diff --git a/.github/workflows/debug-signing-secret.yml b/.github/workflows/debug-signing-secret.yml new file mode 100644 index 0000000..2f4ee32 --- /dev/null +++ b/.github/workflows/debug-signing-secret.yml @@ -0,0 +1,45 @@ +name: Debug Signing Secret + +on: + workflow_dispatch: + +jobs: + debug: + runs-on: ubuntu-latest-large + environment: deployment + steps: + - name: Inspect signing secrets (no key material printed) + env: + SIGNING_KEY_ID: ${{ secrets.SIGNING_KEY_ID }} + SIGNING_KEY_PASSWORD: ${{ secrets.SIGNING_KEY_PASSWORD }} + SIGNING_PRIVATE_KEY_BASE64: ${{ secrets.SIGNING_PRIVATE_KEY_BASE64 }} + run: | + echo "SIGNING_KEY_ID length: ${#SIGNING_KEY_ID}" + echo "SIGNING_KEY_PASSWORD length: ${#SIGNING_KEY_PASSWORD}" + echo "SIGNING_PRIVATE_KEY_BASE64 length: ${#SIGNING_PRIVATE_KEY_BASE64}" + + if [ -z "$SIGNING_PRIVATE_KEY_BASE64" ]; then + echo "RESULT: SIGNING_PRIVATE_KEY_BASE64 is empty or unset." + exit 0 + fi + + printf '%s' "$SIGNING_PRIVATE_KEY_BASE64" | base64 -d > /tmp/key.bin 2>/tmp/decode_err.txt + decode_status=$? + echo "base64 decode exit code: $decode_status" + if [ -s /tmp/decode_err.txt ]; then + echo "base64 decode stderr:" + cat /tmp/decode_err.txt + fi + + byte_count=$(wc -c < /tmp/key.bin | tr -d ' ') + echo "decoded byte count: $byte_count" + + first_bytes=$(head -c 11 /tmp/key.bin) + first_byte_hex=$(head -c 1 /tmp/key.bin | xxd -p) + echo "first byte (hex): $first_byte_hex" + + if [ "$first_bytes" = "-----BEGIN" ]; then + echo "RESULT: decoded content looks like an ASCII-armored PGP key block (starts with '-----BEGIN'). Gradle's signing.secretKeyRingFile expects a BINARY keyring, not armored text -- this is the likely cause." + else + echo "RESULT: decoded content does not start with '-----BEGIN'; does not look like armored ASCII. Could be a valid binary keyring or something else unexpected." + fi diff --git a/publishing-plugins/src/main/kotlin/mvn-publish.gradle.kts b/publishing-plugins/src/main/kotlin/mvn-publish.gradle.kts index 327a641..be1770a 100644 --- a/publishing-plugins/src/main/kotlin/mvn-publish.gradle.kts +++ b/publishing-plugins/src/main/kotlin/mvn-publish.gradle.kts @@ -16,6 +16,9 @@ ext["signing.secretKeyRingFile"] = null ext["ossrhUsername"] = null ext["ossrhPassword"] = null +// Set when signing via CI env vars; holds the ASCII-armored private key for useInMemoryPgpKeys +var ciSigningKey: String? = null + fun loadSecrets(secretPropsFile: File) { if (secretPropsFile.exists()) { secretPropsFile.reader().use { @@ -37,15 +40,9 @@ if (getExtraString("signing.keyId") == null) { val pgpKeyContent = System.getenv("SIGNING_PRIVATE_KEY_BASE64") if (pgpKeyContent != null) { - val tmpDir = File("${project.rootProject.rootDir}/tmp") - mkdir(tmpDir) - val keyFile = File("$tmpDir/key.pgp") - keyFile.createNewFile() - val os = keyFile.outputStream() - os.write(Base64.getDecoder().decode(pgpKeyContent)) - os.close() - - ext["signing.secretKeyRingFile"] = keyFile.absolutePath + // useInMemoryPgpKeys expects the ASCII-armored key text, not a binary keyring file, + // so decode straight to a string instead of writing out a secretKeyRingFile. + ciSigningKey = String(Base64.getDecoder().decode(pgpKeyContent)) } } @@ -113,6 +110,10 @@ afterEvaluate { } signing { + val signingKey = ciSigningKey + if (signingKey != null) { + useInMemoryPgpKeys(getExtraString("signing.keyId"), signingKey, getExtraString("signing.password")) + } sign(publishing.publications) } }