fix(release): preserve stable binary immutability and manual publish opt-out - #373
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2d444c540b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| - name: Record verified release publication | ||
| if: github.ref_type == 'tag' || github.ref == 'refs/heads/main' || inputs.publish_release == true | ||
| if: ((github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || (github.event_name == 'workflow_dispatch' && inputs.publish_release == true)) && env.RELEASE_ALREADY_PUBLISHED != 'true' |
There was a problem hiding this comment.
Recover missing publication evidence after a release no-op
If gh release create succeeds but the subsequent publication-record API request fails, rerunning the workflow takes the exact-match path, sets RELEASE_ALREADY_PUBLISHED, and this condition permanently suppresses the only step that can repair .release/published.json. Because .github/workflows/sync-release-evidence.yml:3-7 updates the public updater/site only when that file changes, the rerun can report success while public metadata remains stale or absent. Skip this step only after verifying that the existing record matches the release; otherwise recreate the missing evidence.
AGENTS.md reference: AGENTS.md:L58-L66
Useful? React with 👍 / 👎.
| $published = gh release view $env:RELEASE_TAG --repo $env:GITHUB_REPOSITORY --json assets | ConvertFrom-Json | ||
| if ($LASTEXITCODE -ne 0) { throw "Cannot inspect existing release assets." } |
There was a problem hiding this comment.
Validate release state before declaring an immutable no-op
When an existing release has matching assets and source but is still a draft or prerelease, this query requests only assets, so the workflow declares success without producing the stable/latest release promised by a main or stable-tag run. This can occur after an interrupted gh release create, whose help documents a draft → asset upload → publish sequence, or after a manual prerelease; gh release view --help exposes isDraft, isPrerelease, and publishedAt, so inspect those fields and reject or explicitly handle non-stable state before setting RELEASE_ALREADY_PUBLISHED.
AGENTS.md reference: AGENTS.md:L58-L66
Useful? React with 👍 / 👎.
Problem
The canonical Windows publisher could replace existing stable assets using
--clobber, and its publication step could run on manualmainworkflow dispatch even whenpublish_release=false. The older verified publisher had a second overwrite path.Changes
Release boundary
This is future-release infrastructure only. No application/engine/runtime/Discovery/Reporting changes, no manifest version bump, no v1.6.40 release mutation.
v1.6.40remains the accepted stable package.Validation
Run source-clean and full PR CI. The publish workflow is not invoked by modifying its YAML; no release is created by this PR. Existing-tag behavior must remain fail-closed.