Verify JDK downloads with vendor checksums (#1167)

* Verify JDK downloads with vendor checksums

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a800a031-600e-4d28-b23e-be309555d38d

* Handle missing vendor checksum values

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a800a031-600e-4d28-b23e-be309555d38d

* Preserve checksum error during cleanup failure

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a800a031-600e-4d28-b23e-be309555d38d

* Validate checksum metadata value types

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a800a031-600e-4d28-b23e-be309555d38d

* Clarify checksum documentation

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a800a031-600e-4d28-b23e-be309555d38d

* Expand vendor checksum verification

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a800a031-600e-4d28-b23e-be309555d38d

* Accept SHA-256 or SHA-512 for JetBrains checksum sibling

JetBrains publishes a single, generically-named ".checksum" sibling
whose digest algorithm isn't disclosed by the filename. Older JBR 11
builds (e.g. jbrsdk_nomod-11_0_16-*-b2043.64.tar.gz) publish a SHA-256
digest there, while newer builds publish SHA-512. The JetBrains
installer previously assumed SHA-512 unconditionally, so verification
failed with "Malformed sha512 checksum metadata ... expected a
128-character hexadecimal digest" for those older builds, breaking the
jetbrains 11 e2e job on macOS and Windows.

fetchChecksum now accepts a list of candidate algorithms and infers
the actual algorithm from the returned digest's length, preferring the
strongest match. The JetBrains installer passes ['sha512', 'sha256'];
all other callers are unaffected since they already pass a single,
vendor-disclosed algorithm.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a800a031-600e-4d28-b23e-be309555d38d

* Use SapMachine archive checksum files

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a800a031-600e-4d28-b23e-be309555d38d

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a800a031-600e-4d28-b23e-be309555d38d
This commit is contained in:
Bruno Borges
2026-07-29 04:43:56 -04:00
committed by GitHub
parent 19c23b379e
commit 27f2c62824
39 changed files with 1629 additions and 103 deletions
+15 -8
View File
@@ -19,6 +19,9 @@ import {
renameWinArchive
} from '../../util.js';
const KONA_RELEASES_URL =
'https://tencent.github.io/konajdk/releases/kona-v1.json';
export class KonaDistribution extends JavaBase {
constructor(installerOptions: JavaInstallerOptions) {
super('Kona', installerOptions);
@@ -30,7 +33,7 @@ export class KonaDistribution extends JavaBase {
core.info(
`Downloading Kona JDK ${javaRelease.version} (${this.distribution}) from ${javaRelease.url} ...`
);
const javaArchivePath = await tc.downloadTool(javaRelease.url);
const javaArchivePath = await this.downloadAndVerify(javaRelease);
core.info(`Extracting Java archive...`);
@@ -74,7 +77,14 @@ export class KonaDistribution extends JavaBase {
.map(item => {
return {
version: item.version,
url: item.downloadUrl
url: item.downloadUrl,
checksum: item.checksum
? {
algorithm: 'sha256',
value: item.checksum,
source: KONA_RELEASES_URL
}
: undefined
} as JavaDownloadRelease;
})
.sort((a, b) => -semver.compareBuild(a.version, b.version));
@@ -115,16 +125,13 @@ export class KonaDistribution extends JavaBase {
}
private async fetchReleaseInfo(): Promise<IKonaReleaseInfo | null> {
const releasesInfoUrl =
'https://tencent.github.io/konajdk/releases/kona-v1.json';
try {
core.debug(`Fetching Kona release info from URL: ${releasesInfoUrl}`);
return (await this.http.getJson<IKonaReleaseInfo>(releasesInfoUrl))
core.debug(`Fetching Kona release info from URL: ${KONA_RELEASES_URL}`);
return (await this.http.getJson<IKonaReleaseInfo>(KONA_RELEASES_URL))
.result;
} catch (err) {
core.debug(
`Fetching Kona release info from the URL: ${releasesInfoUrl} failed with the error: ${
`Fetching Kona release info from the URL: ${KONA_RELEASES_URL} failed with the error: ${
(err as Error).message
}`
);