Skip to content

feat(ota): let publish-ota take baseline-tag latest and default the smoke's runtime version - #103

Merged
blink-admin merged 5 commits into
mainfrom
feat/ota-baseline-latest
Sep 28, 2026
Merged

blink-admin merged 5 commits into
mainfrom
feat/ota-baseline-latest

Conversation

@grimen

@grimen grimen commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

What and why

A hotfix caller has to find its own baseline. The template's cd-ota-hotfix.yml runs a job of inline shell that:

  • lists the releases to find the newest store build;
  • downloads its build-info.json;
  • reads fingerprint.ios out of it to pass as runtime-version.

publish-ota.yml downloads that same file itself, one step later. Every other caller also passes runtime-version, carried from build-prepare, and it is always the same value: the baseline's iOS fingerprint.

  • scripts/ota/baseline.sh: latest resolves to the newest published release that is neither a draft nor a pre-release (gh release list --exclude-drafts --exclude-pre-releases); the -build.N internal pre-releases never are. No such release, or a failed listing, is fatal.
  • scripts/ota/smoke.sh: with no OTA_RUNTIME_VERSION, it sends the platform's fingerprint from OTA_BASELINE_BUILD_INFO.
    • This is correct because the fingerprint gate has just proven this commit fingerprints the same, and that fingerprint is the runtime version the update is served under.
    • An explicit value still wins.
    • A baseline without that platform's fingerprint, or no file at all, sends no header, as before.
    • An unreadable file is fatal.
  • publish-ota.yml: hands the smoke step the baseline path, and both input descriptions say what empty and latest mean.

Not breaking. A caller passing runtime-version is unchanged. A caller that passed a manifest-url and no runtime-version used to send no runtime header, and now sends the fingerprint the update is actually served under.

How to verify

  • make check passes: exit 0.
  • test/baseline.bats, 3 new cases:
    • latest resolves, excludes drafts and pre-releases, and downloads from the resolved tag;
    • latest with no release is fatal and says to pass the tag, with no download;
    • a failed listing is fatal.
  • test/smoke.bats, 5 new cases:
    • the baseline's iOS fingerprint is sent when no version is given;
    • it follows OTA_SMOKE_PLATFORM;
    • an explicit version wins;
    • no fingerprint for the platform, or no baseline file, sends no header;
    • a baseline that is not JSON is fatal.
  • test/consumer-contract.bats: the guide's publish-ota.yml table still matches the inputs.

Docs

  • docs/consumer-guide.md:
    • the baseline-tag and runtime-version rows;
    • "The OTA fingerprint gate", on latest and the runtime default;
    • the release diagram's hotfix edge (baseline-tag latest), and the prose on callers that never prepare.
  • README.md: the test count.

The template's cd-ota-hotfix.yml loses its baseline job, and its other callers their runtime-version: lines, after it moves its pin to the release carrying this.

Checklist

  • PR title is a Conventional Commit with a valid scope
  • make check passes locally
  • Every behaviour this PR adds is tested here (test/baseline.bats, test/smoke.bats)
  • docs/consumer-guide.md updated: two inputs changed meaning
  • Every doc and diagram that shows the hotfix baseline is updated
  • Not breaking

…moke's runtime version

A hotfix caller had to find its own baseline: list the releases for the
newest store build, download its build-info.json, and read the iOS
fingerprint out of it for the smoke check. That is a job of inline shell
in every consumer, re-fetching a file publish-ota.yml downloads anyway.

- baseline.sh takes `latest`: the newest published release that is
  neither a draft nor a pre-release. None, or a failed listing, is fatal.
- smoke.sh, with no OTA_RUNTIME_VERSION, sends the platform's fingerprint
  from the baseline publish-ota.yml hands it. The fingerprint gate has
  just proven this commit fingerprints the same, and that fingerprint is
  the runtime version the update is served under. An explicit value
  still wins; a baseline without that fingerprint sends no header.

So every caller can drop its runtime-version, and a hotfix caller its
whole baseline job.
# Conflicts:
#	README.md
#	docs/consumer-guide.md
@blink-admin
blink-admin merged commit f20fe98 into main Sep 28, 2026
10 checks passed
@blink-admin
blink-admin deleted the feat/ota-baseline-latest branch September 28, 2026 09:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants