ name: Signing check on: workflow_dispatch: +# Shared with the release workflows' signing jobs: one Certum account, one login at a time. concurrency: - group: "${{ github.workflow }}" + group: certum-simplysign cancel-in-progress: false jobs: diff --git a/scripts/Connect-SimplySign.ps1 b/scripts/Connect-SimplySign.ps1 index b456e4f1..74e6560f 100644 --- a/scripts/Connect-SimplySign.ps1 +++ b/scripts/Connect-SimplySign.ps1 @@ -248,7 +248,7 @@ for ($elapsed = 0; $elapsed -lt 180; $elapsed += 5) { exit 0 } if (Get-AppWindows | Where-Object { $_ -ne $login }) { - if ($retries -ge 3) { throw "SimplySign rejected the credentials $retries times; check the account name, the otpauth URI and the clock." } + if ($retries -ge 3) { throw "SimplySign refused the login $retries times. The likeliest cause is another signing job holding the account: a TOTP code is single-use, so whichever login lands second reads 'invalid user name or token'. Check that no other run is signing, then the account name, the otpauth URI and the clock." } $retries++ if (Dismiss-Modals $login) { Start-Sleep -Milliseconds 500