From f9369a3566ba6597e1542db65f394c06c1a9d8a2 Mon Sep 17 00:00:00 2001 From: frodehus Date: Sat, 19 Sep 2026 15:08:42 +0200 Subject: [PATCH] Order the Windows signing jobs instead of grouping them MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The concurrency group added an hour ago made things worse, not better. Only one job per group may be pending: when the CLI matrix's three legs and the Windows app all queued on `certum-simplysign`, each new pending leg cancelled the one before it, and the v1.8.0 run lost "CLI (linux)" and "CLI (windows)" outright. The documentation's "up to 100 pending" describes `queue: max`, not the default. So the group now covers only jobs that are not matrices — the Windows app and the manual signing check — where at most one can ever be pending. The race it was meant to fix is between the Windows app and the CLI's windows leg, and that is now ordering: `cli` lists `windows` in `needs`, with an `always()` guard so a failed Windows app still lets the CLI build and sign rather than skipping it. The cost is that the linux and macOS legs start after the app job, which the group was charging them anyway. Co-authored-by: Claude Opus 5 --- .github/workflows/release-audit.yml | 8 -------- .github/workflows/release.yml | 17 +++++++---------- 2 files changed, 7 insertions(+), 18 deletions(-) diff --git a/.github/workflows/release-audit.yml b/.github/workflows/release-audit.yml index e4ab059..6e0dae0 100644 --- a/.github/workflows/release-audit.yml +++ b/.github/workflows/release-audit.yml @@ -132,14 +132,6 @@ jobs: if: github.event_name == 'push' needs: check runs-on: ${{ matrix.os }} - # One Certum SimplySign account serves every signing job, and a TOTP code is single-use, so - # two logins that overlap make the loser read "invalid user name or token" — which the script - # can only see as a rejected credential. This group holds every signing job in the repository, - # across workflows, to one login at a time. Not `matrix`-scoped: job-level concurrency may use - # only the github, inputs and vars contexts, so the CLI's other legs queue here too. - concurrency: - group: certum-simplysign - cancel-in-progress: false strategy: fail-fast: false matrix: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index fe61e64..4c69792 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -527,17 +527,14 @@ jobs: # archive holds just the executable; the .sha256 next to it feeds the formula and the manifest. cli: name: CLI (${{ matrix.name }}) - if: github.event_name == 'push' - needs: check + if: always() && github.event_name == 'push' && needs.check.result == 'success' + # Ordered after the Windows app, not dependent on it: its windows leg signs with the same + # single-use TOTP as that job, and two overlapping logins make the loser read "invalid user + # name or token". A concurrency group cannot serialise them — job-level concurrency cannot + # read `matrix`, and one group for the whole matrix cancels queued legs, since only one job + # per group may be pending. + needs: [check, windows] runs-on: ${{ matrix.os }} - # One Certum SimplySign account serves every signing job, and a TOTP code is single-use, so - # two logins that overlap make the loser read "invalid user name or token" — which the script - # can only see as a rejected credential. This group holds every signing job in the repository, - # across workflows, to one login at a time. Not `matrix`-scoped: job-level concurrency may use - # only the github, inputs and vars contexts, so the CLI's other legs queue here too. - concurrency: - group: certum-simplysign - cancel-in-progress: false strategy: fail-fast: false matrix: