Changelog
Notable Changes
No breaking change: the BREAKING CHANGE trailer of ad9f231 described a
rejection of DSA and ElGamal keys and of SHA-1 signatures that the verification
path never applies, since that policy belongs to the openpgp/v2 API and trdl
uses v1. Tags signed with such keys keep passing verification.
These do change behaviour, without breaking a working configuration:
onQuorumFailureandonCommandSkippedrun in the working directory trx was started in, not in the checkout, so that a hook reporting a failed verification cannot execute unverified repository content. A relative path such as./notify.shstops resolving inside the repository.- The operator
envoverrides the repository one, as the README documents, and env names coming from a repositorytrx.yamlare upper-cased. - An unknown template variable fails the run instead of being rendered as the literal
<no value>. - Checking out the target tag removes untracked files left in the clone.
--disable-lockskips locking outright, and an instance that loses the lock race fails instead of deploying concurrently.- A quorum that lists the same GPG key twice keeps loading, with a warning, but the duplicate no longer counts towards
minNumberOfKeys: such a quorum now fails verification throughonQuorumFailure.
Bug Fixes
- command: fail on an unknown template variable (f6b265e)
- command: render commands with text/template (4f4543b)
- command: signal the whole process group, keep hooks alive (11e8e8e)
- command: upper-case env names in one place, let the operator win (6c32151)
- config: keep accepting initial_last_published_git_commit (5b8f75a)
- git: bound clone and fetch, and repair a broken clone (7e9f572)
- git: clean the worktree when checking out the target tag (6101d8c)
- git: resolve an annotated tag to its commit (3ec414f)
- lock: skip locking with --disable-lock and fail on a lost race (#34) (418047c)
- print hook errors, name the right hooks, drop dead code (4256e98)
- quorum: do not panic on a quorum without a name (1dc7384)
- quorum: support EdDSA (Ed25519) GPG keys in signature verification (#12) (b32caf4)
- quorum: warn about a duplicate GPG key instead of refusing to start (f454712)
- report the locker and ssh key errors instead of ignoring them (6caa0b8)
- storage: write the state atomically (b39a881)
- the blocking findings of the main audit (#37) (c8c3cd9)
Tests
- quorum: cover a real two-signature quorum, generate the test key (ad9f231)
Miscellaneous Chores
- release the audit fixes as 1.1.0 (9b5d0bc)
Installation
Download trx binaries from here:
- Linux amd64 (PGP signature)
- Linux arm64 (PGP signature)
- macOS amd64 (PGP signature)
- macOS arm64 (PGP signature)
- Windows amd64 (PGP signature)
These binaries were signed with PGP and could be verified with this PGP public key.
For example, trx binary can be downloaded, verified with gpg and then installed to ~/bin/ on Linux with these commands:
curl -sSLO "https://tuf.trx.flant.com/targets/releases/1.1.0/linux-amd64/bin/trx" -O "https://tuf.trx.flant.com/targets/signatures/1.1.0/linux-amd64/bin/trx.sig"
curl -sSL https://raw.githubusercontent.com/flant/trx/refs/heads/main/trx.asc | gpg --import
gpg --verify trx.sig trx
install -D trx ~/bin/trx