Skip to content

ci: qualify Windows ARM64 engine artifacts - #10

Merged
steipete merged 2 commits into
openclaw/release-5718a6ecfrom
codex/w173-windows-arm64
Oct 5, 2026
Merged

steipete merged 2 commits into
openclaw/release-5718a6ecfrom
codex/w173-windows-arm64

Conversation

@steipete

@steipete steipete commented Oct 5, 2026 •

Copy link
Copy Markdown

Windows ARM64 Bun ships upstream, but the published OpenClaw WebKit matrix omits its non-LTO engine archive. Add the existing upstream bun-webkit-windows-arm64 lane as the tenth archive, without changing engine source, Dockerfiles, toolchain pins or upstream lane recipes relative to the qualified release tip 641c15f9283845195dd3520dddc1fbd668379350.

A native windows-11-arm job verifies the archive/source receipt and ARM64 PE identity of both JSC and testFFI, then runs startup/DFG and FFI checks. Assembly binds this receipt to the exact archive hash, and publication authorization requires the native job alongside every existing build, Linux qualification and assembly gate. Missing or failed proof fails closed. The existing protected publication and immutability controls remain intact.

Validation on head e760c66892141e4028fd13b18bd2b0a242cf7be2:

  • All four checks pass in 37293130816: Linux native qualification, Linux-hosted macOS fork artifact, Windows ARM64 build, and native Windows ARM64 qualification.
  • Native testFFI executes 1,509,848 checks with zero failures. JSC startup and DFG JIT pass. Both executables are verified ARM64, preventing an emulated x64 binary from satisfying the native gate.
  • CI merge source 8b1a979c5ac866d8c927c3d7a0179b2002185f7d has the same tree as the reviewed head: 006761875cd6ed9d4d64e478b7ed144651d99c0f. Independent download verification matches the 367,107,253-byte CI archive's SHA-256 dbe30b56af503584b2fc512c1669217bb8ef7daf4d155fb614387d219052b9b7 and both PE architectures.
  • 25 publication-integrity tests, four JSC-result verifier tests, actionlint and whitespace checks pass. Local integration and final committed-branch P2 Codex autoreviews are scoped-clean. Incoming perf(jsc): carry stack coordinate cache into rebased release #9 engine/regression/qualification source is byte-identical to its released tip.

The predecessor nine-archive publication completed immutable readback before this PR's landing. This PR does not publish a release or change repository settings. A separately authorized ten-archive publication and matching Bun checksum pin are required before openclaw/bun#128 can qualify its ARM64 release lane; CI artifact hashes must not be substituted for a published pin.

Upstream Bun cross-compiles Windows aarch64 from Debian ARM64 with clang-cl/lld-link and xwin, then tests on Windows 11 ARM64; bun-v1.4.2 publishes the target. This WebKit lane follows the existing Linux x64 Docker recipe. ARM64 deliberately stays non-LTO because LLVM CodeView cannot encode its LTO register tuples (oven-sh/bun#31345). No compiler workaround is introduced.

@steipete
steipete marked this pull request as ready for review October 5, 2026 10:40
@steipete
steipete merged commit c75925d into openclaw/release-5718a6ec Oct 5, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant