Skip to content

Parallel artifact extraction corrupts APK payloads

scope: generic · severity: trap · confidence: proven · subsystem: ci

Symptom — A signed repository indexes packages successfully, but image installation reports unexpected end of file, v2 package format error, or file format is invalid or inconsistent for their payloads.

Observed — Both the Settings and Phosh jobs uploaded Settings APKs with the same filename. Each original artifact passed Alpine’s apk verify --allow-untrusted; the merged public asset had different bytes and failed. Six public Settings and libcamera APKs failed native verification. A gzip check alone missed the Settings package with one trailing zero byte.

Cause — download-artifact with merge-multiple: true extracted competing dependency builds into the same paths. Metadata indexing did not verify their complete payloads. Attesting the merged files faithfully described corrupt bytes rather than establishing installability.

What to do — Upload only packages whose origin matches the matrix job’s requested aport. Verify APK payloads before publishing, compare downloaded assets against upload bytes, and remove malformed retained candidates from the new index before deleting their assets. Valid older versions stay available.

Control — The ownership check executes the production branch with both a foreign dependency and the requested origin. Publisher checks reject a new invalid payload and remove a retained invalid candidate while keeping valid history. Native verification of the original artifact versus public asset separates a working build from a broken publication step.