Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 9 additions & 1 deletion .github/workflows/release-audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -132,6 +132,14 @@ jobs:
if: github.event_name == 'push'
needs: check
runs-on: ${{ matrix.os }}
# One Certum SimplySign account serves every signing job, and a TOTP code is single-use, so
# two logins that overlap make the loser read "invalid user name or token" — which the script
# can only see as a rejected credential. This group holds every signing job in the repository,
# across workflows, to one login at a time. Not `matrix`-scoped: job-level concurrency may use
# only the github, inputs and vars contexts, so the CLI's other legs queue here too.
concurrency:
group: certum-simplysign
cancel-in-progress: false
strategy:
fail-fast: false
matrix:
Expand Down Expand Up @@ -308,7 +316,7 @@ jobs:
echo ' brew trust frodehus/elevate'
echo ' brew install frodehus/elevate/elevate-audit'
echo
echo 'Windows: `winget install Reothor.Elevate.Audit` (the manifest goes to winget-pkgs with each release and is published once Microsoft's checks pass, usually within a day or two), or download `elevate-audit-'"$VERSION"'-win-x64.zip` (or `-win-arm64.zip`) below and put `elevate-audit.exe` on your PATH.'
echo 'Windows: `winget install Reothor.Elevate.Audit` (the manifest goes to winget-pkgs with each release and is published once Microsoft'"'"'s checks pass, usually within a day or two), or download `elevate-audit-'"$VERSION"'-win-x64.zip` (or `-win-arm64.zip`) below and put `elevate-audit.exe` on your PATH.'
echo
echo 'Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with `sha256sum -c elevate-audit-'"$VERSION"'-checksums.txt`. See [docs/audit.md](https://github.com/'"${{ github.repository }}"'/blob/main/docs/audit.md).'
echo
Expand Down
18 changes: 17 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -427,6 +427,14 @@ jobs:
if: github.event_name == 'push'
needs: check
runs-on: windows-latest
# One Certum SimplySign account serves every signing job, and a TOTP code is single-use, so
# two logins that overlap make the loser read "invalid user name or token" — which the script
# can only see as a rejected credential. This group holds every signing job in the repository,
# across workflows, to one login at a time. Not `matrix`-scoped: job-level concurrency may use
# only the github, inputs and vars contexts, so the CLI's other legs queue here too.
concurrency:
group: certum-simplysign
cancel-in-progress: false
env:
TAG: ${{ github.ref_name }}
outputs:
Expand Down Expand Up @@ -522,6 +530,14 @@ jobs:
if: github.event_name == 'push'
needs: check
runs-on: ${{ matrix.os }}
# One Certum SimplySign account serves every signing job, and a TOTP code is single-use, so
# two logins that overlap make the loser read "invalid user name or token" — which the script
# can only see as a rejected credential. This group holds every signing job in the repository,
# across workflows, to one login at a time. Not `matrix`-scoped: job-level concurrency may use
# only the github, inputs and vars contexts, so the CLI's other legs queue here too.
concurrency:
group: certum-simplysign
cancel-in-progress: false
strategy:
fail-fast: false
matrix:
Expand Down Expand Up @@ -759,7 +775,7 @@ jobs:
echo
echo ' brew install frodehus/elevate/elevate-cli'
echo
echo 'Windows: `Elevate-'"$VERSION"'-x64.msi` (or `-arm64.msi`) installs `elevate.exe` in a `cli` folder under the app and adds that folder to your PATH. Standalone: `winget install Reothor.Elevate.CLI` (the manifest goes to winget-pkgs with each release and is published once Microsoft's checks pass, usually within a day or two), or download `elevate-cli-'"$VERSION"'-win-x64.zip` (or `-win-arm64.zip`) below and put `elevate.exe` on your PATH.'
echo 'Windows: `Elevate-'"$VERSION"'-x64.msi` (or `-arm64.msi`) installs `elevate.exe` in a `cli` folder under the app and adds that folder to your PATH. Standalone: `winget install Reothor.Elevate.CLI` (the manifest goes to winget-pkgs with each release and is published once Microsoft'"'"'s checks pass, usually within a day or two), or download `elevate-cli-'"$VERSION"'-win-x64.zip` (or `-win-arm64.zip`) below and put `elevate.exe` on your PATH.'
echo
echo 'Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with `sha256sum -c elevate-cli-'"$VERSION"'-checksums.txt`. See [cli/README.md](https://github.com/'"${{ github.repository }}"'/blob/main/cli/README.md).'
if [ "$MAC_SIGNED" != "1" ]; then
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/signing-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,9 @@ name: Signing check
on:
workflow_dispatch:

# Shared with the release workflows' signing jobs: one Certum account, one login at a time.
concurrency:
group: "${{ github.workflow }}"
group: certum-simplysign
cancel-in-progress: false

jobs:
Expand Down
2 changes: 1 addition & 1 deletion scripts/Connect-SimplySign.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -248,7 +248,7 @@ for ($elapsed = 0; $elapsed -lt 180; $elapsed += 5) {
exit 0
}
if (Get-AppWindows | Where-Object { $_ -ne $login }) {
if ($retries -ge 3) { throw "SimplySign rejected the credentials $retries times; check the account name, the otpauth URI and the clock." }
if ($retries -ge 3) { throw "SimplySign refused the login $retries times. The likeliest cause is another signing job holding the account: a TOTP code is single-use, so whichever login lands second reads 'invalid user name or token'. Check that no other run is signing, then the account name, the otpauth URI and the clock." }
$retries++
if (Dismiss-Modals $login) {
Start-Sleep -Milliseconds 500
Expand Down
Loading