Skip to content

fix(release): preserve stable binary immutability and manual publish opt-out - #373

Merged
masarray merged 3 commits into
mainfrom
fix/immutable-stable-publication
Sep 24, 2026
Merged

masarray merged 3 commits into
mainfrom
fix/immutable-stable-publication

Conversation

@masarray

Copy link
Copy Markdown
Owner

Problem

The canonical Windows publisher could replace existing stable assets using --clobber, and its publication step could run on manual main workflow dispatch even when publish_release=false. The older verified publisher had a second overwrite path.

Changes

  • Canonical publishing is allowed for release push/tag events or an explicitly opted-in manual run.
  • For an existing tag, verify its resolved source commit and download/compare SHA-256 of every published asset. Exact match is a no-op; any source/asset difference or missing asset fails closed. Never overwrite a published binary.
  • Skip regenerating public publication metadata after an exact existing-release no-op.
  • Older publisher refuses an existing stable tag instead of overwriting it.
  • Add regression tests for both workflows.

Release boundary

This is future-release infrastructure only. No application/engine/runtime/Discovery/Reporting changes, no manifest version bump, no v1.6.40 release mutation. v1.6.40 remains the accepted stable package.

Validation

Run source-clean and full PR CI. The publish workflow is not invoked by modifying its YAML; no release is created by this PR. Existing-tag behavior must remain fail-closed.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2d444c540b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".


- name: Record verified release publication
if: github.ref_type == 'tag' || github.ref == 'refs/heads/main' || inputs.publish_release == true
if: ((github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || (github.event_name == 'workflow_dispatch' && inputs.publish_release == true)) && env.RELEASE_ALREADY_PUBLISHED != 'true'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Recover missing publication evidence after a release no-op

If gh release create succeeds but the subsequent publication-record API request fails, rerunning the workflow takes the exact-match path, sets RELEASE_ALREADY_PUBLISHED, and this condition permanently suppresses the only step that can repair .release/published.json. Because .github/workflows/sync-release-evidence.yml:3-7 updates the public updater/site only when that file changes, the rerun can report success while public metadata remains stale or absent. Skip this step only after verifying that the existing record matches the release; otherwise recreate the missing evidence.

AGENTS.md reference: AGENTS.md:L58-L66

Useful? React with 👍 / 👎.

Comment on lines +474 to +475
$published = gh release view $env:RELEASE_TAG --repo $env:GITHUB_REPOSITORY --json assets | ConvertFrom-Json
if ($LASTEXITCODE -ne 0) { throw "Cannot inspect existing release assets." }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Validate release state before declaring an immutable no-op

When an existing release has matching assets and source but is still a draft or prerelease, this query requests only assets, so the workflow declares success without producing the stable/latest release promised by a main or stable-tag run. This can occur after an interrupted gh release create, whose help documents a draft → asset upload → publish sequence, or after a manual prerelease; gh release view --help exposes isDraft, isPrerelease, and publishedAt, so inspect those fields and reject or explicitly handle non-stable state before setting RELEASE_ALREADY_PUBLISHED.

AGENTS.md reference: AGENTS.md:L58-L66

Useful? React with 👍 / 👎.

@masarray
masarray merged commit 8165ec8 into main Sep 24, 2026
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant