Skip to content

Commit ec5db2f

Browse files
fix(ci): install Zig from a pinned, verified tarball — replaces non-allow-listed mlugg/setup-zig (#103) (#104)
## Summary Owner ruling 2026-09-30: swap the Zig setup action instead of changing the allow-list. Part of #103, item 1. `ABI Contract` and `Cross-Platform Build & Test` ended in `startup_failure` on `main` and on every PR. Their run pages (35609965294, 35609970129) give this cause: ``` The action mlugg/setup-zig@d1434d0 is not allowed in hyperpolymath/game-server-admin because all actions must be from a repository owned by hyperpolymath, created by GitHub, or verified in the GitHub Marketplace. ``` Repo Actions policy: `allowed_actions=selected`, `github_owned_allowed=true`, `verified_allowed=true`, `patterns_allowed=[]`, `sha_pinning_required=true`. None of the Zig installers is GitHub-owned or from a verified creator (mlugg/setup-zig, goto-bus-stop/setup-zig, korandoru/setup-zig), so no allow-listed action can do this. ## Change - **New `scripts/install-zig.sh`** (MPL-2.0, mode 100755). It downloads `zig-x86_64-linux-0.15.2.tar.xz` from ziglang.org over HTTPS. - It checks the download against the pinned sha256 `02aa270f…f93239`, then puts Zig on `PATH` via `$GITHUB_PATH`. - It checks that `zig version` prints 0.15.2. - It fails loudly on any platform other than x86_64-linux. - At pin time, the tarball's minisign signature was verified against the ZSF key `RWSGOq2NVecA2UPN…`. Both the file signature and the trusted-comment signature passed, and a tampered digest was rejected. - **`abi-contract.yml`** (2 sites) and **`cross-platform.yml`** (1 site): `uses: mlugg/setup-zig` → `run: bash scripts/install-zig.sh`. The idris2-pack container job now also installs `curl ca-certificates`. - **`actions.lock`**, edited by hand; the `gh actions-lock` rewrite mode was not used. Three `mlugg/setup-zig@v2.2.1` entries were removed: two workflow lists and one dependency. `gh actions-lock --no-fix` reports `valid: true`. - **`docs/maintainer/CI-CD-GUIDE.adoc`**: updated to describe how Zig is now installed. ## Validation - `actionlint` on both workflows: clean. `shellcheck` and `bash -n` on the script: clean. - The script ran locally: sha256 OK, and zig 0.15.2 was installed. - Mutant check: with a one-character change to the pinned sha256, the script exits 1 and does not write `GITHUB_PATH`. ## Not in this PR These #103 items are left for follow-up: the Governance, Pages and Mirror startup failures, the K9 pedigree `name` error, and the SonarCloud and Hypatia reds. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
1 parent 070529e commit ec5db2f

5 files changed

Lines changed: 70 additions & 19 deletions

File tree

‎.github/workflows/abi-contract.yml‎

Lines changed: 6 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -35,9 +35,8 @@ jobs:
3535
uses: actions/checkout@v4.2.2
3636

3737
- name: Install Zig 0.15.2
38-
uses: mlugg/setup-zig@v2.2.1
39-
with:
40-
version: 0.15.2
38+
# Pinned + sha256-verified tarball; no third-party action (#103).
39+
run: bash scripts/install-zig.sh
4140

4241
- name: Regenerate expected tables from the Idris2 model
4342
run: |
@@ -78,15 +77,14 @@ jobs:
7877
- name: Checkout
7978
uses: actions/checkout@v4.2.2
8079

81-
- name: Install Zig archive prerequisite in the Idris image
80+
- name: Install Zig download prerequisites in the Idris image
8281
run: |
8382
apt-get update
84-
apt-get install --no-install-recommends -y xz-utils
83+
apt-get install --no-install-recommends -y xz-utils curl ca-certificates
8584
8685
- name: Install Zig 0.15.2 for the real shared-library boundary
87-
uses: mlugg/setup-zig@v2.2.1
88-
with:
89-
version: 0.15.2
86+
# Pinned + sha256-verified tarball; no third-party action (#103).
87+
run: bash scripts/install-zig.sh
9088

9189
- name: Type-check and execute Idris wrappers against libgsa
9290
run: bash scripts/test-idris-ffi.sh "$RUNNER_TEMP/gsa-abi-contract"

‎.github/workflows/actions.lock‎

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,6 @@ version: 'v0.0.2'
55
workflows:
66
'.github/workflows/abi-contract.yml':
77
- 'actions/checkout@v4.2.2'
8-
- 'mlugg/setup-zig@v2.2.1'
98
'.github/workflows/boj-build.yml':
109
- 'actions/checkout@v4.1.7'
1110
'.github/workflows/casket-pages.yml':
@@ -21,7 +20,6 @@ workflows:
2120
'.github/workflows/cross-platform.yml':
2221
- 'actions/cache@v4.2.0'
2322
- 'actions/checkout@v4.2.2'
24-
- 'mlugg/setup-zig@v2.2.1'
2523
'.github/workflows/dogfood-gate.yml':
2624
- 'actions/checkout@v4.3.1'
2725
- 'hyperpolymath/deed-ecosystem@main'
@@ -196,11 +194,6 @@ dependencies:
196194
commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7'
197195
owner_id: 6759885
198196
repo_id: 1352485172
199-
'mlugg/setup-zig@v2.2.1':
200-
ref: 'v2.2.1'
201-
commit: 'sha1-d1434d08867e3ee9daa34448df10607b98908d29'
202-
owner_id: 7289241
203-
repo_id: 812112570
204197
'peter-evans/repository-dispatch@v4.0.1':
205198
ref: 'v4.0.1'
206199
commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697'

‎.github/workflows/cross-platform.yml‎

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -36,9 +36,8 @@ jobs:
3636
uses: actions/checkout@v4.2.2
3737

3838
- name: Install Zig 0.15.2
39-
uses: mlugg/setup-zig@v2.2.1
40-
with:
41-
version: 0.15.2
39+
# Pinned + sha256-verified tarball; no third-party action (#103).
40+
run: bash scripts/install-zig.sh
4241

4342
- name: Cache Zig
4443
uses: actions/cache@v4.2.0

‎docs/maintainer/CI-CD-GUIDE.adoc‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -158,7 +158,7 @@ failure instead of a runtime surprise. It has two jobs.
158158

159159
=== Job `zig-contract` — "Zig ↔ Idris tables in sync"
160160

161-
Runs on `ubuntu-latest` with Zig 0.15.2 installed via `mlugg/setup-zig`.
161+
Runs on `ubuntu-latest` with Zig 0.15.2 installed by `scripts/install-zig.sh` (pinned ziglang.org tarball, sha256-verified; no third-party action).
162162
Steps, in order:
163163

164164
. **Regenerate expected tables from the Idris2 model** —

‎scripts/install-zig.sh‎

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
#!/usr/bin/env bash
2+
# SPDX-License-Identifier: MPL-2.0
3+
#
4+
# Install a pinned, hash-verified Zig toolchain for CI — no third-party action.
5+
#
6+
# Why this exists: the repo's Actions policy admits only GitHub-owned and
7+
# Marketplace-verified-creator actions. mlugg/setup-zig is neither, so every
8+
# workflow that used it ended in startup_failure before running a single step
9+
# (game-server-admin#103). This script needs no action at all.
10+
#
11+
# Trust chain: the tarball is fetched from ziglang.org over HTTPS and must
12+
# match the sha256 pinned below, or the step fails. At pin time (2026-09-30)
13+
# the tarball's minisign signature was verified against the Zig Software
14+
# Foundation release key
15+
# RWSGOq2NVecA2UPNdBUZykf1CCb147pkmdtYxgb3Ti+JO/wCYvhbAb/U
16+
# (file signature and trusted-comment signature, timestamp:1760215991), and a
17+
# one-byte-altered digest was rejected as a negative control. The committed
18+
# sha256 carries that binding into CI.
19+
#
20+
# To bump: change ZIG_VERSION and ZIG_SHA256 together, taking the shasum from
21+
# https://ziglang.org/download/index.json and re-verifying the .minisig.
22+
#
23+
# Usage: bash scripts/install-zig.sh
24+
# Puts `zig` on PATH for subsequent steps via $GITHUB_PATH.
25+
26+
set -euo pipefail
27+
28+
ZIG_VERSION="0.15.2"
29+
ZIG_SHA256_X86_64_LINUX="02aa270f183da276e5b5920b1dac44a63f1a49e55050ebde3aecc9eb82f93239"
30+
31+
os="$(uname -s)"
32+
arch="$(uname -m)"
33+
if [ "$os" != "Linux" ] || [ "$arch" != "x86_64" ]; then
34+
echo "::error::install-zig.sh pins only x86_64-linux; got ${os}/${arch}. Add a pinned sha256 for this platform." >&2
35+
exit 1
36+
fi
37+
38+
tarball="zig-x86_64-linux-${ZIG_VERSION}.tar.xz"
39+
url="https://ziglang.org/download/${ZIG_VERSION}/${tarball}"
40+
41+
dest_root="${RUNNER_TEMP:?RUNNER_TEMP must be set (GitHub Actions)}"
42+
work="${dest_root}/zig-download"
43+
dest="${dest_root}/zig-${ZIG_VERSION}"
44+
mkdir -p "$work" "$dest"
45+
46+
curl --proto '=https' --tlsv1.2 -fsSL --retry 5 --retry-delay 5 \
47+
-o "${work}/${tarball}" "$url"
48+
49+
echo "${ZIG_SHA256_X86_64_LINUX} ${work}/${tarball}" | sha256sum -c -
50+
51+
tar -xJf "${work}/${tarball}" -C "$dest" --strip-components=1
52+
rm -rf "$work"
53+
54+
got="$("${dest}/zig" version)"
55+
if [ "$got" != "$ZIG_VERSION" ]; then
56+
echo "::error::installed zig reports '${got}', expected '${ZIG_VERSION}'" >&2
57+
exit 1
58+
fi
59+
60+
echo "$dest" >> "${GITHUB_PATH:?GITHUB_PATH must be set (GitHub Actions)}"
61+
echo "Installed zig ${got} at ${dest}"

0 commit comments

Comments
 (0)