From 629dd8ec160dbf5607426712ac70a36afdaec6a6 Mon Sep 17 00:00:00 2001 From: Harshavardhana Date: Mon, 14 Sep 2026 15:06:34 -0700 Subject: [PATCH 1/2] ci: take the server from the aistor download path, which still serves MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Alpine, both Windows jobs and both macOS jobs fail on the same thing: the legacy community download path is gone. `dl.min.io/server/minio/release/...` answers 410 for the Windows binary, for the pinned Alpine release, and for the darwin-arm64 archive that `minio/stable/minio` resolves to, so three different install steps and one brew formula all fail to fetch a server. The Ubuntu jobs pass because they already pull from `dl.min.io/aistor/minio/release/...`, which serves 200 for linux, darwin-arm64 and windows-amd64 alike. The rest now do the same. macOS stops taking the server from brew, since that formula pins a withdrawn release, and fetches with curl rather than wget — a macOS runner has no wget unless something installs one. That binary wants a license, as the Ubuntu job's start step already shows, so the other three export MINIO_LICENSE the same way. Alpine keeps verifying what it downloaded. The published sum names the release archive rather than `minio`, so the digest is compared directly instead of handing the file to `sha256sum -c` whole. Dropping the pinned release is the point: a pin is what expires into a 410. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/ci.yml | 23 ++++++++++++++--------- 1 file changed, 14 insertions(+), 9 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 65001b1b..5f0542fd 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -128,16 +128,18 @@ jobs: - name: Install dependencies if macOS if: startsWith(matrix.config.os, 'macos') run: | - brew install pkg-config cmake minio/stable/minio + brew install pkg-config cmake + curl -fsSL -o minio https://dl.min.io/aistor/minio/release/darwin-arm64/minio + chmod +x minio cmake --version - minio --version + ./minio --version - name: Install dependencies if Windows shell: bash if: startsWith(matrix.config.os, 'windows') run: | choco install -y --no-progress cmake wget - wget --quiet https://dl.min.io/server/minio/release/windows-amd64/minio.exe + wget --quiet https://dl.min.io/aistor/minio/release/windows-amd64/minio.exe chmod +x minio.exe cmake --version @@ -164,7 +166,8 @@ jobs: - name: Start MinIO server if macOS if: startsWith(matrix.config.name, 'macos') run: | - MINIO_CI_CD=true minio server test-xl/{1...4}/ & + export MINIO_LICENSE=$(cat ./minio-cpp/.github/aistor-free-license.jwt) + MINIO_CI_CD=true ./minio server test-xl/{1...4}/ & sleep 10 - name: Start MinIO server if Windows @@ -174,6 +177,7 @@ jobs: mkdir -p ~/.minio/certs cp ./minio-cpp/tests/public.crt ./minio-cpp/tests/private.key ~/.minio/certs/ certutil -addstore -f "ROOT" ./minio-cpp/tests/public.crt + export MINIO_LICENSE=$(cat ./minio-cpp/.github/aistor-free-license.jwt) MINIO_CI_CD=true ./minio.exe server test-xl/{1...4}/ & sleep 10 @@ -219,13 +223,14 @@ jobs: cmake --build build - name: Start MinIO server run: | - MINIO_RELEASE=RELEASE.2025-09-07T16-13-09Z - wget --quiet https://dl.min.io/server/minio/release/linux-amd64/archive/minio.${MINIO_RELEASE} - wget --quiet https://dl.min.io/server/minio/release/linux-amd64/archive/minio.${MINIO_RELEASE}.sha256sum - sha256sum -c minio.${MINIO_RELEASE}.sha256sum - mv minio.${MINIO_RELEASE} minio + wget --quiet https://dl.min.io/aistor/minio/release/linux-amd64/minio + wget --quiet https://dl.min.io/aistor/minio/release/linux-amd64/minio.sha256sum + # The published sum names the release archive, not `minio`, so check the + # digest itself rather than feeding the file to `sha256sum -c` verbatim. + echo "$(cut -d' ' -f1 minio.sha256sum) minio" | sha256sum -c - chmod +x minio mkdir -p /data + export MINIO_LICENSE=$(cat .github/aistor-free-license.jwt) MINIO_CI_CD=true ./minio server /data --address 127.0.0.1:9000 & MINIO_PID=$! for i in $(seq 1 30); do From 08f2ab22421ca2440eee3d15aa150a7b1044a15f Mon Sep 17 00:00:00 2001 From: Harshavardhana Date: Mon, 14 Sep 2026 15:33:10 -0700 Subject: [PATCH 2/2] ci: pin the server CI runs, and verify it against a digest we keep Moving off the withdrawn download path took two integrity properties with it. macOS had been installing through the brew formula, which carries a sha256 in the tap -- a check from a different origin than the binary -- and a direct download dropped it. Alpine had pinned a release, an artifact whose bytes cannot change underneath it, and a mutable URL gave that up. Windows never checked anything. Nor was the pin what expired: the whole `server/` path went, not one release. The aistor path publishes the same immutable archives, for every platform CI builds on, so all four downloads now name a release rather than "latest". Verification reads the digest from `.github/minio-release.env` instead of fetching it beside the binary. A checksum served by the origin that serves the download attests to nothing about that origin; one committed here is something an attacker would have to change in a reviewed diff. Bumping means editing that file, where the digests moving is the visible part. Windows names its artifact minio.exe.RELEASE., and macOS has shasum rather than sha256sum. Co-Authored-By: Claude Opus 5 (1M context) --- .github/minio-release.env | 12 ++++++++++++ .github/workflows/ci.yml | 26 ++++++++++++++++++-------- 2 files changed, 30 insertions(+), 8 deletions(-) create mode 100644 .github/minio-release.env diff --git a/.github/minio-release.env b/.github/minio-release.env new file mode 100644 index 00000000..915d9a16 --- /dev/null +++ b/.github/minio-release.env @@ -0,0 +1,12 @@ +# The MinIO server CI runs its tests against, pinned by release and verified +# against a digest that lives here rather than being fetched beside the binary +# -- a checksum from the same origin as the download cannot attest to it. +# +# To bump: change MINIO_RELEASE, then replace each digest from +# https://dl.min.io/aistor/minio/release//archive/minio.$MINIO_RELEASE.sha256sum +# The digests changing is the point: they show up in review. +MINIO_RELEASE=RELEASE.2026-09-07T08-39-31Z +MINIO_SHA256_LINUX_AMD64=f62b67211cb8c19bb37aa5f318b8842987b261b7f0e985df61a5fe30707e7827 +MINIO_SHA256_LINUX_ARM64=8667dbae348167a71dd686177845c09bd033b4fbed155fa2bb5b2ad4f67e5644 +MINIO_SHA256_DARWIN_ARM64=5c7edd0bab341a94b18da4b24e76c1b5a9272f67d015a643d48fd0e3618c54a0 +MINIO_SHA256_WINDOWS_AMD64=393be601638a2ec57bc334400baadce8c27fdcb1e8c4f35e7c21a1fd121167fb diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5f0542fd..16474d5d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -120,7 +120,15 @@ jobs: - name: Install dependencies if Ubuntu if: startsWith(matrix.config.name, 'Ubuntu_Latest_GCC') run: | - wget --quiet https://dl.min.io/aistor/minio/release/linux-${{ matrix.config.arch }}/minio + . ./minio-cpp/.github/minio-release.env + arch=${{ matrix.config.arch }} + case "$arch" in + amd64) expected=$MINIO_SHA256_LINUX_AMD64 ;; + arm64) expected=$MINIO_SHA256_LINUX_ARM64 ;; + *) echo "no pinned digest for linux-$arch" >&2; exit 1 ;; + esac + wget --quiet -O minio "https://dl.min.io/aistor/minio/release/linux-${arch}/archive/minio.${MINIO_RELEASE}" + echo "${expected} minio" | sha256sum -c - chmod +x minio cmake --version ./minio --version @@ -129,7 +137,9 @@ jobs: if: startsWith(matrix.config.os, 'macos') run: | brew install pkg-config cmake - curl -fsSL -o minio https://dl.min.io/aistor/minio/release/darwin-arm64/minio + . ./minio-cpp/.github/minio-release.env + curl -fsSL -o minio "https://dl.min.io/aistor/minio/release/darwin-arm64/archive/minio.${MINIO_RELEASE}" + echo "${MINIO_SHA256_DARWIN_ARM64} minio" | shasum -a 256 -c - chmod +x minio cmake --version ./minio --version @@ -139,7 +149,9 @@ jobs: if: startsWith(matrix.config.os, 'windows') run: | choco install -y --no-progress cmake wget - wget --quiet https://dl.min.io/aistor/minio/release/windows-amd64/minio.exe + . ./minio-cpp/.github/minio-release.env + wget --quiet -O minio.exe "https://dl.min.io/aistor/minio/release/windows-amd64/archive/minio.exe.${MINIO_RELEASE}" + echo "${MINIO_SHA256_WINDOWS_AMD64} minio.exe" | sha256sum -c - chmod +x minio.exe cmake --version @@ -223,11 +235,9 @@ jobs: cmake --build build - name: Start MinIO server run: | - wget --quiet https://dl.min.io/aistor/minio/release/linux-amd64/minio - wget --quiet https://dl.min.io/aistor/minio/release/linux-amd64/minio.sha256sum - # The published sum names the release archive, not `minio`, so check the - # digest itself rather than feeding the file to `sha256sum -c` verbatim. - echo "$(cut -d' ' -f1 minio.sha256sum) minio" | sha256sum -c - + . .github/minio-release.env + wget --quiet -O minio "https://dl.min.io/aistor/minio/release/linux-amd64/archive/minio.${MINIO_RELEASE}" + echo "${MINIO_SHA256_LINUX_AMD64} minio" | sha256sum -c - chmod +x minio mkdir -p /data export MINIO_LICENSE=$(cat .github/aistor-free-license.jwt)