Repository navigation
ci: sign Windows releases and qualify ARM64 targets - #128
Merged
Merged
Conversation
|
Dependency limit exceeded — report not shown. This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report. Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard. Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account. |
This was referenced Oct 5, 2026
steipete
added a commit
to openclaw/WebKit
that referenced
this pull request
Oct 5, 2026
Windows ARM64 Bun ships upstream, but the published OpenClaw WebKit matrix omits its non-LTO engine archive. Add the existing upstream `bun-webkit-windows-arm64` lane as the tenth archive, without changing engine source, Dockerfiles, toolchain pins or upstream lane recipes relative to the qualified release tip `641c15f9283845195dd3520dddc1fbd668379350`. A native `windows-11-arm` job verifies the archive/source receipt and ARM64 PE identity of both JSC and testFFI, then runs startup/DFG and FFI checks. Assembly binds this receipt to the exact archive hash, and publication authorization requires the native job alongside every existing build, Linux qualification and assembly gate. Missing or failed proof fails closed. The existing protected publication and immutability controls remain intact. Validation on head `e760c66892141e4028fd13b18bd2b0a242cf7be2`: - All four checks pass in [37293130816](https://github.com/openclaw/WebKit/actions/runs/37293130816): Linux native qualification, Linux-hosted macOS fork artifact, Windows ARM64 build, and native Windows ARM64 qualification. - Native testFFI executes 1,509,848 checks with zero failures. JSC startup and DFG JIT pass. Both executables are verified ARM64, preventing an emulated x64 binary from satisfying the native gate. - CI merge source `8b1a979c5ac866d8c927c3d7a0179b2002185f7d` has the same tree as the reviewed head: `006761875cd6ed9d4d64e478b7ed144651d99c0f`. Independent download verification matches the 367,107,253-byte CI archive's SHA-256 `dbe30b56af503584b2fc512c1669217bb8ef7daf4d155fb614387d219052b9b7` and both PE architectures. - 25 publication-integrity tests, four JSC-result verifier tests, actionlint and whitespace checks pass. Local integration and final committed-branch P2 Codex autoreviews are scoped-clean. Incoming #9 engine/regression/qualification source is byte-identical to its released tip. The predecessor nine-archive publication completed immutable readback before this PR's landing. This PR does not publish a release or change repository settings. A separately authorized ten-archive publication and matching Bun checksum pin are required before openclaw/bun#128 can qualify its ARM64 release lane; CI artifact hashes must not be substituted for a published pin. Upstream Bun cross-compiles Windows aarch64 from Debian ARM64 with clang-cl/lld-link and xwin, then tests on Windows 11 ARM64; bun-v1.4.2 publishes the target. This WebKit lane follows the existing Linux x64 Docker recipe. ARM64 deliberately stays non-LTO because LLVM CodeView cannot encode its LTO register tuples (oven-sh/bun#31345). No compiler workaround is introduced.
steipete
marked this pull request as ready for review
October 5, 2026 19:04
steipete
added a commit
that referenced
this pull request
Oct 5, 2026
…113) Make ArrayBuffer and external-memory reporting reflect fresh allocations, transfer ownership, native storage and reclamation without counting backing stores as JavaScript heap. Classify allocation mode explicitly across the Rust/C++ boundary, preserve node:v8's wire envelope, and inspect busy or atomically waiting workers on their owning VM thread. Rebased after #128's fixed OpenClaw WebKit pin. Preserve all accounting assertions while removing fixture-owned references and separating setup compilation from measurements; stabilize native conversion output under backpressure. Builds on oven-sh#34406 and oven-sh/WebKit#303; thanks @robobun. Validation: scoped-clean P2 review; five-mode accounting matrices on macOS and Linux plus Node 24.21.0 controls; full N-API, worker and serializer regressions; OpenClaw worker-CPU consumers; plain selection with zero new regressions. Exact-head native CI: https://github.com/openclaw/bun/actions/runs/37366689402
steipete
added a commit
that referenced
this pull request
Oct 5, 2026
Publishing currently requires six targets, so missing Azure signing configuration blocks Darwin/Linux prereleases too. Make Windows publication an explicit, default-off repository opt-in while preserving the rule that unsigned Windows binaries are never published. The plan job captures `OPENCLAW_RELEASE_WINDOWS_SIGNED` once and enables it only for the literal value `true`. Planning and manifest assembly share the resulting target policy: four Darwin/Linux targets by default; all six targets, both Windows signature receipts and the existing signer/hash checks when enabled. An off-mode manifest rejects Windows archives, including orphan profile archives, before the workflow can upload them. PR and non-publishing dry runs retain all six default targets and both test-only Windows compatibility lanes. The release guide documents Azure setup and the federated credential subject `repo:openclaw/bun:environment:release-signing`. The manifest schema and consumer pins work with both shapes. This PR changes no repository variable, secret, environment, Azure resource or release tag. This is fork-specific release policy following #128; upstream search found no applicable release-switch fix. Validation on `326b7aa663a25d127413587b635ad05336fdb53d`: - Final Codex P2 review with ultrafast service: scoped-clean. Release tooling: 9 tests / 91 assertions; full source-lints: 202 tests / 515 assertions; actionlint, Prettier, JavaScript lint and build/CI-script typechecks pass. The actual Plan shell accepts only lowercase `true` among empty/false/true/True/TRUE/1. Baseline `695dda4942` rejects four-target publication; the candidate accepts both manifest shapes. - [Native fork run 37372144833](https://github.com/openclaw/bun/actions/runs/37372144833): Linux 16/16 and Darwin 12/12 result rows, with every selected file present, including release-tooling tests. Tested merge `b171816fa803c16a40aff154460b4b71df5a7041` has exactly the reviewed head's tree. Source and JavaScript lint CI also passed after infrastructure retries; format passed. - [Standard Windows dry run 37372159644](https://github.com/openclaw/bun/actions/runs/37372159644), first attempt, exact source/head: x64 and ARM64 each pass 31/31 result rows (29 selected files plus dependency checks), both native smokes and manifest assembly pass. Downloaded archive/executable/profile hashes, source and WebKit identity, PE architectures and test-only flags were independently verified. Publishing was disabled. - Unmodified OpenClaw pin projections handle both generated shapes; actual Tauri admission rejects missing Windows entries. Its unchanged staging/admission suite passes 22 tests, including absent/unsigned Windows, both signed architectures, identity and checksum failures. No OpenClaw source change is needed. CI context: GitHub Actions reported a major outage. The full PR release run's Plan job was cancelled twice without a runner or executed steps; those runs do not provide build evidence. The successful standard Windows run above provides the required Windows gates. A separately reviewed, non-landing qualification branch using existing Blacksmith Linux runners also passed both builds/smokes and x64 compatibility, but its ARM64 run hit the unchanged `fs.createReadStream` offset test's 100 ms callback deadline at 522 ms. That failed run is retained and is not the qualifying result. Runtime, test, harness, build, runner, selection and lockfile inputs are identical to `695dda4942`; no assertions, deadlines or test selection changed, and this PR does not claim to fix that timeout. The unrelated duplicate-PR bot failed before review because its credentials are not configured.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add Windows ARM64 alongside x64 in the fork release pipeline and pin the complete immutable ten-archive WebKit release. The engine includes repeated stack-coordinate caching, Windows ARM64, and the ARM64 allocation-accounting arithmetic correction. All 14 public files were independently downloaded and verified; the committed manifest matches the published bytes.
WEBKIT_VERSIONderives from it.Both Windows targets use upstream's Linux cross toolchain. ARM64 stays non-LTO for LLVM's CodeView limitation and is tested natively on
windows-11-arm; x64 useswindows-2025. Both share 29 compatibility files and two dependency-install rows, plus startup, full Bun/WebKit/CPU identity, SQLite and DFG checks.Publishing runs sign normal and profile executables for both Windows architectures through the OpenClaw Foundation Azure identity. The separate x64 signing job uses the protected
release-signingenvironment and job-scoped OIDC. Valid Authenticode status, the exact Foundation subject, timestamp and PE architecture are required before final ZIPs and hashes. Hash-bound receipts cover both normal and profile artifacts; manifests exposeauthenticodeSigned,signerSubjectandtestOnly. Missing signing fails a release closed. Non-release runs use a separate unsigned/test-only path.The first ARM64 run exposed a timezone-test assumption: deleting
TZrestored the host-default hour 4 instead of hardcoded UTC hour 12. The corrected fixture starts Node and Bun with the same TZ-free environment, chooses a distinct override, and preserves Date reuse, deletion and reset assertions. This changes no runtime semantics, skip or deadline.Validation is bound to head
5cb26403ad05bf4b23a6d5c386a2927c59b78d5f, tree7f0f5b1962c13ec2fa193905e763090bccf030f3. The PR CI merge26c1b0e8160513b4e6f6892cdf74d6607218d2a8has that same tree. Full scoped P2 review is clean.Consumer replay uses unchanged OpenClaw consumer source
d8916dcf74d44113988816264f6a94be223653f4, native Rust 1.97.1 on each architecture, and actual exact-head Windows ZIPs bound by manifest SHA-256a022d9cc622f50b1974b11f5e1af8e7d7ef17a2d035085d79da47cf22a1f85d0. Four tests overlap the materializer and Windows filters. There is no architecture outcome difference; the fs row reports x64 633 pass/103 skip and ARM64 634 pass/102 skip, both zero failures.Earlier source
0e6a7b354built and smoke-tested all six targets; x64 passed 31/31 and ARM64 failed only the now-corrected timezone fixture. Its Darwin lane failed the unchangedvm.ScriptRSS guard at 200.44/202.05 MiB versus<200. The current combined head passes that original guard on its first attempt; this is not a claim that the intermittent guard was fixed. Separate investigation remains in #131. The recurring deferred-idle compile-cache issue documented in.github/OPENCLAW_CI.mdis tracked separately in #130 and did not recur in this head's Windows selections. Mordant is explicitly advisory and reports the inherited bare-boolean warning in an unchanged resolver blob.Live Azure signing has not been exercised. Azure federation/environment setup and cutting the next prerelease remain release-owner tasks. This qualification creates no Bun tag or release and does not qualify the separate privileged GUI/S4U migration flow.