Reviewing a Log4cxx release

The review should confirm the uploaded source code is not corrupt and is identical to the package generated by the Github action. The steps below use version 2.0.0 as an example.

Prerequisites

  • A C++ compiler is available on your system
  • cmake, APR-Util and the GitHub CLI are installed on your system
  • GNU Privacy Guard is installed on your system

Additional Prerequisites (Windows only)

  • The PATH environment variable includes directories containing cmake.exe and gpg.exe
  • One of these environment variables is set (using / directory separators):
    • CMAKE_TOOLCHAIN_FILE - The full path to the vcpkg.cmake file (where APR-Util is installed)
    • CMAKE_INSTALL_PREFIX - The full path to the directory where EXPAT, APR and APR-Util libraries are installed (they can be built using these instructions)
  • If the programs zip.exe, gzip.exe and sed.exe are not in C:\msys64\usr\bin, the environment has a variable LOG4CXX_TEST_PROGRAM_PATH set to the full path (using / directory separators) containing those programs

Steps

  1. Save to your system a verification script from https://github.com/apache/logging-log4cxx/blob/master/admin
    • Linux, MacOS: validate-release.sh
    • Windows: validate-release.ps1
  2. Run the script that will download files, verify check-sums, verify signatures, check provenance, build and test
    • Linux, MacOS:
      • sh validate-release.sh 2.0.0
    • Windows:
      • .\validate-release.ps1 2.0.0
  3. For success, the final output line needs to include:
    • 100% tests passed, 0 tests failed out of ...