Repository navigation
ci(signing): harden SimplySign connection - #400
Merged
Merged
Conversation
- Preserve display and native library settings across signing steps. - Target visible windows and replace cached login fields. - Generate fresh OTPs before submission and wait for response dialogs. - Report PKCS#11 connection timeouts with their exit status.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What kind of change does this PR introduce?
CI signing reliability fix.
What is the new behavior?
The signing job shares its X display and native library path across login and package signing. Login automation targets visible windows, replaces cached field contents, generates the OTP immediately before entry with a rollover margin, and waits for a separate response dialog while preserving a visible original-window fallback. PKCS#11 connection failures report an explicit error and preserve the exit status.
What is the current behavior?
BuildDeploy run 37602834267 finds the SimplySign login window, then times out in the PKCS#11 probe with exit 124 before jsign runs. The original automation selects windows without checking visibility and assumes a response after a fixed delay. Display and library settings used for login do not persist to the signing step.
The logs establish the connection timeout, but do not establish the exact authentication or dialog failure.
Checklist
Additional information
Validation: actionlint 1.7.12, Bash syntax checks for all seven inline scripts, and git diff --check passed. Independent review identified and corrected a window-selection regression.
No .NET code changed, so no unit tests or documentation changes were added. Live signing with release-environment credentials remains unverified and needs CI confirmation.