fix(release): repair Snap uploads and retry published releases (#1691)

* fix(release): allow Snapcraft scratch extraction and retry public releases

* test(release): detect local Snap permission test prerequisites
This commit is contained in:
4gray authored and GitHub committed 2026-09-25 23:34:44 +02:00
1 parent 0ecfc06494
commit 3ed612ba65
6 files changed
+310 -18

No files matched your search

+15
View File
@@ -439,6 +439,21 @@ candidate/stable promotion remain manual (see
draft during artifact verification, then publish it in a follow-up commit and
verify the website deployment.
If a Store upload fails after publication, run `publish-snap.yaml` from
`master` with its `tag` input set to the existing public stable tag, for example
`gh workflow run publish-snap.yaml --ref master -f tag=v0.24.0`. The workflow
resolves the public release through the API, rejects drafts/prereleases and
invalid tags, and repeats the full released-tooling, asset and source-archive
verification before uploading to `edge`. Do not move the release tag, rebuild
its assets or republish the GitHub release to retry a Store upload.
Snapcraft extracts metadata into a temporary sibling of the input `.snap`.
The publisher therefore gives it root-owned read-only hard links in a separate
root-owned sticky directory. Temporary siblings are writable, while the sticky
bit prevents the unprivileged uploader from replacing the root-owned inputs.
The original verified snapshot stays sealed; upload filenames are enumerated
only from that snapshot, never from the writable scratch directory.
## Validation
```bash