[PostGIS] #6115: Release staging can overwrite /stuff tarballs under released names
PostGIS
trac at osgeo.org
Mon Aug 17 10:01:04 PDT 2026
#6115: Release staging can overwrite /stuff tarballs under released names
-------------------------+-------------------------------------------------
Reporter: komzpa | Owner: robe
Type: defect | Status: new
Priority: high | Milestone: Website Management, Bots
Component: | Version: 3.5.x
QA/buildbots | Keywords: release tarball checksum md5 debbie
Resolution: | buildbot
-------------------------+-------------------------------------------------
Old description:
> The release staging area can publish tarballs under an already-released
> name when a release branch is built after the release tag but before the
> branch version is bumped to the next dev version.
>
> Observed case:
>
> * `https://download.osgeo.org/postgis/source/postgis-3.5.7.tar.gz`
> * size: `14975173`
> * md5: `480b8a90e32cb1ce6f2852f73aa9e835`
> * sha256:
> `af9ab591854d52a0d1115f90b797ef1cd60d01b85a11ff813073689e332272ff`
> * HTTP Last-Modified: `2026-06-10 19:15:43 GMT`
> * extracted tracked files match tag `3.5.7`, commit
> `9816f82458db774e62906cfb2c4f01f8b262c862`
>
> * `https://postgis.net/stuff/postgis-3.5.7.tar.gz`
> * size: `14989106`
> * md5: `26788e82bb74e83d2b441d647d6f0100`
> * sha256:
> `20801761cf4a4c6a84abb00dde4bbe8f435ab2a037ea8bb2a4f0ce771a73323c`
> * HTTP Last-Modified: `2026-06-30 21:25:45 GMT`
> * extracted tracked files match stable-3.5 commit
> `b775c99ddeeecd32fe68a23cc95963c59c81029d`, not tag `3.5.7`
>
> The later archive still has `POSTGIS_MICRO_VERSION=7` in
> `Version.config`, but its `NEWS` already contains post-release
> hardening/backpatch entries such as OSSFuzz fixes, address_standardizer
> and tiger_geocoder hardening, `#6081`, `GH-888`, `GH-889`, `GH-890`,
> `GH-894`, `GH-895`, `GH-897`, and `GH-898`.
>
> Likely mechanism:
>
> * `ci/debbie/postgis_make_dist.sh` derives `newoutdir` from
> `Version.config`.
> * It then calls `sh make_dist.sh` without an explicit release tag.
> * `make_dist.sh` defaults to `git rev-parse HEAD`.
> * If the Debbie job is run on `stable-3.5` after tag `3.5.7` but before
> `Version.config` is bumped to `3.5.8dev`, the generated file is named
> `postgis-3.5.7.tar.gz` while containing a post-release stable-3.5
> snapshot.
>
> The 3.5 branch was only bumped to `3.5.8dev` by commit
> `aadeecfb513034ce713c51285286d6989096b3d2` on `2026-07-06`, while the
> `/stuff` archive content matches `b775c99d` from `2026-06-30`, so it
> falls exactly into that window.
>
> For comparison, `postgis-3.4.6.tar.gz` and `postgis-3.3.10.tar.gz` differ
> between `download.osgeo.org` and `/stuff` only at the tar/gzip stream
> level: extracted file hashes and file sizes/modes match. Those look like
> repacks, not different source snapshots.
>
> Suggested fixes:
>
> * Make the release/staging job refuse to write `postgis-X.Y.Z.tar.gz`
> unless `HEAD` is exactly tag `X.Y.Z`, or pass the intended tag explicitly
> to `make_dist.sh`.
> * After a release is copied to `download.osgeo.org`, treat
> `postgis.net/stuff/postgis-X.Y.Z.tar.gz` as immutable or remove it from
> active release checksum/source paths.
> * Replace or remove the stale `/stuff/postgis-3.5.7.tar.gz` and `.md5` so
> users do not see a post-release snapshot under the released `3.5.7` name.
>
> Related website mitigation:
> https://gitea.osgeo.org/postgis/postgis.net/pulls/32 changes active
> release checksum links/checks to use the same `download.osgeo.org` source
> as the tarball.
New description:
The release staging area can publish tarballs under an already-released
name when a release branch is built after the release tag but before the
branch version is bumped to the next dev version.
Observed case:
* `https://download.osgeo.org/postgis/source/postgis-3.5.7.tar.gz`
* size: `14975173`
* md5: `480b8a90e32cb1ce6f2852f73aa9e835`
* sha256:
`af9ab591854d52a0d1115f90b797ef1cd60d01b85a11ff813073689e332272ff`
* HTTP Last-Modified: `2026-06-10 19:15:43 GMT`
* extracted tracked files match tag `3.5.7`, commit
`9816f82458db774e62906cfb2c4f01f8b262c862`
* `https://postgis.net/stuff/postgis-3.5.7.tar.gz`
* size: `14989106`
* md5: `26788e82bb74e83d2b441d647d6f0100`
* sha256:
`20801761cf4a4c6a84abb00dde4bbe8f435ab2a037ea8bb2a4f0ce771a73323c`
* HTTP Last-Modified: `2026-06-30 21:25:45 GMT`
* extracted tracked files match stable-3.5 commit
`b775c99ddeeecd32fe68a23cc95963c59c81029d`, not tag `3.5.7`
The later archive still has `POSTGIS_MICRO_VERSION=7` in `Version.config`,
but its `NEWS` already contains post-release hardening/backpatch entries
such as OSSFuzz fixes, address_standardizer and tiger_geocoder hardening,
`#6081`, `GH-888`, `GH-889`, `GH-890`, `GH-894`, `GH-895`, `GH-897`, and
`GH-898`.
Likely mechanism:
* `ci/debbie/postgis_make_dist.sh` derives `newoutdir` from
`Version.config`.
* It then calls `sh make_dist.sh` without an explicit release tag.
* `make_dist.sh` defaults to `git rev-parse HEAD`.
* If the Debbie job is run on `stable-3.5` after tag `3.5.7` but before
`Version.config` is bumped to `3.5.8dev`, the generated file is named
`postgis-3.5.7.tar.gz` while containing a post-release stable-3.5
snapshot.
The 3.5 branch was only bumped to `3.5.8dev` by commit
`aadeecfb513034ce713c51285286d6989096b3d2` on `2026-07-06`, while the
`/stuff` archive content matches `b775c99d` from `2026-06-30`, so it falls
exactly into that window.
For comparison, `postgis-3.4.6.tar.gz` and `postgis-3.3.10.tar.gz` differ
between `download.osgeo.org` and `/stuff` only at the tar/gzip stream
level: extracted file hashes and file sizes/modes match. Those look like
repacks, not different source snapshots.
Suggested fixes:
* Make the release/staging job refuse to write `postgis-X.Y.Z.tar.gz`
unless `HEAD` is exactly tag `X.Y.Z`, or pass the intended tag explicitly
to `make_dist.sh`.
* After a release is copied to `download.osgeo.org`, treat
`postgis.net/stuff/postgis-X.Y.Z.tar.gz` as immutable or remove it from
active release checksum/source paths.
* Replace or remove the stale `/stuff/postgis-3.5.7.tar.gz` and `.md5` so
users do not see a post-release snapshot under the released `3.5.7` name.
Related website mitigation:
https://gitea.osgeo.org/postgis/postgis.net/pulls/32 changes active
release checksum links/checks to use the same `download.osgeo.org` source
as the tarball.
--
Comment (by robe):
I guess we can just change this to always have the .md5 published on
download and make that the official one. having it on separate servers
just seems to be causing issues.
--
Ticket URL: <https://trac.osgeo.org/postgis/ticket/6115#comment:2>
PostGIS <http://trac.osgeo.org/postgis/>
The PostGIS Trac is used for bug, enhancement & task tracking, a user and developer wiki, and a view into the subversion code repository of PostGIS project.
More information about the postgis-tickets
mailing list