Download page builds SHA-512/signature links from artifact-root instead of checksum-root
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 75/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- css, html, jekyll
- 領域
- documentation, web-dev
調査の方向性
この issue は download.md ファイルの 51-52 行目にあります。まず、リポジトリの _releases/ ディレクトリを探し、リリースデータの構造を理解します(checksum-root と artifact-root を探します)。テンプレートを修正して、SHA-512 と署名リンクの href に release.checksum-root を使用するようにします。Jekyll サイトをローカルでビルドし、生成されたリンクが downloads.apache.org を指し、HTML ではなくプレーンテキスト/署名ファイルを返すことを確認してテストします。
索引モデルが issue の本文から書いたものです。
説明
The SHA-512 and Signature columns on the download page link to the mirror selector rather than the canonical distribution host, so they return an HTML mirror-selection page instead of the file.
Reproduction
on https://nuttx.apache.org/download/, click any current release's SHA-512 link (e.g. 13.0.1). curl shows the difference:
Generated: https://www.apache.org/dyn/closer.lua/nuttx/12.12.0/apache-nuttx-12.12.0.tar.gz.sha512 → 200 text/html, ~21 KB mirror-picker page
Canonical: https://downloads.apache.org/nuttx/12.12.0/apache-nuttx-12.12.0.tar.gz.sha512 → 200 text/plain, 158 bytes (the hash)
Same for .asc: the generated URL returns the ~21 KB HTML page; the downloads.apache.org URL returns the 833-byte PGP signature.
Root cause:
download.md:51-52 builds the .sha512/.asc hrefs from release.artifact-root. Every release file defines checksum-root (and key-file) for exactly this purpose — present since the first Apache release file (be0ee1f, 9.0.0, May 2020) — but no template reads them; the same commit wired the columns to artifact-root instead. A repo-wide grep confirms checksum-root/key-file are write-only (only other hit is the dormant generator helpers/syncbbrelease.py).
Scope:
affects all mirror-served Apache releases (9.1.1, 10.0.1, 10.1.0–13.0.1). Archive rows (9.0.0, 9.1.0, 10.0.0) have checksum-root == artifact-root, so they are unaffected and need no special handling. The page text itself (download.md:68-69) already states hashes/signatures are hosted at Apache, and the closer.lua page advises fetching signatures from the main distribution site rather than a mirror.
Proposed fix (scoped to download.md:51-52 only): build the SHA-512 and Signature hrefs from release.checksum-root, leaving the Archive column on artifact-root. Suggested regression check: assert built SHA/ASC hrefs start with each release's checksum-root and return non-HTML 200s.
- 主要言語
- CSS
- スター
- 24
- フォーク
- 37
- 平均マージ
- 1時間 39分
- マージ済み PR(30日)
- 1
環境構築
このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
apache/nuttx-website のほかの issue
-
[www/doc] split ci job for website update and documentation update.再び着手できるかも @cederom が 76 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンdocumentation enhancement
apache/nuttx-website#180 · 担当者 1 名 ·
-
難易度 2/5 1時間未満 初心者へのやさしさ 35/100
apache/nuttx-website#130 · コメント 5 件 · リアクション 2 件 ·
-
[WWW/DOC] NuttX RTOS Website and Documentation再び着手できるかも @cederom が 605 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンdocumentation
apache/nuttx-website#129 · 担当者 1 名 ·
-
[WWW/DOC] CI: build only parts that changed.再び着手できるかも @cederom が 734 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンdocumentation enhancement
apache/nuttx-website#124 · 担当者 1 名 ·
apache/nuttx-website の issue をすべて見る
似ている issue
-
sync-en
難易度 1/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
ACK_WAITING HELP_WANTED UPDATE_CS
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
OWASP/CheatSheetSeries#2458 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
l3montree-dev/devguard#3101 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 90/100
メンテナーはふだん 1 日以内に返信
-
area/documentation status/need-triage
難易度 1/5 1時間未満 初心者へのやさしさ 95/100
google-gemini/gemini-cli#29548 ·
メンテナーはふだん 1 日以内に返信