From f21bd7b94d07aabaa4d5b3b3dcfe095514f21b28 Mon Sep 17 00:00:00 2001 From: Josh Sokol Date: Fri, 21 Aug 2026 17:33:12 -0500 Subject: [PATCH] fix(feed): restore prod bundle hashes and upgrade path clobbered by #140 #140 merged the updates-test.simplerisk.com branch into the prod feed, which carried testing-channel truth into the production manifests. The VM hashes in that merge are correct and are KEPT -- this reverts only the parts that describe the prod channel. What was wrong, and how each value was confirmed: - 20260820-001 bundle_md5/bundle_sha256 pointed at the TESTING bundle (61c78cca...). The testing bundle for this version was rebuilt at 15:04 on 2026-08-21 by the CHERRYPICK-ga-notes-testing merge, so it is different bytes from the GA bundle promoted at 14:41. Restored to 3e279416..., verified by downloading BOTH the prod S3 object and the simplerisk/code release asset -- two independent artifacts that agree with each other. - 20260519-001 bundle_md5/bundle_sha256 likewise. Restored to 7d7fb242..., verified by downloading the served prod S3 bundle. - 20260519-001 next_release, and upgrade_path.xml, routed upgrades through 20260709-001 and 20260811-001. Those are testing RCs that never shipped GA -- simplerisk/code has no release for either, and 20260820-001 is the combined GA record for all three. Their bundles 403 on the prod channel, so a customer on 20260519-001 would have been sent to a bundle that is not there. Restored to the direct 20260519-001 -> 20260820-001 hop. - The 20260811-001 / 20260709-001 release and extra_compatibility entries are removed for the same reason: they are not prod releases. Caught by simplerisk/docker's image build, which verifies the bundle against this feed and fails closed. Every docker master PR has been blocked since 20:49. The prod feed has a single writer -- sync_code_repo.yml's update_feeds.sh, which writes the real GA asset hashes. Merging the testing branch into it bypasses that writer and silently replaces GA truth with RC truth. Co-Authored-By: Claude Opus 5 (1M context) --- extra_compatibility.xml | 108 ------------------------------------ releases.xml | 118 ++-------------------------------------- upgrade_path.xml | 4 +- 3 files changed, 6 insertions(+), 224 deletions(-) diff --git a/extra_compatibility.xml b/extra_compatibility.xml index 8c5324e..aae081e 100644 --- a/extra_compatibility.xml +++ b/extra_compatibility.xml @@ -3,12 +3,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -194,12 +188,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -238,12 +226,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -453,12 +435,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -680,12 +656,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -919,12 +889,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -1119,12 +1083,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -1310,12 +1268,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -1507,12 +1459,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -1686,12 +1632,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -1874,12 +1814,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -2077,12 +2011,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -2250,12 +2178,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -2438,12 +2360,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -2629,12 +2545,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -2811,12 +2721,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -3026,12 +2930,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 @@ -3187,12 +3085,6 @@ 20260820-001 - - 20260811-001 - - - 20260709-001 - 20260519-001 diff --git a/releases.xml b/releases.xml index c4fc8e8..bfacba7 100644 --- a/releases.xml +++ b/releases.xml @@ -3,8 +3,8 @@ 20260820 001 - 35be3fefdfd7814ce5d17cd17191cdff - 61c78cca0d0a74b891694238d5fda1321afff15bf5da562cea7bc2d3dcc5338d + 9b639134c80d1eee1f8c86355f9c6c68 + 3e27941634b3791a17e9f498ea992dc1f2c7aa566e201a8aec6e148120429ecf false @@ -53,120 +53,12 @@ - - 20260811 - 001 - 20260820-001 - fb980f836d4ff2a590f25bac4953ef7d - b403c646250d14dcb609429ec15976748be69d55d8bb485d3a8b5f5f6d5c31a0 - false - - - https://raw.githubusercontent.com/simplerisk/database/testing/simplerisk-en-20260811-001.sql - false - - - https://raw.githubusercontent.com/simplerisk/database/testing/simplerisk-es-20260811-001.sql - false - - - https://raw.githubusercontent.com/simplerisk/database/testing/simplerisk-bp-20260811-001.sql - false - - - false - false - - - false - false - - - false - false - - - - - - - - - - - - - - - - - - - - - - - - - 20260709 - 001 - 20260811-001 - 6616d359385782e05ba431fb3bd210b6 - a5a3640a5a3a9dacc00ceaaf0fcc050c4a10592b153e5ae2e8faa7ac9cd1c4bb - false - - - https://raw.githubusercontent.com/simplerisk/database/testing/simplerisk-en-20260709-001.sql - false - - - https://raw.githubusercontent.com/simplerisk/database/testing/simplerisk-es-20260709-001.sql - false - - - https://raw.githubusercontent.com/simplerisk/database/testing/simplerisk-bp-20260709-001.sql - false - - - false - false - - - false - false - - - false - false - - - - - - - - - - - - - - - - - - - - - - - 20260519 001 - 20260709-001 - 6cce708c9edde0fce04a54934ed1f160 - 9741051f053df1c06b19f0e3f7bbc899a6d4f65c0deddc7e45918c76897a506d + 20260820-001 + e8c049832041864bfa1f629183b732d2 + 7d7fb24214081ef5e51480664d29f084ca6e8e93990fe9da2c957ea1dfff1bb4 false false false diff --git a/upgrade_path.xml b/upgrade_path.xml index 977a2d4..f4ef2d1 100644 --- a/upgrade_path.xml +++ b/upgrade_path.xml @@ -1,8 +1,6 @@ - 20260820-001 - 20260811-001 - 20260709-001 + 20260820-001 20260519-001 20260422-001 20260302-001