ci: qualify Windows ARM64 engine artifacts - #10
Merged
Merged
Conversation
This was referenced Oct 5, 2026
steipete
marked this pull request as ready for review
October 5, 2026 10:40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Windows ARM64 Bun ships upstream, but the published OpenClaw WebKit matrix omits its non-LTO engine archive. Add the existing upstream
bun-webkit-windows-arm64lane as the tenth archive, without changing engine source, Dockerfiles, toolchain pins or upstream lane recipes relative to the qualified release tip641c15f9283845195dd3520dddc1fbd668379350.A native
windows-11-armjob verifies the archive/source receipt and ARM64 PE identity of both JSC and testFFI, then runs startup/DFG and FFI checks. Assembly binds this receipt to the exact archive hash, and publication authorization requires the native job alongside every existing build, Linux qualification and assembly gate. Missing or failed proof fails closed. The existing protected publication and immutability controls remain intact.Validation on head
e760c66892141e4028fd13b18bd2b0a242cf7be2:8b1a979c5ac866d8c927c3d7a0179b2002185f7dhas the same tree as the reviewed head:006761875cd6ed9d4d64e478b7ed144651d99c0f. Independent download verification matches the 367,107,253-byte CI archive's SHA-256dbe30b56af503584b2fc512c1669217bb8ef7daf4d155fb614387d219052b9b7and both PE architectures.The predecessor nine-archive publication completed immutable readback before this PR's landing. This PR does not publish a release or change repository settings. A separately authorized ten-archive publication and matching Bun checksum pin are required before openclaw/bun#128 can qualify its ARM64 release lane; CI artifact hashes must not be substituted for a published pin.
Upstream Bun cross-compiles Windows aarch64 from Debian ARM64 with clang-cl/lld-link and xwin, then tests on Windows 11 ARM64; bun-v1.4.2 publishes the target. This WebKit lane follows the existing Linux x64 Docker recipe. ARM64 deliberately stays non-LTO because LLVM CodeView cannot encode its LTO register tuples (oven-sh/bun#31345). No compiler workaround is introduced.