From d4e5ecce59cd1886163e976d9539418dd210b8bd Mon Sep 17 00:00:00 2001 From: ethernet Date: Fri, 11 Sep 2026 20:15:44 -0400 Subject: [PATCH] fix(bundle): reject nonstable Store builds before staging --- scripts/bundles/desktop.py | 5 +++++ tests/scripts/test_commit_bundle_entrypoints.py | 10 +++++++++- 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/scripts/bundles/desktop.py b/scripts/bundles/desktop.py index 3f5d5395a6..e3f760a741 100644 --- a/scripts/bundles/desktop.py +++ b/scripts/bundles/desktop.py @@ -55,6 +55,11 @@ def build(repo: Path, tag: str | None, variant: str, builder_args: list[str], from pm.store import current_target from scripts.releases.commit_build import require_commit, version_at from scripts.releases.bundle_env import decode + from scripts.termux.deb_version import channel_for_tag + + # Reject before preparing a payload that cannot use the Store identity. + if variant == "store" and (commit_build or not tag or channel_for_tag(tag) != "stable"): + raise ValueError("Store packaging requires a stable release tag") repo = repo.resolve() bundle_env = decode(os.environ.get("HERMES_BUNDLE_ENV_JSON", "")) diff --git a/tests/scripts/test_commit_bundle_entrypoints.py b/tests/scripts/test_commit_bundle_entrypoints.py index d909bfea6e..1dcbfa8bd8 100644 --- a/tests/scripts/test_commit_bundle_entrypoints.py +++ b/tests/scripts/test_commit_bundle_entrypoints.py @@ -15,7 +15,7 @@ from scripts.bundles import desktop from tests.ci.test_desktop_release_tag_admission import _BASH, _child_env, _git, _seed_repo -@pytest.mark.parametrize("variant", ["bundled", "store", "light"]) +@pytest.mark.parametrize("variant", ["bundled", "light"]) def test_desktop_build_reaches_the_managed_payload_with_commit_ref(tmp_path, monkeypatch, variant): _, repo = _seed_repo(tmp_path) sha = _git("rev-parse", "HEAD", cwd=repo) @@ -79,6 +79,14 @@ def test_desktop_build_reaches_the_managed_payload_with_commit_ref(tmp_path, mon +@pytest.mark.parametrize("tag,commit", [(None, "a" * 40), ("v1.2.3-canary.20260911120000", None)]) +def test_store_build_rejects_nonstable_before_reading_or_preparing_repo(tmp_path, tag, commit): + absent = tmp_path / "must-not-be-created" + with pytest.raises(ValueError, match="Store.*stable"): + desktop.build(absent, tag, "store", [], commit_build=commit) + assert not absent.exists() + + def test_termux_commit_args_reach_prerequisite_checks_without_mutation(tmp_path): repo = Path(__file__).resolve().parents[2] out = tmp_path / "must-not-be-written"