diff --git a/.github/OPENCLAW_RELEASE.md b/.github/OPENCLAW_RELEASE.md index 43a17b544efd..442570035006 100644 --- a/.github/OPENCLAW_RELEASE.md +++ b/.github/OPENCLAW_RELEASE.md @@ -124,14 +124,18 @@ attestation](https://docs.github.com/en/actions/security-for-github-actions/usin A packager pins the zip's `sha256` for the download and `executable.sha256` for what it embeds or runs, as `openclaw`'s `setup-test-bun` action already does for the CI build. `libc` (`glibc`/`musl`) is present on Linux entries, -`signing` on darwin ones. - -| Target | Minimum | Smoke-tested on | -| -------------- | ---------------------------------------- | ------------------ | -| `darwin-arm64` | macOS 13.0 | `macos-15` | -| `darwin-x64` | macOS 13.0, x86-64 with SSE4.2 | `macos-15-intel` | -| `linux-x64` | glibc 2.17, x86-64 with SSE4.2 (Nehalem) | `ubuntu-24.04` | -| `linux-arm64` | glibc 2.17, ARMv8.0-A | `ubuntu-24.04-arm` | +`signing` on darwin ones. Windows executable records carry +`authenticodeSigned`, `signerSubject` (signed builds only), and `testOnly`. Both executable and archive +hashes describe the final signed bytes; unsigned dry-run inputs are test-only. + +| Target | Minimum | Smoke-tested on | +| --------------- | ---------------------------------------- | ------------------ | +| `darwin-arm64` | macOS 13.0 | `macos-15` | +| `darwin-x64` | macOS 13.0, x86-64 with SSE4.2 | `macos-15-intel` | +| `linux-x64` | glibc 2.17, x86-64 with SSE4.2 (Nehalem) | `ubuntu-24.04` | +| `linux-arm64` | glibc 2.17, ARMv8.0-A | `ubuntu-24.04-arm` | +| `windows-x64` | Windows 10 1809 | `windows-2025` | +| `windows-arm64` | Windows 11 ARM64 | `windows-11-arm` | The glibc floor is the symbol-version ceiling the build's binary check enforces (`scripts/build/binary-expectations.ts`); libstdc++ is linked statically. x64 @@ -159,7 +163,10 @@ one of those sections. The build is `scripts/build.ts --profile=release --ci=on` with the target's `--os/--arch/--abi`: ThinLTO across Bun, Rust and the `-lto` WebKit prebuilt, -path remapping, and the binary checks as errors. It links without upstream's +path remapping, and the binary checks as errors. Windows ARM64 uses upstream’s +non-LTO release configuration and `bun-webkit-windows-arm64.tar.gz`; LLVM’s +CodeView emitter cannot encode the ARM64 register tuples used by LTO +([oven-sh/bun#31345](https://github.com/oven-sh/bun/issues/31345)). It links without upstream's symbol order file (Buildkite publishes that) and without PGO. The version string keeps upstream's canary suffix (`1.4.3-canary.1+`): these are not upstream releases. @@ -228,34 +235,52 @@ the Docker image is Debian-based. The executable needs `libstdc++` and `libgcc` from the distribution, like upstream's. Adding it to every release costs two more build jobs. -**windows-x64** also builds from the same image (xwin's MSVC CRT and Windows -SDK, `lld-link`); a dispatch builds and smoke-tests it on `windows-2025`. A -release target additionally needs Authenticode signing, which upstream does -with DigiCert KeyLocker on a Windows agent: a certificate (a cloud-HSM-backed -OV certificate, or Azure Trusted Signing) and a signing job on a Windows -runner. Unsigned executables meet SmartScreen warnings and antivirus false -positives. The Tauri app's Windows runtime install is still a stub. +## Windows signing and qualification + +Windows x64 and ARM64 are release targets. Both cross-compile on the same Debian +ARM64 image using clang-cl, lld-link and xwin's MSVC/Windows SDK. Windows ARM64 +uses the existing upstream non-LTO lane. Native smoke tests verify source and +engine identity, architecture, SQLite and DFG JIT startup. Both architectures run +the same 29-file Windows compatibility selection and its dependency checks. + +Only a publishing run enters the `release-signing` environment and grants the +signing job `id-token: write`. `azure/login` uses the environment secrets +`AZURE_CLIENT_ID`, `AZURE_TENANT_ID` and `AZURE_SUBSCRIPTION_ID` for OIDC. +`azure/artifact-signing-action@v2` uses endpoint +`https://eus.codesigning.azure.net/`, signing account `openclaw` and certificate +profile `openclaw`, with SHA-256 file and RFC3161 timestamp digests. The job runs +on x64 because the signing library does not support an ARM64 host. + +Both stripped and profile executables must have a valid Authenticode signature, +a timestamp certificate and the exact subject +`CN=OpenClaw Foundation, O=OpenClaw Foundation, L=Mill Valley, S=California, C=US`. +Verification precedes packaging and hashing. Manifest assembly binds the signed +receipt to both archives and executables. Missing Azure configuration, failed +signing, an unexpected subject or changed bytes fail the release; there is no +unsigned release fallback. + +PRs and non-publishing dispatches use a separate job without signing credentials +or OIDC permission. Their Windows artifact is named `test-only-windows` and its +manifest records `authenticodeSigned: false` and `testOnly: true`. Production +consumers must reject it. Signing proves the publisher; SmartScreen reputation is +independent of that signature. ## WebKit -Releases link the oven-sh/WebKit prebuilt that `WEBKIT_VERSION` pins, the same -one upstream Bun ships. The pipeline builds no WebKit. A JavaScriptCore fix -reaches a release in one of three ways: - -1. It lands in oven-sh/WebKit `main`: pin its `autobuild-` (upstream Bun - usually does within days, and an upstream sync brings the pin along). -2. It is an open oven-sh/WebKit pull request from a branch of that repository: - its `autobuild-preview-pr--` prebuilt can be pinned. A preview is - built on the pull request's base, which can be weeks behind `main`. -3. Neither: the fork needs its own WebKit prebuilts (see decisions below). - -The pinned WebKit `f20ce7744553c910bcf16a33faf976af208de091` contains the -upstream replacement for oven-sh/WebKit#578, which is now closed. String -indexing lowers its bounds check to a separate `CheckInBounds` node, so -dead-code elimination preserves the check even when the access result is -unused. The pin includes `JSTests/stress/string-index-dce-bounds-check.js`. -This fixes the FTL CSS-tokenizer defect that previously required OpenClaw's -custom WebKit build; this fork no longer needs that backport. +Releases link the OpenClaw WebKit archives committed in +`scripts/build/deps/webkit-artifacts.json`. The full engine commit and each +archive URL/SHA-256 move together. Missing variants fail closed; the build never +falls back to an upstream archive with a different engine ABI. + +The separate [OpenClaw WebKit pipeline](https://github.com/openclaw/WebKit) +builds, qualifies and publishes immutable engine releases. The current +[ten-archive release](https://github.com/openclaw/WebKit/releases/tag/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661) +includes the non-LTO `bun-webkit-windows-arm64.tar.gz` archive, cached repeated +stack coordinates and corrected ARM64 allocation-accounting arithmetic. +Qualify and publish each complete matrix before adding its checksums to Bun. +A workflow artifact is test input, not a published release pin. +Bun must rebuild against the exact matching headers and libraries whenever the +engine pin changes. ## Upstream sync and security patches @@ -266,21 +291,18 @@ qualify a sync PR's release build, dispatch this workflow on target as a dry run. - **Routine:** land one upstream sync a week, then tag `main` once the fork's - own CI is green. The weekly release brings upstream's WebKit bumps along - (57 between July and September 2026, several a week lately); the fork does - not bump WebKit on its own. OpenClaw moves its pins in its own pull requests, - against its own CI. + own CI is green. Coordinate WebKit changes with a separately qualified + OpenClaw WebKit publication and its matching Bun adapters. OpenClaw moves its + runtime pins in its own pull requests, against its own CI. - **Bun security fix upstream:** within one working day for high or critical issues. When the pending sync is otherwise ready, land it and release; otherwise cherry-pick the fix onto `main` in a pull request titled after the upstream one (`fix(security): backport oven-sh/bun#`), then release. The next sync merges the upstream commit without conflict. -- **JavaScriptCore security fix:** once upstream Bun pins a WebKit containing - it, sync or cherry-pick that pin bump (with the bindings changes it came - with). If only oven-sh/WebKit has it, pin its `autobuild-` in a fork - pull request and qualify with a dry run: pins are not ABI-stable, so a bump - that needs bindings changes waits for upstream's. A fix only in WebKit - proper, not in oven-sh/WebKit, needs route 3 above. +- **JavaScriptCore security fix:** carry the fix into OpenClaw WebKit, qualify + and publish an immutable engine release, then update Bun's complete checksum + manifest with any required binding changes. Engine pins are not ABI-stable; + a matching rebuild and native qualification are required. - **Vendored dependencies** (BoringSSL, c-ares, libuv, zlib, SQLite, …): the `update-*` workflows only run in `oven-sh/bun`; the fork gets those updates through syncs, or by cherry-picking the upstream update commit. @@ -301,11 +323,9 @@ target as a dry run. (c) stay as linked: the Mac app re-signs, and the Tauri app's own downloads carry no quarantine attribute, but anything downloaded by a browser is refused by Gatekeeper. Recommended: (a). -2. **Whether the fork builds its own WebKit.** Continue using oven-sh/WebKit - prebuilts: the pinned engine contains the upstream replacement for #578. - A future fix unavailable in an upstream prebuilt would require separate - WebKit build lanes and an explicit prebuilt repository setting in - `webkit.ts` before a fork-specific engine could be released. +2. **WebKit publication.** Engine releases are owned by the separate OpenClaw + WebKit pipeline. Bun consumes only its committed checksum manifest; adding a + platform requires a qualified, published matching engine archive first. 3. **Build runner.** Recommended: keep GitHub's free runners. Change `vars.OPENCLAW_RELEASE_BUILD_RUNNER` only if release latency matters. 4. **Release visibility.** Releases are prereleases and never "latest" until @@ -313,8 +333,8 @@ target as a dry run. 5. **Tag protection.** A ruleset on `openclaw-v*` tags (creation by maintainers, no updates or deletions) keeps a published release's tag from moving. The publish job refuses a moved tag, but only while it runs. -6. **musl and Windows.** musl is left out of releases until a consumer needs - it; windows-x64 waits for an Authenticode certificate. +6. **musl.** musl is left out of releases until a consumer needs it. Windows + releases require the Foundation Authenticode identity described above. 7. **Cadence.** Weekly releases after the upstream sync; security fixes within a working day (above). 8. **A cached builder image.** Provisioning downloads from a dozen hosts on diff --git a/.github/UPSTREAM_SYNC.md b/.github/UPSTREAM_SYNC.md index aeb923e38188..10b0a5dc65f4 100644 --- a/.github/UPSTREAM_SYNC.md +++ b/.github/UPSTREAM_SYNC.md @@ -96,11 +96,15 @@ release target as a dry run; the release cadence and security-patch policy are i The sync through upstream Bun `9bd19c98eacc01530a4e7609bc427abffa87d77e` targets upstream WebKit `5718a6ec579b98362ea7276a426deedcc6281ef5`. The fork consumes immutable OpenClaw WebKit -[`42ab38d705d4838748ccee77e7deb0e4e35515ee`](https://github.com/openclaw/WebKit/releases/tag/autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee) +[`f1e1ca1156c8cb3b468bec0e1989fbfa08899661`](https://github.com/openclaw/WebKit/releases/tag/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661) through the complete published manifest in `scripts/build/deps/webkit-artifacts.json`. Every archive is verified before extraction, with no upstream-artifact fallback. +The ten-archive manifest includes the non-LTO Windows ARM64 build, cached +repeated stack coordinates, and the ARM64 register-to-memory addition fix used +by typed-array allocation accounting. + This engine provides upstream's idle compiler-thread and `Atomics.wait` memory release. Its namespace facade API also requires the paired Bun integration from [#106](https://github.com/openclaw/bun/pull/106): import namespaces remain diff --git a/.github/workflows/openclaw-release.yml b/.github/workflows/openclaw-release.yml index aab70b7d49e0..8a913ac45a6d 100644 --- a/.github/workflows/openclaw-release.yml +++ b/.github/workflows/openclaw-release.yml @@ -22,7 +22,7 @@ on: type: boolean default: false targets: - description: "Comma-separated targets; empty = the release targets. Also: linux-x64-musl, linux-arm64-musl, windows-x64" + description: "Comma-separated targets; empty = six release targets. Also: linux-x64-musl, linux-arm64-musl" type: string default: "" @@ -49,6 +49,9 @@ jobs: publish: ${{ steps.plan.outputs.publish }} matrix: ${{ steps.plan.outputs.matrix }} darwin: ${{ steps.plan.outputs.darwin }} + windows: ${{ steps.plan.outputs.windows }} + windows-matrix: ${{ steps.plan.outputs.windows-matrix }} + mtime: ${{ steps.plan.outputs.mtime }} steps: - name: Checkout pipeline uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -159,7 +162,7 @@ jobs: - name: Upload uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: - name: build-${{ matrix.target }} + name: ${{ startsWith(matrix.target, 'windows-') && format('test-only-input-{0}', matrix.target) || format('build-{0}', matrix.target) }} path: dist/ if-no-files-found: error retention-days: 14 @@ -259,10 +262,95 @@ jobs: retention-days: 14 compression-level: 0 + sign-windows: + name: Sign Windows releases + needs: [plan, build] + if: github.event_name != 'pull_request' && (github.event_name == 'push' || inputs.publish == true) && needs.plan.outputs.windows == 'true' && needs.plan.outputs.publish == 'true' + # The signing dlib requires x64 even when the executable being signed is ARM64. + runs-on: windows-2025 + timeout-minutes: 30 + environment: release-signing + permissions: + contents: read + id-token: write + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + sparse-checkout: scripts/openclaw-release + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + pattern: test-only-input-windows-* + merge-multiple: true + path: dist + - name: Azure OIDC login + uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3 + with: + client-id: ${{ secrets.AZURE_CLIENT_ID }} + tenant-id: ${{ secrets.AZURE_TENANT_ID }} + subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }} + - name: Sign both Windows architectures and profile executables + uses: azure/artifact-signing-action@c7ab2a863ab5f9a846ddb8265964877ef296ee82 # v2 + with: + endpoint: https://eus.codesigning.azure.net/ + signing-account-name: openclaw + certificate-profile-name: openclaw + files-folder: dist + files-folder-filter: exe + files-folder-recurse: true + file-digest: SHA256 + timestamp-rfc3161: http://timestamp.acs.microsoft.com + timestamp-digest: SHA256 + - name: Verify Foundation signatures and package final bytes + shell: pwsh + env: + MTIME: ${{ needs.plan.outputs.mtime }} + run: ./scripts/openclaw-release/package-windows.ps1 -Dist dist -Mtime $env:MTIME -Mode SignedRelease + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: signed-windows + path: | + dist/*.zip + dist/*.signing.json + if-no-files-found: error + compression-level: 0 + retention-days: 14 + + windows-test-only: + name: Package unsigned Windows test artifacts + needs: [plan, build] + if: needs.plan.outputs.windows == 'true' && needs.plan.outputs.publish != 'true' + runs-on: windows-2025 + timeout-minutes: 15 + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + sparse-checkout: scripts/openclaw-release + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + pattern: test-only-input-windows-* + merge-multiple: true + path: dist + - name: Package test-only bytes without signing credentials + shell: pwsh + env: + MTIME: ${{ needs.plan.outputs.mtime }} + run: ./scripts/openclaw-release/package-windows.ps1 -Dist dist -Mtime $env:MTIME -Mode UnsignedTest + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: test-only-windows + path: | + dist/*.zip + dist/*.signing.json + if-no-files-found: error + compression-level: 0 + retention-days: 14 + smoke: name: Smoke ${{ matrix.target }} - needs: [plan, build, sign-macos] - if: ${{ !cancelled() && needs.build.result == 'success' && needs.sign-macos.result != 'failure' }} + needs: [plan, build, sign-macos, sign-windows, windows-test-only] + if: ${{ !cancelled() && needs.build.result == 'success' && needs.sign-macos.result != 'failure' && (needs.plan.outputs.windows != 'true' || (needs.plan.outputs.publish == 'true' && needs.sign-windows.result == 'success') || (needs.plan.outputs.publish != 'true' && needs.windows-test-only.result == 'success')) }} runs-on: ${{ matrix.runner }} timeout-minutes: 15 strategy: @@ -305,10 +393,61 @@ jobs: codesign -dv "$exe" 2>&1 | grep -E '^(Authority|TeamIdentifier|CodeDirectory)' || true fi + windows-compatibility: + name: Compatibility ${{ matrix.target }} + needs: [plan, build, sign-windows, windows-test-only] + if: ${{ !cancelled() && needs.plan.outputs.windows == 'true' && ((needs.plan.outputs.publish == 'true' && needs.sign-windows.result == 'success') || (needs.plan.outputs.publish != 'true' && needs.windows-test-only.result == 'success')) }} + runs-on: ${{ matrix.runner }} + timeout-minutes: 40 + strategy: + fail-fast: false + matrix: + include: ${{ fromJSON(needs.plan.outputs.windows-matrix) }} + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + path: pipeline + persist-credentials: false + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + path: source + ref: ${{ needs.plan.outputs.commit }} + persist-credentials: false + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: "26.3.0" + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: ${{ matrix.artifact }} + path: dist + - name: Run shared Windows compatibility selection + working-directory: source + shell: pwsh + env: + TRIPLET: ${{ matrix.triplet }} + EXPECTED_ARCH: ${{ matrix.target == 'windows-arm64' && 'arm64' || 'x64' }} + run: | + Expand-Archive -LiteralPath "../dist/$env:TRIPLET.zip" -DestinationPath ../runtime + $exe = (Resolve-Path "../runtime/$env:TRIPLET/bun.exe").Path + $arch = & $exe -p process.arch + if ($LASTEXITCODE -ne 0 -or $arch -cne $env:EXPECTED_ARCH) { throw 'Unexpected runtime architecture.' } + $env:PATH = "$(Split-Path $exe);$env:PATH" + & $exe ../pipeline/scripts/openclaw-ci/tests.ts select-windows + if ($LASTEXITCODE -ne 0) { throw 'Test selection failed.' } + & $exe ../pipeline/scripts/openclaw-ci/tests.ts test + if ($LASTEXITCODE -ne 0) { throw 'Windows compatibility tests failed.' } + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + if: always() + with: + name: compatibility-${{ matrix.target }} + path: source/build/openclaw-ci/*.json + if-no-files-found: error + retention-days: 14 + manifest: name: Manifest - needs: [plan, build, sign-macos, smoke] - if: ${{ !cancelled() && needs.smoke.result == 'success' }} + needs: [plan, build, sign-macos, smoke, windows-compatibility] + if: ${{ !cancelled() && needs.smoke.result == 'success' && (needs.plan.outputs.windows != 'true' || needs.windows-compatibility.result == 'success') }} runs-on: ubuntu-24.04 timeout-minutes: 15 steps: @@ -330,21 +469,24 @@ jobs: - name: Download uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: - pattern: "{build-linux-*,build-windows-*,signed-*}" + pattern: "{build-linux-*,signed-*,test-only-windows}" path: dist merge-multiple: true - name: Write manifest env: TAG: ${{ needs.plan.outputs.tag }} RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} + PUBLISH: ${{ needs.plan.outputs.publish }} run: | revision="" if [ -f dist/bun-linux-x64.zip ]; then unzip -q dist/bun-linux-x64.zip -d "$RUNNER_TEMP" revision="$("$RUNNER_TEMP/bun-linux-x64/bun" --revision)" fi + args=() + [ "$PUBLISH" = true ] && args+=(--publish) bun pipeline/scripts/openclaw-release/release.ts manifest --source source --commit HEAD \ - --dist dist --out release --tag "$TAG" --workflow-run "$RUN_URL" ${revision:+--revision "$revision"} + --dist dist --out release --tag "$TAG" --workflow-run "$RUN_URL" ${revision:+--revision "$revision"} "${args[@]}" cp dist/*.zip release/ cat release/manifest.json cat release/release-notes.md >> "$GITHUB_STEP_SUMMARY" diff --git a/CHANGELOG.md b/CHANGELOG.md index f3e73f501a42..0c1f28468834 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -203,3 +203,7 @@ - Add position-preserving `module.stripTypeScriptTypes()` strip mode for tooling that analyzes TypeScript exports. Adapts [oven-sh/bun#35517](https://github.com/oven-sh/bun/pull/35517); thanks @cirospaciari! - Keep query and fragment imports of compiled embedded modules on their canonical module record, including Windows and non-ASCII filenames. + +- Build Windows ARM64 alongside x64, require Foundation Authenticode signatures before Windows release packaging, and qualify both architectures with the same native compatibility selection. Unsigned CI artifacts are explicitly test-only. + +- Pin immutable [OpenClaw WebKit `f1e1ca1156`](https://github.com/openclaw/WebKit/releases/tag/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661) with all ten archive checksums, including Windows ARM64, cached repeated stack coordinates, and the ARM64 allocation-accounting arithmetic fix. diff --git a/scripts/build/deps/webkit-artifacts.json b/scripts/build/deps/webkit-artifacts.json index 2b890b053603..ae512c15eb3a 100644 --- a/scripts/build/deps/webkit-artifacts.json +++ b/scripts/build/deps/webkit-artifacts.json @@ -1,53 +1,58 @@ { "schema_version": 1, - "version": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "version": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "repository": "openclaw/WebKit", - "tag": "autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee", + "tag": "autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "artifacts": { "bun-webkit-linux-amd64.tar.gz": { - "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee/bun-webkit-linux-amd64.tar.gz", - "sha256": "3f212b2d35218fa53244857a0f87be73a35bfd8a1a7a524a8574c4eb1c545bb5", - "size": 471708368 + "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661/bun-webkit-linux-amd64.tar.gz", + "sha256": "393532ee1de14958ca3016aa75252fc05f24ebc1e9fc952421a962c833810a08", + "size": 471813263 }, "bun-webkit-macos-arm64.tar.gz": { - "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee/bun-webkit-macos-arm64.tar.gz", - "sha256": "6e97f2b3027ecaed2ea6999404c3e21a957236be83879cf6110bc2afcbc648ba", - "size": 210465154 + "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661/bun-webkit-macos-arm64.tar.gz", + "sha256": "d9345a6a6116feb33a3e25bdf87f7325f344e1b70a1956b12ebbb39b11839e9f", + "size": 210441814 }, "bun-webkit-linux-amd64-lto.tar.gz": { - "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee/bun-webkit-linux-amd64-lto.tar.gz", - "sha256": "13a30c6f94b9a3044514136ed8e73e7213a72c99c0296aad27fae0d94266110c", - "size": 262892415 + "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661/bun-webkit-linux-amd64-lto.tar.gz", + "sha256": "bdc5ae411548f4fc7045787105127e44ff499216b62a16161128484318f01dd8", + "size": 262894861 }, "bun-webkit-linux-arm64-lto.tar.gz": { - "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee/bun-webkit-linux-arm64-lto.tar.gz", - "sha256": "43b6d9ca2c94ef340d190c6a97806ca848f866c1b2a9225b9922925e3db8c460", - "size": 257000294 + "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661/bun-webkit-linux-arm64-lto.tar.gz", + "sha256": "ac80d3619592e3689f90f6999e91d4b74628fe73bbfd53e45be0a5187514b933", + "size": 257005812 }, "bun-webkit-macos-arm64-lto.tar.gz": { - "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee/bun-webkit-macos-arm64-lto.tar.gz", - "sha256": "9f2da37e7282fe0aa76e4bc2836eb77eca0465f0b1aeef2aaf00e6fdb10d49f7", - "size": 155369091 + "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661/bun-webkit-macos-arm64-lto.tar.gz", + "sha256": "585d65c91c487167f0d963f6297a2b1ba4c0ff3a902d5a8e54345b00ee718004", + "size": 155373126 }, "bun-webkit-macos-amd64-lto.tar.gz": { - "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee/bun-webkit-macos-amd64-lto.tar.gz", - "sha256": "a26c41479171a1f1bedb2ba50760da1eeff9a43bda4c28ee879e91388accb5e7", - "size": 159719837 + "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661/bun-webkit-macos-amd64-lto.tar.gz", + "sha256": "fd94e8868c6771faa131b8d718aff8281b07d13c95ccbfce6f180df8bbd3a6d5", + "size": 159733683 }, "bun-webkit-linux-amd64-musl-lto.tar.gz": { - "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee/bun-webkit-linux-amd64-musl-lto.tar.gz", - "sha256": "ffc6b56895fdeb1a50929f6f23d598b5aa3077c582ba91139a13b045b05495db", - "size": 221673403 + "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661/bun-webkit-linux-amd64-musl-lto.tar.gz", + "sha256": "6bb81b6854e6683e75beb84b949c6e3fdb097253ca70ae8bd674c02a17a81386", + "size": 221675770 }, "bun-webkit-linux-arm64-musl-lto.tar.gz": { - "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee/bun-webkit-linux-arm64-musl-lto.tar.gz", - "sha256": "b851b7c8b623a3f36e70d389768e97a184cf914b5157f660fd8dfc921d47e3d7", - "size": 223555281 + "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661/bun-webkit-linux-arm64-musl-lto.tar.gz", + "sha256": "e31df77bd1b147d8d22bcd7502e0ae78165dda1180e465cccfc00f02f2f3f4b4", + "size": 223553290 }, "bun-webkit-windows-amd64-lto.tar.gz": { - "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-42ab38d705d4838748ccee77e7deb0e4e35515ee/bun-webkit-windows-amd64-lto.tar.gz", - "sha256": "af35f42d056d4b346fe83e01d8840f63c9303b1dc517e0545cb68e906fcc5af0", - "size": 665538527 + "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661/bun-webkit-windows-amd64-lto.tar.gz", + "sha256": "8481faabd1d67dc17f82684bc5e59417a38c6ea06c734a75157d8511c034d3c7", + "size": 665612707 + }, + "bun-webkit-windows-arm64.tar.gz": { + "url": "https://github.com/openclaw/WebKit/releases/download/autobuild-f1e1ca1156c8cb3b468bec0e1989fbfa08899661/bun-webkit-windows-arm64.tar.gz", + "sha256": "9883a17e6a4a61e9df737ca9c772a1c03b5a157f8f6aca4a5c8e040be893afda", + "size": 367114876 } }, "variants": { @@ -90,9 +95,13 @@ { "label": "bun-webkit-windows-amd64-lto", "consumer": "openclaw-release.yml optional windows-x64" + }, + { + "label": "bun-webkit-windows-arm64", + "consumer": "openclaw-release.yml windows-arm64: release without LTO" } ], - "excluded": "Windows arm64, Android, FreeBSD, debug and ASAN are not selected by the fork's active OpenClaw workflows. There is no separate x64 baseline WebKit archive.", + "excluded": "Android, FreeBSD, debug and ASAN are not selected by the fork's active OpenClaw workflows. Windows arm64 uses upstream's non-LTO lane because LLVM CodeView cannot encode its LTO register tuples. There is no separate x64 baseline WebKit archive.", "upstream_sync": { "base_commit": "d2d2a26ef973cdd97b37953f5dba58052acad74f", "upstream_commit": "1878660bb47a6a87ebe518cea0581ef4bf9b71f8", @@ -103,7 +112,7 @@ }, "qualification": { "passed": true, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "bun_commit": "b83b544ef744b6ab0dc1feadb59652261d64291d", "selected_files": 44, "result_files": 46, @@ -133,32 +142,32 @@ "arraybuffer-serializer": 60, "inspection-idle": 1 }, - "adapter_sha256": "1ad8cdbac31abe252fdaaf933a3ceeada0e7f43d2067469cda6d245d7878effc" + "adapter_sha256": "b75719df52813287a61ede5e8069368ac1739fbc08da56c9d1d1a755c4463265" }, "engine": { "passed": true, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "stress_counts": { - "jsc-stress": 1674, + "jsc-stress": 1778, "jsc-modules": 1639 }, "sampling_tiers": 4, "arraybuffer_execution_modes": 5, - "stack_execution_modes": 4, + "stack_execution_modes": 7, "stack_cache": { "owned": { - "files": 3, - "bytes": 33024 + "files": 4, + "bytes": 36352 }, "persistent": { - "files": 3, - "bytes": 33024 + "files": 4, + "bytes": 36352 } } }, "compatibility": { "passed": true, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "base_commit": "d2d2a26ef973cdd97b37953f5dba58052acad74f", "prepared_tree": "d9ec052fccc81afbf43a5344e52bc980f439d587", "paired_tree": "aee7cd52d7efcb9835b434a24fa47de06cc664f6", @@ -166,13 +175,25 @@ "only_manifest_changed_after_pairing": true, "memory_tests": 3, "startup": true, - "manifest_patch_sha256": "a9c7a9df7e4dba3fedfdb257aa814b1efffdc3b1ce60dc1353a451e673e3a295" + "manifest_patch_sha256": "d343893f082240b1eaf7dc81f767741bedef5d1cec0c0faf3ac099c39557ab2d" + }, + "windows_arm64": { + "arraybuffer_modes": 5, + "lane": "bun-webkit-windows-arm64", + "dfg": true, + "arraybuffer_accounting": true, + "architecture": "arm64", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "sha256": "9883a17e6a4a61e9df737ca9c772a1c03b5a157f8f6aca4a5c8e040be893afda", + "passed": true, + "startup": true, + "ffi": true } }, "lanes": [ { "schema_version": 1, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "base": "5718a6ec579b98362ea7276a426deedcc6281ef5", "lane": { "label": "bun-webkit-linux-amd64", @@ -342,6 +363,21 @@ "commit": "42ab38d705d4838748ccee77e7deb0e4e35515ee", "subject": "build(webkit): qualify complete rebased engine batch (#6)", "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "641c15f9283845195dd3520dddc1fbd668379350", + "subject": "perf(jsc): carry stack coordinate cache into rebased release (#9)", + "patch_sha256": "e1f1e01dc10efb3e448d6ec611d7e9a6a3622f9494b6a09d580b1f4bfa5cb57c" + }, + { + "commit": "c75925d9c51b8df1402320f9c472805a90ac6353", + "subject": "ci: qualify Windows ARM64 engine artifacts", + "patch_sha256": "160ba0c78e66588511288c5893d49dadd2b350c90c10851a7b3888e5e975ecf0" + }, + { + "commit": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "subject": "fix(jsc): correct ARM64 memory addition and qualify native tiers (#13)", + "patch_sha256": "61d94fa0e059f00dcd96e840a77ed8a178198f7db62a5739c3d60029d56e9dc9" } ], "recipe_sha256": { @@ -366,7 +402,7 @@ "macos-cross/mig": "efa2dc0b4a25c65efce82569f6818fd8c6646351446c62fcd7ce36dc3f5a503a", "macos-cross/xmac.mjs": "ba7af744715fec67c8baa3026f679dac75a4ccd30207437572664675f65bd45b" }, - "toolchain_image_id": "sha256:7688c9e0a58e3410c90d6cfa0655daa67eeb6dabc1b006792c84511129811a21", + "toolchain_image_id": "sha256:c7f718d7f4426619dcaf244ff3457cc616ef7320e68dd6ed2e6fcd5cf306a634", "commands": { "base": [ "docker", @@ -447,25 +483,25 @@ "tool_versions": "Ubuntu clang version 23.1.2 (++20260910043923+069ef0e7cb36-1~exp1~20260910043934.72)\nTarget: x86_64-pc-linux-gnu\nThread model: posix\nInstalledDir: /usr/lib/llvm-23/bin\ncmake version 4.4.3\n\nCMake suite maintained and supported by Kitware (kitware.com/cmake).\n1.10.0", "docker_version": "Client: Docker Engine - Community\n Version: 28.0.4\n API version: 1.48\n Go version: go1.23.7\n Git commit: b8034c0\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Context: default\n\nServer: Docker Engine - Community\n Engine:\n Version: 28.0.4\n API version: 1.48 (minimum version 1.24)\n Go version: go1.23.7\n Git commit: 6430e49\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Experimental: false\n containerd:\n Version: v2.2.1\n GitCommit: dea7da592f5d1d2b7755e3a161be07f43fad8f75\n runc:\n Version: 1.3.4\n GitCommit: v1.3.4-0-gd6d73eb8\n docker-init:\n Version: 0.19.0\n GitCommit: de40ad0", "buildx_version": "github.com/docker/buildx v0.23.0 28c90eadc4c12cc78155ad59ca5f486220241d2a", - "workflow_run": "37254059740", + "workflow_run": "37317069743", "run_attempt": "1", - "elapsed_seconds": 498.0978660583496, + "elapsed_seconds": 609.7423703670502, "files": { "bun-webkit-linux-amd64.tar.gz": { - "sha256": "3f212b2d35218fa53244857a0f87be73a35bfd8a1a7a524a8574c4eb1c545bb5", - "size": 471708368 + "sha256": "393532ee1de14958ca3016aa75252fc05f24ebc1e9fc952421a962c833810a08", + "size": 471813263 } }, "provenance_files": { - "toolchain-image.json": "a1e434af7fd07bc13bb34c37e50025b21bb0c93b8af75384985805f159e04d7b", "tool-versions.txt": "1f732938c107d159895e80daffe13bc457ce53c90ec3af6123ca41de962a231f", - "toolchain-build.json": "84b62eadd843a1461cc8e1392c803cc6a2c7f46334c216ec1edb783cbfb46f67", - "artifact-build.json": "61b88855a9b9ef8bff855441f838d270b6efc75803c58c839b763e381264a551" + "toolchain-build.json": "1b93449a6730e767e55b7887adb615e8b2cb4ec590b6adeef289632572c4ec1b", + "toolchain-image.json": "b2c43139030f827a090a2867494d2826d124f83054ed078b213b64520817b86a", + "artifact-build.json": "091b485b600f6da24a1e959d1a851e33750a93f9aa239d97222ebca461634358" } }, { "schema_version": 1, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "base": "5718a6ec579b98362ea7276a426deedcc6281ef5", "lane": { "label": "bun-webkit-macos-arm64", @@ -634,6 +670,21 @@ "commit": "42ab38d705d4838748ccee77e7deb0e4e35515ee", "subject": "build(webkit): qualify complete rebased engine batch (#6)", "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "641c15f9283845195dd3520dddc1fbd668379350", + "subject": "perf(jsc): carry stack coordinate cache into rebased release (#9)", + "patch_sha256": "e1f1e01dc10efb3e448d6ec611d7e9a6a3622f9494b6a09d580b1f4bfa5cb57c" + }, + { + "commit": "c75925d9c51b8df1402320f9c472805a90ac6353", + "subject": "ci: qualify Windows ARM64 engine artifacts", + "patch_sha256": "160ba0c78e66588511288c5893d49dadd2b350c90c10851a7b3888e5e975ecf0" + }, + { + "commit": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "subject": "fix(jsc): correct ARM64 memory addition and qualify native tiers (#13)", + "patch_sha256": "61d94fa0e059f00dcd96e840a77ed8a178198f7db62a5739c3d60029d56e9dc9" } ], "recipe_sha256": { @@ -658,7 +709,7 @@ "macos-cross/mig": "efa2dc0b4a25c65efce82569f6818fd8c6646351446c62fcd7ce36dc3f5a503a", "macos-cross/xmac.mjs": "ba7af744715fec67c8baa3026f679dac75a4ccd30207437572664675f65bd45b" }, - "toolchain_image_id": "sha256:bf7b4f77e1ee7761443528f7a72d63e1bb9693050578510b5d2da0e428699464", + "toolchain_image_id": "sha256:a1d68c831a0a45a5f8c63e7cc42ad1988f3f8d6925128118b587d08df8129cda", "commands": { "base": [ "docker", @@ -739,25 +790,25 @@ "tool_versions": "Ubuntu clang version 23.1.2 (++20260910044232+069ef0e7cb36-1~exp1~20260910044242.70)\nTarget: x86_64-pc-linux-gnu\nThread model: posix\nInstalledDir: /usr/lib/llvm-23/bin\ncmake version 3.28.3\n\nCMake suite maintained and supported by Kitware (kitware.com/cmake).\n1.11.1", "docker_version": "Client: Docker Engine - Community\n Version: 28.0.4\n API version: 1.48\n Go version: go1.23.7\n Git commit: b8034c0\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Context: default\n\nServer: Docker Engine - Community\n Engine:\n Version: 28.0.4\n API version: 1.48 (minimum version 1.24)\n Go version: go1.23.7\n Git commit: 6430e49\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Experimental: false\n containerd:\n Version: v2.2.1\n GitCommit: dea7da592f5d1d2b7755e3a161be07f43fad8f75\n runc:\n Version: 1.3.4\n GitCommit: v1.3.4-0-gd6d73eb8\n docker-init:\n Version: 0.19.0\n GitCommit: de40ad0", "buildx_version": "github.com/docker/buildx v0.23.0 28c90eadc4c12cc78155ad59ca5f486220241d2a", - "workflow_run": "37254059740", + "workflow_run": "37317069743", "run_attempt": "1", - "elapsed_seconds": 264.0893898010254, + "elapsed_seconds": 332.6816554069519, "files": { "bun-webkit-macos-arm64.tar.gz": { - "sha256": "6e97f2b3027ecaed2ea6999404c3e21a957236be83879cf6110bc2afcbc648ba", - "size": 210465154 + "sha256": "d9345a6a6116feb33a3e25bdf87f7325f344e1b70a1956b12ebbb39b11839e9f", + "size": 210441814 } }, "provenance_files": { - "toolchain-build.json": "ba0711835b7c90b2444ce71679fd188c0c940c9b0050490bce796bf86fb33785", - "tool-versions.txt": "9e25fc80a955f54e9ff61e7796df5c0b79d4bc6677fc47ee2357d99fdf5fa8e8", - "toolchain-image.json": "c0d20bff6bfd1dbefe1e0705b2a1eb43aaaad5d0e530fd5ba77772a8f55d0ecb", - "artifact-build.json": "023c27240a88bec583a06e1aa243a9075fc5d07a33386d2d627ed63eec9fc4cd" + "toolchain-build.json": "e00bf91ef1cba9eb2d1520cbb7af942bef643d57a9328fe514c1a47899b49352", + "toolchain-image.json": "fc50f3a14be0e326d31cfbc0393b75e0b958c391bf1eff13d092f7a4cedcbcf3", + "artifact-build.json": "698c84037e00cf3cedd82880f1c6a07f98784a0da8e4fe00cc89e42801bc56aa", + "tool-versions.txt": "9e25fc80a955f54e9ff61e7796df5c0b79d4bc6677fc47ee2357d99fdf5fa8e8" } }, { "schema_version": 1, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "base": "5718a6ec579b98362ea7276a426deedcc6281ef5", "lane": { "label": "bun-webkit-linux-amd64-lto", @@ -927,6 +978,21 @@ "commit": "42ab38d705d4838748ccee77e7deb0e4e35515ee", "subject": "build(webkit): qualify complete rebased engine batch (#6)", "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "641c15f9283845195dd3520dddc1fbd668379350", + "subject": "perf(jsc): carry stack coordinate cache into rebased release (#9)", + "patch_sha256": "e1f1e01dc10efb3e448d6ec611d7e9a6a3622f9494b6a09d580b1f4bfa5cb57c" + }, + { + "commit": "c75925d9c51b8df1402320f9c472805a90ac6353", + "subject": "ci: qualify Windows ARM64 engine artifacts", + "patch_sha256": "160ba0c78e66588511288c5893d49dadd2b350c90c10851a7b3888e5e975ecf0" + }, + { + "commit": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "subject": "fix(jsc): correct ARM64 memory addition and qualify native tiers (#13)", + "patch_sha256": "61d94fa0e059f00dcd96e840a77ed8a178198f7db62a5739c3d60029d56e9dc9" } ], "recipe_sha256": { @@ -951,7 +1017,7 @@ "macos-cross/mig": "efa2dc0b4a25c65efce82569f6818fd8c6646351446c62fcd7ce36dc3f5a503a", "macos-cross/xmac.mjs": "ba7af744715fec67c8baa3026f679dac75a4ccd30207437572664675f65bd45b" }, - "toolchain_image_id": "sha256:74bac7197805a7429614cb6a96e3c1cd594e118063cd54e43d24b2196a66c513", + "toolchain_image_id": "sha256:c7c783b1034aca8f65df808def95aa1f36ad57cea02dc2f7356e24856ce84a7d", "commands": { "base": [ "docker", @@ -1032,25 +1098,25 @@ "tool_versions": "Ubuntu clang version 23.1.2 (++20260910043923+069ef0e7cb36-1~exp1~20260910043934.72)\nTarget: x86_64-pc-linux-gnu\nThread model: posix\nInstalledDir: /usr/lib/llvm-23/bin\ncmake version 4.4.3\n\nCMake suite maintained and supported by Kitware (kitware.com/cmake).\n1.10.0", "docker_version": "Client: Docker Engine - Community\n Version: 28.0.4\n API version: 1.48\n Go version: go1.23.7\n Git commit: b8034c0\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Context: default\n\nServer: Docker Engine - Community\n Engine:\n Version: 28.0.4\n API version: 1.48 (minimum version 1.24)\n Go version: go1.23.7\n Git commit: 6430e49\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Experimental: false\n containerd:\n Version: v2.2.1\n GitCommit: dea7da592f5d1d2b7755e3a161be07f43fad8f75\n runc:\n Version: 1.3.4\n GitCommit: v1.3.4-0-gd6d73eb8\n docker-init:\n Version: 0.19.0\n GitCommit: de40ad0", "buildx_version": "github.com/docker/buildx v0.23.0 28c90eadc4c12cc78155ad59ca5f486220241d2a", - "workflow_run": "37254059740", + "workflow_run": "37317069743", "run_attempt": "1", - "elapsed_seconds": 571.4663543701172, + "elapsed_seconds": 819.3644161224365, "files": { "bun-webkit-linux-amd64-lto.tar.gz": { - "sha256": "13a30c6f94b9a3044514136ed8e73e7213a72c99c0296aad27fae0d94266110c", - "size": 262892415 + "sha256": "bdc5ae411548f4fc7045787105127e44ff499216b62a16161128484318f01dd8", + "size": 262894861 } }, "provenance_files": { - "artifact-build.json": "73ccbcc57ab4193a5547c0b1a75866265cc581b7d72e94b45c8e19fc33b9c308", - "toolchain-image.json": "15256f89bb4e79fb0d393b15f0b4ba672c321aa48cbfe155d53ccc5d9ff9f3d4", - "toolchain-build.json": "e7b854246d252b176ba4c484194e5bd452439d70b204c5f54f04964b62afe1a0", + "toolchain-build.json": "6c78e64657ba8c03dd1d6296556da46069b9ee65d6a5e6023e0d4fee9fc01bc1", + "toolchain-image.json": "6b7024e4e55308490f30631e26103af5f04b931ffb78de23de666cb1478c9320", + "artifact-build.json": "de90d0c22c6bdb9846b0e6544ba059deb082b063f06333048d9a9a243a1379ae", "tool-versions.txt": "1f732938c107d159895e80daffe13bc457ce53c90ec3af6123ca41de962a231f" } }, { "schema_version": 1, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "base": "5718a6ec579b98362ea7276a426deedcc6281ef5", "lane": { "label": "bun-webkit-linux-arm64-lto", @@ -1220,6 +1286,21 @@ "commit": "42ab38d705d4838748ccee77e7deb0e4e35515ee", "subject": "build(webkit): qualify complete rebased engine batch (#6)", "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "641c15f9283845195dd3520dddc1fbd668379350", + "subject": "perf(jsc): carry stack coordinate cache into rebased release (#9)", + "patch_sha256": "e1f1e01dc10efb3e448d6ec611d7e9a6a3622f9494b6a09d580b1f4bfa5cb57c" + }, + { + "commit": "c75925d9c51b8df1402320f9c472805a90ac6353", + "subject": "ci: qualify Windows ARM64 engine artifacts", + "patch_sha256": "160ba0c78e66588511288c5893d49dadd2b350c90c10851a7b3888e5e975ecf0" + }, + { + "commit": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "subject": "fix(jsc): correct ARM64 memory addition and qualify native tiers (#13)", + "patch_sha256": "61d94fa0e059f00dcd96e840a77ed8a178198f7db62a5739c3d60029d56e9dc9" } ], "recipe_sha256": { @@ -1244,7 +1325,7 @@ "macos-cross/mig": "efa2dc0b4a25c65efce82569f6818fd8c6646351446c62fcd7ce36dc3f5a503a", "macos-cross/xmac.mjs": "ba7af744715fec67c8baa3026f679dac75a4ccd30207437572664675f65bd45b" }, - "toolchain_image_id": "sha256:f651976e7743e4e484097bf24df183216bd0def69136b92c40ab630728f4ca0a", + "toolchain_image_id": "sha256:9370d36927301a627de5f43285785facc6fb82f7a99ddf58ae60bca0bd37db34", "commands": { "base": [ "docker", @@ -1325,25 +1406,25 @@ "tool_versions": "Ubuntu clang version 23.1.2 (++20260910043923+069ef0e7cb36-1~exp1~20260910043934.72)\nTarget: x86_64-pc-linux-gnu\nThread model: posix\nInstalledDir: /usr/lib/llvm-23/bin\ncmake version 4.4.3\n\nCMake suite maintained and supported by Kitware (kitware.com/cmake).\n1.10.0", "docker_version": "Client: Docker Engine - Community\n Version: 28.0.4\n API version: 1.48\n Go version: go1.23.7\n Git commit: b8034c0\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Context: default\n\nServer: Docker Engine - Community\n Engine:\n Version: 28.0.4\n API version: 1.48 (minimum version 1.24)\n Go version: go1.23.7\n Git commit: 6430e49\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Experimental: false\n containerd:\n Version: v2.2.1\n GitCommit: dea7da592f5d1d2b7755e3a161be07f43fad8f75\n runc:\n Version: 1.3.4\n GitCommit: v1.3.4-0-gd6d73eb8\n docker-init:\n Version: 0.19.0\n GitCommit: de40ad0", "buildx_version": "github.com/docker/buildx v0.23.0 28c90eadc4c12cc78155ad59ca5f486220241d2a", - "workflow_run": "37254059740", + "workflow_run": "37317069743", "run_attempt": "1", - "elapsed_seconds": 516.0187137126923, + "elapsed_seconds": 751.6207590103149, "files": { "bun-webkit-linux-arm64-lto.tar.gz": { - "sha256": "43b6d9ca2c94ef340d190c6a97806ca848f866c1b2a9225b9922925e3db8c460", - "size": 257000294 + "sha256": "ac80d3619592e3689f90f6999e91d4b74628fe73bbfd53e45be0a5187514b933", + "size": 257005812 } }, "provenance_files": { "tool-versions.txt": "1f732938c107d159895e80daffe13bc457ce53c90ec3af6123ca41de962a231f", - "toolchain-build.json": "a82032a22ec352b13a11ae55f0bd7ff79124f9da30b5b89a2e7b129d0e8f6eb2", - "artifact-build.json": "883722c60181a6c8455e0080bab625730611684ec15339633e47852fb8cc05a0", - "toolchain-image.json": "f4f22657f6b4e905aa99240e5ccd546ea1055379b5ff87a3d25a666d14ec1b6d" + "toolchain-image.json": "ab882dc2782742b24c579b60ccc1eb4686ae00a174936f64eb830e8bdf2a95a8", + "toolchain-build.json": "9b07b16fb81e4e31d0b8b428e820e7b522e4e571a7f1ff3293e8565882db1d95", + "artifact-build.json": "465672ffa5f53f3e0b8ff196423e72088945b6e880a911c9123f4ba3aed55007" } }, { "schema_version": 1, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "base": "5718a6ec579b98362ea7276a426deedcc6281ef5", "lane": { "label": "bun-webkit-macos-arm64-lto", @@ -1512,6 +1593,21 @@ "commit": "42ab38d705d4838748ccee77e7deb0e4e35515ee", "subject": "build(webkit): qualify complete rebased engine batch (#6)", "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "641c15f9283845195dd3520dddc1fbd668379350", + "subject": "perf(jsc): carry stack coordinate cache into rebased release (#9)", + "patch_sha256": "e1f1e01dc10efb3e448d6ec611d7e9a6a3622f9494b6a09d580b1f4bfa5cb57c" + }, + { + "commit": "c75925d9c51b8df1402320f9c472805a90ac6353", + "subject": "ci: qualify Windows ARM64 engine artifacts", + "patch_sha256": "160ba0c78e66588511288c5893d49dadd2b350c90c10851a7b3888e5e975ecf0" + }, + { + "commit": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "subject": "fix(jsc): correct ARM64 memory addition and qualify native tiers (#13)", + "patch_sha256": "61d94fa0e059f00dcd96e840a77ed8a178198f7db62a5739c3d60029d56e9dc9" } ], "recipe_sha256": { @@ -1536,7 +1632,7 @@ "macos-cross/mig": "efa2dc0b4a25c65efce82569f6818fd8c6646351446c62fcd7ce36dc3f5a503a", "macos-cross/xmac.mjs": "ba7af744715fec67c8baa3026f679dac75a4ccd30207437572664675f65bd45b" }, - "toolchain_image_id": "sha256:2779b1ddddf18b31136bd190aec8bc17cfb70bd393d5968c2a846f4eb12c55d7", + "toolchain_image_id": "sha256:76dfad76eca9475f8361eec2e4150205d9d012d3a21059f1500355c2c3e61e35", "commands": { "base": [ "docker", @@ -1617,25 +1713,25 @@ "tool_versions": "Ubuntu clang version 23.1.2 (++20260910044232+069ef0e7cb36-1~exp1~20260910044242.70)\nTarget: x86_64-pc-linux-gnu\nThread model: posix\nInstalledDir: /usr/lib/llvm-23/bin\ncmake version 3.28.3\n\nCMake suite maintained and supported by Kitware (kitware.com/cmake).\n1.11.1", "docker_version": "Client: Docker Engine - Community\n Version: 28.0.4\n API version: 1.48\n Go version: go1.23.7\n Git commit: b8034c0\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Context: default\n\nServer: Docker Engine - Community\n Engine:\n Version: 28.0.4\n API version: 1.48 (minimum version 1.24)\n Go version: go1.23.7\n Git commit: 6430e49\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Experimental: false\n containerd:\n Version: v2.2.1\n GitCommit: dea7da592f5d1d2b7755e3a161be07f43fad8f75\n runc:\n Version: 1.3.4\n GitCommit: v1.3.4-0-gd6d73eb8\n docker-init:\n Version: 0.19.0\n GitCommit: de40ad0", "buildx_version": "github.com/docker/buildx v0.23.0 28c90eadc4c12cc78155ad59ca5f486220241d2a", - "workflow_run": "37254059740", + "workflow_run": "37317069743", "run_attempt": "1", - "elapsed_seconds": 302.5395154953003, + "elapsed_seconds": 408.99868988990784, "files": { "bun-webkit-macos-arm64-lto.tar.gz": { - "sha256": "9f2da37e7282fe0aa76e4bc2836eb77eca0465f0b1aeef2aaf00e6fdb10d49f7", - "size": 155369091 + "sha256": "585d65c91c487167f0d963f6297a2b1ba4c0ff3a902d5a8e54345b00ee718004", + "size": 155373126 } }, "provenance_files": { + "toolchain-build.json": "bb99c3d1a3fa3127cb7d3de55367b0f4a3e3877aa87d330bd61354c1b78eabc7", "tool-versions.txt": "9e25fc80a955f54e9ff61e7796df5c0b79d4bc6677fc47ee2357d99fdf5fa8e8", - "toolchain-build.json": "30e303a76c7db5014617c82d551ad6c0aaa984ecd6498bd01800670df355f655", - "toolchain-image.json": "fcbeab53512bbbe54df4181abe63b7f76a6859f33bfa964f0aa0cbe0fe5971e3", - "artifact-build.json": "2225d838cb43ded9d219c35f8480637042c7f09d775d448e6472ed4cc3d52e95" + "toolchain-image.json": "ea0b5fc6a90763eaadaabaa399d60825df661353a5198bf5b1ab2251b312d659", + "artifact-build.json": "5aa068d4e4676959d7364fada83af9598e095a4de28de9f4c98a1ab0b9b62f3c" } }, { "schema_version": 1, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "base": "5718a6ec579b98362ea7276a426deedcc6281ef5", "lane": { "label": "bun-webkit-macos-amd64-lto", @@ -1804,6 +1900,21 @@ "commit": "42ab38d705d4838748ccee77e7deb0e4e35515ee", "subject": "build(webkit): qualify complete rebased engine batch (#6)", "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "641c15f9283845195dd3520dddc1fbd668379350", + "subject": "perf(jsc): carry stack coordinate cache into rebased release (#9)", + "patch_sha256": "e1f1e01dc10efb3e448d6ec611d7e9a6a3622f9494b6a09d580b1f4bfa5cb57c" + }, + { + "commit": "c75925d9c51b8df1402320f9c472805a90ac6353", + "subject": "ci: qualify Windows ARM64 engine artifacts", + "patch_sha256": "160ba0c78e66588511288c5893d49dadd2b350c90c10851a7b3888e5e975ecf0" + }, + { + "commit": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "subject": "fix(jsc): correct ARM64 memory addition and qualify native tiers (#13)", + "patch_sha256": "61d94fa0e059f00dcd96e840a77ed8a178198f7db62a5739c3d60029d56e9dc9" } ], "recipe_sha256": { @@ -1828,7 +1939,7 @@ "macos-cross/mig": "efa2dc0b4a25c65efce82569f6818fd8c6646351446c62fcd7ce36dc3f5a503a", "macos-cross/xmac.mjs": "ba7af744715fec67c8baa3026f679dac75a4ccd30207437572664675f65bd45b" }, - "toolchain_image_id": "sha256:4bdbdfd4c0cadcd2737a6900eb09d6f871453753b1f7c7bf7900a102828ceafe", + "toolchain_image_id": "sha256:5c6caa4b711ebd6737ad1fdea97c1cf93aeadaac872a809ef8cd623f099c2bfe", "commands": { "base": [ "docker", @@ -1909,25 +2020,25 @@ "tool_versions": "Ubuntu clang version 23.1.2 (++20260910044232+069ef0e7cb36-1~exp1~20260910044242.70)\nTarget: x86_64-pc-linux-gnu\nThread model: posix\nInstalledDir: /usr/lib/llvm-23/bin\ncmake version 3.28.3\n\nCMake suite maintained and supported by Kitware (kitware.com/cmake).\n1.11.1", "docker_version": "Client: Docker Engine - Community\n Version: 28.0.4\n API version: 1.48\n Go version: go1.23.7\n Git commit: b8034c0\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Context: default\n\nServer: Docker Engine - Community\n Engine:\n Version: 28.0.4\n API version: 1.48 (minimum version 1.24)\n Go version: go1.23.7\n Git commit: 6430e49\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Experimental: false\n containerd:\n Version: v2.2.1\n GitCommit: dea7da592f5d1d2b7755e3a161be07f43fad8f75\n runc:\n Version: 1.3.4\n GitCommit: v1.3.4-0-gd6d73eb8\n docker-init:\n Version: 0.19.0\n GitCommit: de40ad0", "buildx_version": "github.com/docker/buildx v0.23.0 28c90eadc4c12cc78155ad59ca5f486220241d2a", - "workflow_run": "37254059740", + "workflow_run": "37317069743", "run_attempt": "1", - "elapsed_seconds": 301.75275921821594, + "elapsed_seconds": 431.33096528053284, "files": { "bun-webkit-macos-amd64-lto.tar.gz": { - "sha256": "a26c41479171a1f1bedb2ba50760da1eeff9a43bda4c28ee879e91388accb5e7", - "size": 159719837 + "sha256": "fd94e8868c6771faa131b8d718aff8281b07d13c95ccbfce6f180df8bbd3a6d5", + "size": 159733683 } }, "provenance_files": { - "toolchain-image.json": "1b85e0430351703297c5a998c2040d38567a8f2a435066a63e58e7ac088862cc", + "toolchain-build.json": "c8e4675cbc5c61bf7da80ee2d34a626ac84324cbc1e673d116a0555bf72cbb0a", + "artifact-build.json": "56769241357fd42575d03c4423a33d795d98362484d2732ba3fec325a073d155", "tool-versions.txt": "9e25fc80a955f54e9ff61e7796df5c0b79d4bc6677fc47ee2357d99fdf5fa8e8", - "artifact-build.json": "100e0bdcc628ceb37ce17e1f7e9791abe14106a3b808b9d4cdaf50cbfda8501f", - "toolchain-build.json": "a14a557ac12c358ef6924abfc3ad4c1ee0759583b87c3862d3bfe979cc280f9b" + "toolchain-image.json": "ffd8a8fcb7267d622a478b4547ce38a0066430ffdbf3db886872d028a4993435" } }, { "schema_version": 1, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "base": "5718a6ec579b98362ea7276a426deedcc6281ef5", "lane": { "label": "bun-webkit-linux-amd64-musl-lto", @@ -2094,6 +2205,21 @@ "commit": "42ab38d705d4838748ccee77e7deb0e4e35515ee", "subject": "build(webkit): qualify complete rebased engine batch (#6)", "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "641c15f9283845195dd3520dddc1fbd668379350", + "subject": "perf(jsc): carry stack coordinate cache into rebased release (#9)", + "patch_sha256": "e1f1e01dc10efb3e448d6ec611d7e9a6a3622f9494b6a09d580b1f4bfa5cb57c" + }, + { + "commit": "c75925d9c51b8df1402320f9c472805a90ac6353", + "subject": "ci: qualify Windows ARM64 engine artifacts", + "patch_sha256": "160ba0c78e66588511288c5893d49dadd2b350c90c10851a7b3888e5e975ecf0" + }, + { + "commit": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "subject": "fix(jsc): correct ARM64 memory addition and qualify native tiers (#13)", + "patch_sha256": "61d94fa0e059f00dcd96e840a77ed8a178198f7db62a5739c3d60029d56e9dc9" } ], "recipe_sha256": { @@ -2118,7 +2244,7 @@ "macos-cross/mig": "efa2dc0b4a25c65efce82569f6818fd8c6646351446c62fcd7ce36dc3f5a503a", "macos-cross/xmac.mjs": "ba7af744715fec67c8baa3026f679dac75a4ccd30207437572664675f65bd45b" }, - "toolchain_image_id": "sha256:81527131a43664cd03effdf2564c929e414cc253e2b739cf07a77cfc7f5dc3f9", + "toolchain_image_id": "sha256:2e6be4857bc530acc57ecef56eeec2a4835c72c1a394747bf37bf6e79b06772d", "commands": { "base": [ "docker", @@ -2191,25 +2317,25 @@ "tool_versions": "Alpine clang version 23.1.2\nTarget: x86_64-alpine-linux-musl\nThread model: posix\nInstalledDir: /usr/lib/llvm23/bin\nConfiguration file: /etc/clang23/x86_64-alpine-linux-musl.cfg\ncmake version 4.1.3\n\nCMake suite maintained and supported by Kitware (kitware.com/cmake).\n1.9", "docker_version": "Client: Docker Engine - Community\n Version: 28.0.4\n API version: 1.48\n Go version: go1.23.7\n Git commit: b8034c0\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Context: default\n\nServer: Docker Engine - Community\n Engine:\n Version: 28.0.4\n API version: 1.48 (minimum version 1.24)\n Go version: go1.23.7\n Git commit: 6430e49\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Experimental: false\n containerd:\n Version: v2.2.1\n GitCommit: dea7da592f5d1d2b7755e3a161be07f43fad8f75\n runc:\n Version: 1.3.4\n GitCommit: v1.3.4-0-gd6d73eb8\n docker-init:\n Version: 0.19.0\n GitCommit: de40ad0", "buildx_version": "github.com/docker/buildx v0.23.0 28c90eadc4c12cc78155ad59ca5f486220241d2a", - "workflow_run": "37254059740", + "workflow_run": "37317069743", "run_attempt": "1", - "elapsed_seconds": 666.6592268943787, + "elapsed_seconds": 1054.9010455608368, "files": { "bun-webkit-linux-amd64-musl-lto.tar.gz": { - "sha256": "ffc6b56895fdeb1a50929f6f23d598b5aa3077c582ba91139a13b045b05495db", - "size": 221673403 + "sha256": "6bb81b6854e6683e75beb84b949c6e3fdb097253ca70ae8bd674c02a17a81386", + "size": 221675770 } }, "provenance_files": { + "toolchain-image.json": "3845747a2a5f0f0587fd151dcd8ff10da7d409ae993f9d090e05661eff6e04a0", "tool-versions.txt": "4792d68346e97d6f8bcf05124f904e68c9f56299be740663f00da9e1ddc96e9f", - "artifact-build.json": "c6920fafd5a457c2874739a2b72a7f6f27ef70826c6d44cae6f7ee479c189f83", - "toolchain-image.json": "23db5680caccd6926074ffcddd530f3f771a113f387c0c45a06a318ed8dd2c20", - "toolchain-build.json": "4a03764226facbc57cb6409bf2aaca1ed26513819cfa4f6523234b8942c7b7ea" + "artifact-build.json": "133bfccee876923fdf37727a18daea8ee63e80a09960d38b842e8acd4304c1a6", + "toolchain-build.json": "0e25f47e824e99043c869cd733ed0f5ea6cec2ba96b9b61e7522550fee9296de" } }, { "schema_version": 1, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "base": "5718a6ec579b98362ea7276a426deedcc6281ef5", "lane": { "label": "bun-webkit-linux-arm64-musl-lto", @@ -2376,6 +2502,21 @@ "commit": "42ab38d705d4838748ccee77e7deb0e4e35515ee", "subject": "build(webkit): qualify complete rebased engine batch (#6)", "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "641c15f9283845195dd3520dddc1fbd668379350", + "subject": "perf(jsc): carry stack coordinate cache into rebased release (#9)", + "patch_sha256": "e1f1e01dc10efb3e448d6ec611d7e9a6a3622f9494b6a09d580b1f4bfa5cb57c" + }, + { + "commit": "c75925d9c51b8df1402320f9c472805a90ac6353", + "subject": "ci: qualify Windows ARM64 engine artifacts", + "patch_sha256": "160ba0c78e66588511288c5893d49dadd2b350c90c10851a7b3888e5e975ecf0" + }, + { + "commit": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "subject": "fix(jsc): correct ARM64 memory addition and qualify native tiers (#13)", + "patch_sha256": "61d94fa0e059f00dcd96e840a77ed8a178198f7db62a5739c3d60029d56e9dc9" } ], "recipe_sha256": { @@ -2400,7 +2541,7 @@ "macos-cross/mig": "efa2dc0b4a25c65efce82569f6818fd8c6646351446c62fcd7ce36dc3f5a503a", "macos-cross/xmac.mjs": "ba7af744715fec67c8baa3026f679dac75a4ccd30207437572664675f65bd45b" }, - "toolchain_image_id": "sha256:c50870b96551722e712703c14a07245285edf5339120bf3c19454d77fce155c5", + "toolchain_image_id": "sha256:045a3e910aa6a1ecdce327aefe22f0162d378cb044c2836772a3d0f8d4d4db2e", "commands": { "base": [ "docker", @@ -2473,25 +2614,25 @@ "tool_versions": "Alpine clang version 23.1.2\nTarget: x86_64-alpine-linux-musl\nThread model: posix\nInstalledDir: /usr/lib/llvm23/bin\nConfiguration file: /etc/clang23/x86_64-alpine-linux-musl.cfg\ncmake version 4.1.3\n\nCMake suite maintained and supported by Kitware (kitware.com/cmake).\n1.9", "docker_version": "Client: Docker Engine - Community\n Version: 28.0.4\n API version: 1.48\n Go version: go1.23.7\n Git commit: b8034c0\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Context: default\n\nServer: Docker Engine - Community\n Engine:\n Version: 28.0.4\n API version: 1.48 (minimum version 1.24)\n Go version: go1.23.7\n Git commit: 6430e49\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Experimental: false\n containerd:\n Version: v2.2.1\n GitCommit: dea7da592f5d1d2b7755e3a161be07f43fad8f75\n runc:\n Version: 1.3.4\n GitCommit: v1.3.4-0-gd6d73eb8\n docker-init:\n Version: 0.19.0\n GitCommit: de40ad0", "buildx_version": "github.com/docker/buildx v0.23.0 28c90eadc4c12cc78155ad59ca5f486220241d2a", - "workflow_run": "37254059740", + "workflow_run": "37317069743", "run_attempt": "1", - "elapsed_seconds": 673.2071342468262, + "elapsed_seconds": 868.9853370189667, "files": { "bun-webkit-linux-arm64-musl-lto.tar.gz": { - "sha256": "b851b7c8b623a3f36e70d389768e97a184cf914b5157f660fd8dfc921d47e3d7", - "size": 223555281 + "sha256": "e31df77bd1b147d8d22bcd7502e0ae78165dda1180e465cccfc00f02f2f3f4b4", + "size": 223553290 } }, "provenance_files": { - "artifact-build.json": "a21c8fc6b53b7a6d0f6a700f655cf57903c95755077bf34fa1e3b1d034cc6df2", - "toolchain-build.json": "1b1d7bfb5ec5d70a93792e75e50ac61339dec021864e898c5c71a2aa025f5bb1", + "toolchain-image.json": "05d27ce6d37c90baff3465fee2151267d0bc707fa155d9d7fe4b6d0ca5be5f09", + "artifact-build.json": "5bd10e18a1ce60856ab551b33786593af8a9bc83ecaa94fb2f75579b9dd93872", "tool-versions.txt": "4792d68346e97d6f8bcf05124f904e68c9f56299be740663f00da9e1ddc96e9f", - "toolchain-image.json": "1793295ac1092cab438ff01d5a7142fb962cf84af64854cd376ab16158ef3b4d" + "toolchain-build.json": "efaeaf348fd9c9c689edf0e7ca652a5849960614ff8e9a52cec669f266fc944f" } }, { "schema_version": 1, - "source": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", "base": "5718a6ec579b98362ea7276a426deedcc6281ef5", "lane": { "label": "bun-webkit-windows-amd64-lto", @@ -2661,6 +2802,21 @@ "commit": "42ab38d705d4838748ccee77e7deb0e4e35515ee", "subject": "build(webkit): qualify complete rebased engine batch (#6)", "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "641c15f9283845195dd3520dddc1fbd668379350", + "subject": "perf(jsc): carry stack coordinate cache into rebased release (#9)", + "patch_sha256": "e1f1e01dc10efb3e448d6ec611d7e9a6a3622f9494b6a09d580b1f4bfa5cb57c" + }, + { + "commit": "c75925d9c51b8df1402320f9c472805a90ac6353", + "subject": "ci: qualify Windows ARM64 engine artifacts", + "patch_sha256": "160ba0c78e66588511288c5893d49dadd2b350c90c10851a7b3888e5e975ecf0" + }, + { + "commit": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "subject": "fix(jsc): correct ARM64 memory addition and qualify native tiers (#13)", + "patch_sha256": "61d94fa0e059f00dcd96e840a77ed8a178198f7db62a5739c3d60029d56e9dc9" } ], "recipe_sha256": { @@ -2685,7 +2841,7 @@ "macos-cross/mig": "efa2dc0b4a25c65efce82569f6818fd8c6646351446c62fcd7ce36dc3f5a503a", "macos-cross/xmac.mjs": "ba7af744715fec67c8baa3026f679dac75a4ccd30207437572664675f65bd45b" }, - "toolchain_image_id": "sha256:487bcf22d867b1d16cc02d3bf15dffe636c3cdb181c1724b3a12a832be1839d5", + "toolchain_image_id": "sha256:01ac4db049f8a5525e614ec0b7ddbbeaa8d78cc8037eb94650f4dc9474a1c605", "commands": { "base": [ "docker", @@ -2770,31 +2926,343 @@ "tool_versions": "Ubuntu clang version 23.1.2 (++20260910044232+069ef0e7cb36-1~exp1~20260910044242.70)\nTarget: x86_64-pc-linux-gnu\nThread model: posix\nInstalledDir: /usr/lib/llvm-23/bin\ncmake version 3.28.3\n\nCMake suite maintained and supported by Kitware (kitware.com/cmake).\n1.11.1", "docker_version": "Client: Docker Engine - Community\n Version: 28.0.4\n API version: 1.48\n Go version: go1.23.7\n Git commit: b8034c0\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Context: default\n\nServer: Docker Engine - Community\n Engine:\n Version: 28.0.4\n API version: 1.48 (minimum version 1.24)\n Go version: go1.23.7\n Git commit: 6430e49\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Experimental: false\n containerd:\n Version: v2.2.1\n GitCommit: dea7da592f5d1d2b7755e3a161be07f43fad8f75\n runc:\n Version: 1.3.4\n GitCommit: v1.3.4-0-gd6d73eb8\n docker-init:\n Version: 0.19.0\n GitCommit: de40ad0", "buildx_version": "github.com/docker/buildx v0.23.0 28c90eadc4c12cc78155ad59ca5f486220241d2a", - "workflow_run": "37254059740", + "workflow_run": "37317069743", "run_attempt": "1", - "elapsed_seconds": 695.2037205696106, + "elapsed_seconds": 1806.358342409134, "files": { "bun-webkit-windows-amd64-lto.tar.gz": { - "sha256": "af35f42d056d4b346fe83e01d8840f63c9303b1dc517e0545cb68e906fcc5af0", - "size": 665538527 + "sha256": "8481faabd1d67dc17f82684bc5e59417a38c6ea06c734a75157d8511c034d3c7", + "size": 665612707 + } + }, + "provenance_files": { + "tool-versions.txt": "9e25fc80a955f54e9ff61e7796df5c0b79d4bc6677fc47ee2357d99fdf5fa8e8", + "toolchain-build.json": "49affb69ae57d5ae786e2b01569b22b5823ca14754a45398083a1ecaa16b90bc", + "toolchain-image.json": "263d5a543b1d7cefcdccd8090074032eab5af4834027bde0f0b94eb9cbf5fc35", + "artifact-build.json": "35101618f08040328c1e60a95385c29c44b82f715e3e56344dc3fcc3862f0327" + } + }, + { + "schema_version": 1, + "source": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "base": "5718a6ec579b98362ea7276a426deedcc6281ef5", + "lane": { + "label": "bun-webkit-windows-arm64", + "runner": "linux-x64-gh", + "dockerfile": "Dockerfile.windows", + "package_os": "windows", + "package_cpu": "arm64", + "test": false, + "test_quick": false, + "image": "ghcr.io/openclaw/bun-webkit-build-env:windows-33415817992ee645", + "build_args": { + "WEBKIT_RELEASE_TYPE": "Release", + "LTO_FLAG": "", + "USE_MIMALLOC": "ON", + "USE_EXTERNAL_MIMALLOC": "ON", + "ICU_VERSION": "78.3", + "ICU_SHA256": "3a2e7a47604ba702f345878308e6fefeca612ee895cf4a5f222e7955fabfe0c0", + "WIN_ARCH": "arm64", + "WIN_TRIPLE_ARCH": "aarch64", + "MARCH_FLAG": "/clang:-march=armv8-a+crc", + "ICU_MARCH_FLAG": "-march=armv8-a+crc", + "ENABLE_SANITIZERS": "" + } + }, + "patches": [ + { + "commit": "49286a32907699162758f576e322a5897d08cbcb", + "subject": "fix(intl): preserve segment boundaries around surrogate pairs", + "patch_sha256": "c00e0c3c83191c04f0527d1920e10649774f1da1857fd26f7a483b12edb7885e" + }, + { + "commit": "5aa47f6979ce50d222ade62731035deb5821989d", + "subject": "fix(jsc): allow opt-in Proxy global prototypes", + "patch_sha256": "12077938391f390ec50bd926e171e7e0531963ba399c5006db481c7ca86e451f" + }, + { + "commit": "0ea86969847cbf6457e047eda34047fd2c378e86", + "subject": "fix(jsc): preserve module-loader async context", + "patch_sha256": "6d5e3ceadedd4a4f0f96b42d4f53b5589bca053f18ffd7b2a587d9330f22b0fa" + }, + { + "commit": "d4629bd619c57675b55534e9e1f7cc4a66d1ced0", + "subject": "feat(jsc): add per-VM worker heap and stack budgets", + "patch_sha256": "11847006c75b609004823a471e8a8a8b02755e99b590782769272195d92b069a" + }, + { + "commit": "ecc75afe1e4df1bc7d6949fb596872cfdf5b547d", + "subject": "ci: add immutable OpenClaw WebKit artifact pipeline", + "patch_sha256": "36980d4214adbd9bc4ae34cb2fcff988fcf4f9ab7b497d2663ab8aebb035d5f8" + }, + { + "commit": "2200e39644d22733a8aad5814837a6cea1eb0934", + "subject": "fix(ci): bind qualification binaries to the Bun source revision", + "patch_sha256": "411ebf8fcc84e7dfce128f7ee9a2bc8af6a696e8ff276ba3f617f5d4d829f067" + }, + { + "commit": "1ee09069fef6bdf26a899b3da06fc48714aa8a4d", + "subject": "ci: isolate batch-one artifact publication from later engine work", + "patch_sha256": "ec2f19cbd075d30517073388fc00d3ae5986ecfa25ca6811e5078da373d4fa8d" + }, + { + "commit": "72feb0be76fd1ac55f034dc979c0ad3c51d6278f", + "subject": "fix(jsc): give require(esm) its own namespace marker (#1)", + "patch_sha256": "7f0aa66d664843dd927b954227f01d97407b50273f6e681df4181aa0f70d7207" + }, + { + "commit": "594794f9d021d9debde5fe713b021e6e1978395e", + "subject": "feat(jsc): add byte-based heap allocation sampling (#2)", + "patch_sha256": "f7d840462b1ae22b8ada916e5b5777efc2afefb01cfed5f1d4ef6738dc4c5885" + }, + { + "commit": "aa631fd8d6a48a092d4fa8089ff1ff5b532353bc", + "subject": "fix(intl): preserve segment boundaries around surrogate pairs", + "patch_sha256": "c00e0c3c83191c04f0527d1920e10649774f1da1857fd26f7a483b12edb7885e" + }, + { + "commit": "297efd07d765336410671c36218dfe233dee5540", + "subject": "fix(jsc): allow opt-in Proxy global prototypes", + "patch_sha256": "12077938391f390ec50bd926e171e7e0531963ba399c5006db481c7ca86e451f" + }, + { + "commit": "fcda75076bdcffeef3973cdf1376cfb9cd22048e", + "subject": "fix(jsc): preserve module-loader async context", + "patch_sha256": "6d5e3ceadedd4a4f0f96b42d4f53b5589bca053f18ffd7b2a587d9330f22b0fa" + }, + { + "commit": "602011ef916a0b756d628e2f1ab2344f3e7a2594", + "subject": "feat(jsc): add per-VM worker heap and stack budgets", + "patch_sha256": "11847006c75b609004823a471e8a8a8b02755e99b590782769272195d92b069a" + }, + { + "commit": "6ec8002ae1e3388a5ec7984608bbac4063ef2e66", + "subject": "ci: add immutable OpenClaw WebKit artifact pipeline", + "patch_sha256": "36980d4214adbd9bc4ae34cb2fcff988fcf4f9ab7b497d2663ab8aebb035d5f8" + }, + { + "commit": "85513c6d6f4636d9378508d001079109057aabc8", + "subject": "fix(ci): bind qualification binaries to the Bun source revision", + "patch_sha256": "411ebf8fcc84e7dfce128f7ee9a2bc8af6a696e8ff276ba3f617f5d4d829f067" + }, + { + "commit": "010f0d898d24c488efcf8aef72932108de771a9e", + "subject": "ci: isolate batch-one artifact publication from later engine work", + "patch_sha256": "ec2f19cbd075d30517073388fc00d3ae5986ecfa25ca6811e5078da373d4fa8d" + }, + { + "commit": "8367b3b8ebf5901418b68b10d60f8f5f32385b4b", + "subject": "fix(jsc): give require(esm) its own namespace marker (#1)", + "patch_sha256": "7f0aa66d664843dd927b954227f01d97407b50273f6e681df4181aa0f70d7207" + }, + { + "commit": "25931e1f0fdec40b11f690067bd31f4f4190be90", + "subject": "feat(jsc): add byte-based heap allocation sampling (#2)", + "patch_sha256": "f7d840462b1ae22b8ada916e5b5777efc2afefb01cfed5f1d4ef6738dc4c5885" + }, + { + "commit": "3d5a89ec92c686406f23d7cbde49dc14f841818c", + "subject": "build(webkit): record the rebased upstream engine target", + "patch_sha256": "d29f543ef609bcf94b6dab4c1163117bc0676678955f607280e5a8af84a2d158" + }, + { + "commit": "e1d5f3504b4f7bfcb0499c8beea4db5bf6cf5f85", + "subject": "ci: qualify rebased WebKit with upstream-synced Bun", + "patch_sha256": "054da8412a0939c111668943a45b5241ce1d864e5322f5873944706d837be0e2" + }, + { + "commit": "c34e80468daad729d1c82de497920116579164c6", + "subject": "build(webkit): qualify rebased engine and upstream-synced Bun (#4)", + "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "e9d324af5e808691f1c1ad9874f0f07e80bbddd3", + "subject": "fix(jsc): retain syntax-selected stack source positions", + "patch_sha256": "a8e42625359f866f879dfcacb81fac5fc69242402a92fef8fe221c1006d2f054" + }, + { + "commit": "47ad5343455b112acfb54325738f302d269d4f65", + "subject": "ci: qualify stack positions and exact Bun sync compatibility", + "patch_sha256": "352e7334c6826c2a193a860c68babc47942668cb86b8d030b1df3757dec47ff1" + }, + { + "commit": "25bd0667289b4ee2c9bc35e087b1e7257fbfffd6", + "subject": "test(jsc): align promise stack goldens with syntax positions", + "patch_sha256": "bdc4c9790c952a2f967edbabe6345ff14d7cb8d8429156cccdaa1747d4971f0f" + }, + { + "commit": "6fceea99edb111efebf25032935b75cfe7bf3a7f", + "subject": "fix(jsc): track ArrayBuffer ownership and inspect worker memory (#5)", + "patch_sha256": "64a37019bbd69aae6716ec27c4f385bb42f883631977dd1424aa4c79150860a1" + }, + { + "commit": "228016b0eb4b9d80fc5148cf46a5f6c3c116b38f", + "subject": "build(webkit): qualify the complete rebased engine batch", + "patch_sha256": "6fc5f2c3afe8e80098f35da8bdb95f3e11ac3879907c2a6b5196fb7545e24de6" + }, + { + "commit": "85e51313e8ce7279c2700432f0d24dda78b56c8d", + "subject": "ci: pin the required namespace counterpart for Bun sync", + "patch_sha256": "646e6877930066ea6de645b543803c75cba0eb8cf2de25b3756bbc4f933a1d15" + }, + { + "commit": "8bf4642bf8f6f091f250ca79b05dc0ab3baf2ac7", + "subject": "test: align inspected error caret in sync qualification", + "patch_sha256": "4b2ddfd4a834d38a39402e6a59b982d634ac421315399fec1807ae2e61ec2223" + }, + { + "commit": "42ab38d705d4838748ccee77e7deb0e4e35515ee", + "subject": "build(webkit): qualify complete rebased engine batch (#6)", + "patch_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + { + "commit": "641c15f9283845195dd3520dddc1fbd668379350", + "subject": "perf(jsc): carry stack coordinate cache into rebased release (#9)", + "patch_sha256": "e1f1e01dc10efb3e448d6ec611d7e9a6a3622f9494b6a09d580b1f4bfa5cb57c" + }, + { + "commit": "c75925d9c51b8df1402320f9c472805a90ac6353", + "subject": "ci: qualify Windows ARM64 engine artifacts", + "patch_sha256": "160ba0c78e66588511288c5893d49dadd2b350c90c10851a7b3888e5e975ecf0" + }, + { + "commit": "f1e1ca1156c8cb3b468bec0e1989fbfa08899661", + "subject": "fix(jsc): correct ARM64 memory addition and qualify native tiers (#13)", + "patch_sha256": "61d94fa0e059f00dcd96e840a77ed8a178198f7db62a5739c3d60029d56e9dc9" + } + ], + "recipe_sha256": { + ".github/scripts/lanes.mjs": "a69a43b99d6bd98379f9bf2bcde76928788ab06fd114d3aa976342e87ea48125", + "Dockerfile": "444340335972f60f2ac3af4cf2d9404a1d7870571d17d5e0ad13540e2291e963", + "Dockerfile.macos": "dc457cc551d60e951394a28ec3b272180f397084f76d7a79ec7168e76006129c", + "Dockerfile.musl": "f66ba3898f2e66452b9d643929c989e261a6d8466b61f55c9f8e4e635954ec35", + "Dockerfile.windows": "66b6a6d02689558e9f9571c5ee05e4f91b4c860545666fe69cdac26d8a5d93b5", + "icu/compress-data.ts": "d01fe5b67691d5d6d96a9f66631bafec2049471318f71ac78ed49af9bdbfa93d", + "icu/keep-raw.txt": "5bc256dcef00b6d62e41e3311f02b73108f52b6c715823c887deb4834876b2ce", + "icu/source.json": "e36325676eca93b29751793fbdbc13846a24c775e1e137da5d35956e46158365", + "icu/udata-decompress-hook.patch": "039f68bafcb875f3e688f3461e8ec7924416e6006d517def1441ab8e4ae87c81", + "macos-cross/README.md": "dd1f9dbe1852e4b855c7f16a8a3c9b023c0db1af292de63384448c6969cf5b5d", + "macos-cross/mach/boolean.h": "55492e527046f7b12dc9830f400ceffed79dc1d42a7f9a72afd52ed7ab85ffea", + "macos-cross/mach/compat.h": "7936278356124c7f0768703c670e5c90a4e8b437616a23683fa7c067877b2b20", + "macos-cross/mach/kern_return.h": "55492e527046f7b12dc9830f400ceffed79dc1d42a7f9a72afd52ed7ab85ffea", + "macos-cross/mach/machine/vm_types.h": "55492e527046f7b12dc9830f400ceffed79dc1d42a7f9a72afd52ed7ab85ffea", + "macos-cross/mach/message.h": "55492e527046f7b12dc9830f400ceffed79dc1d42a7f9a72afd52ed7ab85ffea", + "macos-cross/mach/ndr.h": "55492e527046f7b12dc9830f400ceffed79dc1d42a7f9a72afd52ed7ab85ffea", + "macos-cross/mach/port.h": "55492e527046f7b12dc9830f400ceffed79dc1d42a7f9a72afd52ed7ab85ffea", + "macos-cross/mach/std_types.h": "55492e527046f7b12dc9830f400ceffed79dc1d42a7f9a72afd52ed7ab85ffea", + "macos-cross/mig": "efa2dc0b4a25c65efce82569f6818fd8c6646351446c62fcd7ce36dc3f5a503a", + "macos-cross/xmac.mjs": "ba7af744715fec67c8baa3026f679dac75a4ccd30207437572664675f65bd45b" + }, + "toolchain_image_id": "sha256:6d19ef8da1705666c50e348eb07b44018d3c646547431cbb4fe3db30fe96e4b6", + "commands": { + "base": [ + "docker", + "buildx", + "build", + "-f", + "Dockerfile.windows", + "--platform", + "linux/amd64", + "--progress=plain", + "--build-arg", + "WEBKIT_RELEASE_TYPE=Release", + "--build-arg", + "LTO_FLAG=", + "--build-arg", + "USE_MIMALLOC=ON", + "--build-arg", + "USE_EXTERNAL_MIMALLOC=ON", + "--build-arg", + "ICU_VERSION=78.3", + "--build-arg", + "ICU_SHA256=3a2e7a47604ba702f345878308e6fefeca612ee895cf4a5f222e7955fabfe0c0", + "--build-arg", + "WIN_ARCH=arm64", + "--build-arg", + "WIN_TRIPLE_ARCH=aarch64", + "--build-arg", + "MARCH_FLAG=/clang:-march=armv8-a+crc", + "--build-arg", + "ICU_MARCH_FLAG=-march=armv8-a+crc", + "--build-arg", + "ENABLE_SANITIZERS=", + "--target=base", + "--load", + "--tag", + "openclaw-webkit-toolchain:1b8878c46c6d814320d2cae2", + "--metadata-file", + "/home/runner/_work/_temp/lane/provenance/toolchain-build.json", + "." + ], + "artifact": [ + "docker", + "buildx", + "build", + "-f", + "Dockerfile.windows", + "--platform", + "linux/amd64", + "--progress=plain", + "--build-arg", + "WEBKIT_RELEASE_TYPE=Release", + "--build-arg", + "LTO_FLAG=", + "--build-arg", + "USE_MIMALLOC=ON", + "--build-arg", + "USE_EXTERNAL_MIMALLOC=ON", + "--build-arg", + "ICU_VERSION=78.3", + "--build-arg", + "ICU_SHA256=3a2e7a47604ba702f345878308e6fefeca612ee895cf4a5f222e7955fabfe0c0", + "--build-arg", + "WIN_ARCH=arm64", + "--build-arg", + "WIN_TRIPLE_ARCH=aarch64", + "--build-arg", + "MARCH_FLAG=/clang:-march=armv8-a+crc", + "--build-arg", + "ICU_MARCH_FLAG=-march=armv8-a+crc", + "--build-arg", + "ENABLE_SANITIZERS=", + "--build-context", + "base=docker-image://openclaw-webkit-toolchain:1b8878c46c6d814320d2cae2", + "--target=artifact", + "--output", + "type=local,dest=/home/runner/_work/_temp/lane/bun-webkit", + "--metadata-file", + "/home/runner/_work/_temp/lane/provenance/artifact-build.json", + "." + ] + }, + "tool_versions": "Ubuntu clang version 23.1.2 (++20260910044232+069ef0e7cb36-1~exp1~20260910044242.70)\nTarget: x86_64-pc-linux-gnu\nThread model: posix\nInstalledDir: /usr/lib/llvm-23/bin\ncmake version 3.28.3\n\nCMake suite maintained and supported by Kitware (kitware.com/cmake).\n1.11.1", + "docker_version": "Client: Docker Engine - Community\n Version: 28.0.4\n API version: 1.48\n Go version: go1.23.7\n Git commit: b8034c0\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Context: default\n\nServer: Docker Engine - Community\n Engine:\n Version: 28.0.4\n API version: 1.48 (minimum version 1.24)\n Go version: go1.23.7\n Git commit: 6430e49\n Built: Tue Mar 25 15:07:16 2025\n OS/Arch: linux/amd64\n Experimental: false\n containerd:\n Version: v2.2.1\n GitCommit: dea7da592f5d1d2b7755e3a161be07f43fad8f75\n runc:\n Version: 1.3.4\n GitCommit: v1.3.4-0-gd6d73eb8\n docker-init:\n Version: 0.19.0\n GitCommit: de40ad0", + "buildx_version": "github.com/docker/buildx v0.23.0 28c90eadc4c12cc78155ad59ca5f486220241d2a", + "workflow_run": "37317069743", + "run_attempt": "1", + "elapsed_seconds": 862.9645998477936, + "files": { + "bun-webkit-windows-arm64.tar.gz": { + "sha256": "9883a17e6a4a61e9df737ca9c772a1c03b5a157f8f6aca4a5c8e040be893afda", + "size": 367114876 } }, "provenance_files": { - "toolchain-build.json": "bb8bcccc977d7a76980eae301de902232d2e60c6f028cac96eb1033c1b598440", - "artifact-build.json": "6a467d425f31cb08d299c4d7a4b1f736acb95380bb094a5b14a3354a1d1e591c", "tool-versions.txt": "9e25fc80a955f54e9ff61e7796df5c0b79d4bc6677fc47ee2357d99fdf5fa8e8", - "toolchain-image.json": "2fa252d6d51f99181a3a73170ede4b14218b07c2fcd4fc924df797a1adaf4777" + "toolchain-build.json": "ddc8df319539799314260e06ffb2d788a5e2a2b11a4fca3bb3896dcf7b7ef6c3", + "toolchain-image.json": "8f546fdf207b72f52b8e44a1f2ba2d2e30e4d4da4927257ca8c4bbd379294968", + "artifact-build.json": "173d4a202834aa5d9c08c46f297c46e5397c5d271d818fa9e64c18ae528ca45f" } } ], "supporting_files": { "LICENSE-SOURCES.txt": { - "sha256": "4a3435cd8b5dbeea7a68faa1d9b315917eb29849018943a88201ccb5fa46b64f", + "sha256": "501a99ee9a404c0e604c7407997cfaab429c2058aa4be2867a74c00ed96597e2", "size": 26102 }, "provenance.tar.gz": { - "sha256": "a1bedace2ee9431653b39cead947391c3804872b5010ae57e989971952757bfc", - "size": 856881 + "sha256": "12b7cd6d7282b2cd01da5685c0102755ae71d00b1dd156aad440150a4814c38d", + "size": 915782 } } } diff --git a/scripts/openclaw-ci/tests.ts b/scripts/openclaw-ci/tests.ts index 7b5da596aef4..58922b1c76ba 100644 --- a/scripts/openclaw-ci/tests.ts +++ b/scripts/openclaw-ci/tests.ts @@ -45,6 +45,16 @@ export const darwinSmoke = [ "test/js/node/child_process/child-process-stdio.test.js", ]; +// The same Windows compatibility selection runs on x64 and ARM64. +export const windowsSmoke = [ + ...smoke, + ...broader, + "test/js/bun/plugin/plugin-resolved-key.test.ts", + "test/js/bun/plugin/plugins.test.ts", + "test/js/bun/resolve/import-meta-resolve.test.mjs", + "test/js/bun/resolve/import-meta.test.js", +]; + const webkitSensitive = [ "test/js/node/async_hooks/AsyncLocalStorage.test.ts", "test/js/node/worker_threads/worker_threads.test.ts", @@ -91,9 +101,13 @@ export function isTest(path: string): boolean { } export function selectTests(changed: string[], tracked: string[], nightly: boolean, platform = "linux"): string[] { - if (platform !== "linux" && platform !== "darwin") throw new Error(`Unsupported CI platform: ${platform}`); + if (platform !== "linux" && platform !== "darwin" && platform !== "windows") + throw new Error(`Unsupported CI platform: ${platform}`); const available = new Set(tracked); - const selected = new Set([...(platform === "darwin" ? darwinSmoke : smoke), ...(nightly ? broader : [])]); + const selected = new Set([ + ...(platform === "windows" ? windowsSmoke : platform === "darwin" ? darwinSmoke : smoke), + ...(nightly ? broader : []), + ]); const tests = tracked.filter(isTest); for (const path of changed) { if (path === "scripts/build/deps/webkit.ts" || path === "scripts/build/deps/webkit-artifacts.json") { @@ -144,11 +158,32 @@ function summary(text: string) { console.log(text); } +export function assertSelectedTestResults( + selected: readonly string[], + results: readonly { testPath: string; ok: boolean }[], + platform: string = process.platform, +): void { + // The runner reports native paths; selections come from Git with forward slashes. + const passed = new Set( + results + .filter(result => result.ok) + .map(result => (platform === "win32" ? result.testPath.replaceAll("\\", "/") : result.testPath)), + ); + for (const test of selected) { + if (!passed.has(test)) throw new Error(`Selected test did not pass (or was skipped by expectations): ${test}`); + } +} + if (import.meta.main) { const command = process.argv[2]; const selectionPath = "build/openclaw-ci/selected.json"; const resultsPath = "build/openclaw-ci/results.json"; - if (command === "select") { + if (command === "select-windows") { + const selected = selectTests([], git("ls-files", "-z", "test"), false, "windows"); + mkdirSync(dirname(selectionPath), { recursive: true }); + writeFileSync(selectionPath, JSON.stringify(selected, null, 2) + "\n"); + summary(`Windows compatibility selection: ${selected.length} files\n`); + } else if (command === "select") { const base = process.env.PR_BASE_SHA; const head = process.env.PR_HEAD_SHA; if (process.env.GITHUB_EVENT_NAME === "pull_request" && (!base || !head)) throw new Error("Missing PR commits"); @@ -179,11 +214,7 @@ if (import.meta.main) { if (result.error) throw result.error; if (result.status !== 0) process.exit(result.status ?? 1); const results: { testPath: string; ok: boolean }[] = JSON.parse(readFileSync(resultsPath, "utf8")); - for (const test of selected) { - if (!results.some(result => result.testPath === test && result.ok)) { - throw new Error(`Selected test did not pass (or was skipped by expectations): ${test}`); - } - } + assertSelectedTestResults(selected, results); } else if (command === "summary") { summary(`## Result\n\nBuild: **${process.env.BUILD_OUTCOME}**. Tests: **${process.env.TEST_OUTCOME}**.\n`); if (existsSync(resultsPath)) { @@ -199,6 +230,6 @@ if (import.meta.main) { if (process.env.TEST_OUTCOME === "success") throw new Error(message); } } else { - throw new Error("Usage: tests.ts select|test|summary"); + throw new Error("Usage: tests.ts select|select-windows|test|summary"); } } diff --git a/scripts/openclaw-release/package-windows.ps1 b/scripts/openclaw-release/package-windows.ps1 new file mode 100644 index 000000000000..1fd26c7060af --- /dev/null +++ b/scripts/openclaw-release/package-windows.ps1 @@ -0,0 +1,64 @@ +param( + [Parameter(Mandatory)][string]$Dist, + [Parameter(Mandatory)][long]$Mtime, + [Parameter(Mandatory)][ValidateSet('SignedRelease', 'UnsignedTest')][string]$Mode +) +$ErrorActionPreference = 'Stop' +$Dist = (Resolve-Path -LiteralPath $Dist).Path +$expectedSignerSubject = 'CN=OpenClaw Foundation, O=OpenClaw Foundation, L=Mill Valley, S=California, C=US' +$targets = @( + @{ Name = 'windows-x64'; Triplet = 'bun-windows-x64'; Machine = 0x8664 }, + @{ Name = 'windows-arm64'; Triplet = 'bun-windows-aarch64'; Machine = 0xaa64 } +) +$found = 0 +function Hash([string]$Path) { (Get-FileHash -Algorithm SHA256 -LiteralPath $Path).Hash.ToLowerInvariant() } +function Pack([string]$Directory) { + $root = Join-Path $Dist $Directory + $stream = [IO.File]::Open((Join-Path $Dist "$Directory.zip"), [IO.FileMode]::CreateNew) + $archive = [IO.Compression.ZipArchive]::new($stream, [IO.Compression.ZipArchiveMode]::Create) + try { + foreach ($file in (Get-ChildItem -LiteralPath $root -Recurse -File | Sort-Object FullName)) { + $relative = [IO.Path]::GetRelativePath($Dist, $file.FullName).Replace('\', '/') + $entry = $archive.CreateEntry($relative, [IO.Compression.CompressionLevel]::Optimal) + $entry.LastWriteTime = [DateTimeOffset]::FromUnixTimeSeconds($Mtime) + $inputStream = $file.OpenRead() + $outputStream = $entry.Open() + try { $inputStream.CopyTo($outputStream) } finally { $outputStream.Dispose(); $inputStream.Dispose() } + } + } finally { $archive.Dispose(); $stream.Dispose() } +} +foreach ($target in $targets) { + $triplet = $target.Triplet + if (-not (Test-Path -LiteralPath (Join-Path $Dist $triplet))) { + if ($Mode -eq 'SignedRelease') { throw "Missing release target $triplet" } + continue + } + $found++ + $executables = @((Join-Path $Dist "$triplet/bun.exe"), (Join-Path $Dist "$triplet-profile/bun-profile.exe")) + foreach ($exe in $executables) { + $bytes = [IO.File]::ReadAllBytes($exe) + $pe = [BitConverter]::ToInt32($bytes, 0x3c) + if ([BitConverter]::ToUInt16($bytes, $pe + 4) -ne $target.Machine) { throw "Wrong PE architecture: $exe" } + if ($Mode -eq 'SignedRelease') { + $signature = Get-AuthenticodeSignature -LiteralPath $exe + if ($signature.Status -ne 'Valid') { throw "$exe Authenticode signature was $($signature.Status)." } + if (-not $signature.SignerCertificate -or $signature.SignerCertificate.Subject -cne $expectedSignerSubject) { + throw "$exe has an unexpected signer subject." + } + if (-not $signature.TimeStamperCertificate) { throw "$exe has no timestamp certificate." } + } + } + Pack $triplet + Pack "$triplet-profile" + $record = @{ + authenticodeSigned = $Mode -eq 'SignedRelease' + testOnly = $Mode -eq 'UnsignedTest' + executableSha256 = Hash $executables[0] + profileExecutableSha256 = Hash $executables[1] + archiveSha256 = Hash (Join-Path $Dist "$triplet.zip") + profileArchiveSha256 = Hash (Join-Path $Dist "$triplet-profile.zip") + } + if ($Mode -eq 'SignedRelease') { $record.signerSubject = $expectedSignerSubject } + $record | ConvertTo-Json | Set-Content -Encoding utf8 (Join-Path $Dist "$($target.Name).signing.json") +} +if ($found -eq 0) { throw 'No Windows executables to package.' } diff --git a/scripts/openclaw-release/release.ts b/scripts/openclaw-release/release.ts index 3da44f94164c..a0c67a2f8743 100644 --- a/scripts/openclaw-release/release.ts +++ b/scripts/openclaw-release/release.ts @@ -22,6 +22,7 @@ import { spawnSync, type SpawnSyncOptions } from "node:child_process"; import { createHash } from "node:crypto"; import { appendFileSync, + cpSync, existsSync, lstatSync, mkdirSync, @@ -44,7 +45,8 @@ export type TargetName = | "linux-arm64" | "linux-x64-musl" | "linux-arm64-musl" - | "windows-x64"; + | "windows-x64" + | "windows-arm64"; export interface Target { name: TargetName; @@ -82,9 +84,12 @@ export const targets: Record = { runner: "ubuntu-24.04-arm", container: alpine, }), - "windows-x64": target("windows-x64", "windows", "x64", undefined, ["windows-sysroot"], false, { + "windows-x64": target("windows-x64", "windows", "x64", undefined, ["windows-sysroot"], true, { runner: "windows-2025", }), + "windows-arm64": target("windows-arm64", "windows", "arm64", undefined, ["windows-sysroot"], true, { + runner: "windows-11-arm", + }), }; function target( @@ -107,7 +112,7 @@ export const releaseTargets: readonly TargetName[] = (Object.keys(targets) as Ta ); /** The workflow's matrix entries. Darwin executables are smoke-tested from the signing job's artifact. */ -export function matrix(names: readonly TargetName[]) { +export function matrix(names: readonly TargetName[], publish = false) { return names.map(name => { const t = targets[name]; return { @@ -115,7 +120,12 @@ export function matrix(names: readonly TargetName[]) { triplet: t.triplet, runner: t.smoke.runner, container: t.smoke.container ?? "", - artifact: `${t.os === "darwin" ? "signed" : "build"}-${name}`, + artifact: + t.os === "windows" + ? publish + ? "signed-windows" + : "test-only-windows" + : `${t.os === "darwin" ? "signed" : "build"}-${name}`, }; }); } @@ -325,6 +335,17 @@ export function build(source: string, name: TargetName, out: string, mtime: numb join(buildDir, "bun-profile.linker-map"), join(buildDir, "features.json"), ].filter(existsSync); + if (t.os === "windows") { + // Windows release bytes are signed and verified on x64 before packaging or hashing. + for (const [directory, files] of [ + [t.triplet, [stripped]], + [`${t.triplet}-profile`, [profile, ...debugInfo]], + ] as const) { + mkdirSync(join(out, directory), { recursive: true }); + for (const file of files) cpSync(file, join(out, directory, basename(file)), { recursive: true }); + } + return; + } zip(join(out, `${t.triplet}.zip`), t.triplet, [stripped], mtime); zip(join(out, `${t.triplet}-profile.zip`), `${t.triplet}-profile`, [profile, ...debugInfo], mtime); writeFileSync( @@ -384,12 +405,15 @@ export function smoke(zipPath: string, name: TargetName, commit: string, webkitV // interpreter and still computes the right sum; numberOfDFGCompiles then reports 1000000, JSC's "no // JIT" answer. The sum of 7i for i < 1e5, mod 1000003, is 545003. `const { numberOfDFGCompiles } = require("bun:jsc"); + const { Database } = require("bun:sqlite"); + const db = new Database(":memory:"); + const sqlite = db.query("SELECT 42 AS answer").get().answer; db.close(); function f(n) { let s = 0; for (let i = 0; i < n; i++) s = (s + i * 7) % 1000003; return s; } let sum = 0; for (let round = 0; round < 50 && !(numberOfDFGCompiles(f) > 0); round++) for (let k = 0; k < 200; k++) sum = f(1e5); console.log(JSON.stringify({ revision: Bun.revision, version: Bun.version, webkit: process.versions.webkit, - platform: process.platform, arch: process.arch, sum: f(1e5), dfg: numberOfDFGCompiles(f) }))`, + platform: process.platform, arch: process.arch, sqlite, sum: f(1e5), dfg: numberOfDFGCompiles(f) }))`, ], {}, ), @@ -401,6 +425,7 @@ export function smoke(zipPath: string, name: TargetName, commit: string, webkitV arch: string; sum: number; dfg: number; + sqlite: number; }; const problems: string[] = []; if (facts.revision !== commit) problems.push(`Bun.revision is ${facts.revision}, expected ${commit}`); @@ -411,6 +436,7 @@ export function smoke(zipPath: string, name: TargetName, commit: string, webkitV problems.push(`runs as ${facts.platform}-${facts.arch}, expected ${platform}-${t.arch}`); } if (facts.sum !== 545003) problems.push(`the loop computed ${facts.sum}`); + if (facts.sqlite !== 42) problems.push(`SQLite probe returned ${facts.sqlite}`); if (!(facts.dfg > 0 && facts.dfg < 1000000)) problems.push(`the DFG JIT did not compile (numberOfDFGCompiles: ${facts.dfg})`); if (problems.length) throw new Error(`${name} smoke test failed:\n ${problems.join("\n ")}`); @@ -443,6 +469,46 @@ export interface ManifestInput { dist: string; /** TargetName → signing record (darwin only). Defaults to the linker's ad-hoc signature on darwin. */ signing: Partial>; + windowsSigning?: Partial>; + publish?: boolean; +} + +export const windowsSignerSubject = "CN=OpenClaw Foundation, O=OpenClaw Foundation, L=Mill Valley, S=California, C=US"; + +export interface WindowsSigning { + authenticodeSigned: boolean; + signerSubject?: string; + executableSha256: string; + profileExecutableSha256: string; + archiveSha256: string; + profileArchiveSha256: string; +} + +function windowsSigning( + input: ManifestInput, + name: TargetName, + archive: string, + executableSha256: string, + profile: string, +) { + const record = input.windowsSigning?.[name]; + if (input.publish && record?.authenticodeSigned !== true) + throw new Error(`${name}: release requires Authenticode signing`); + if (record?.authenticodeSigned === true) { + if (record.signerSubject !== windowsSignerSubject) + throw new Error(`${name}: unexpected Authenticode signer subject`); + const t = targets[name]; + if ( + record.executableSha256 !== executableSha256 || + record.archiveSha256 !== sha256File(archive) || + record.profileArchiveSha256 !== sha256File(profile) || + record.profileExecutableSha256 !== extractedDigest(profile, `${t.triplet}-profile/bun-profile.exe`).sha256 + ) { + throw new Error(`${name}: Authenticode receipt does not match packaged bytes`); + } + return { authenticodeSigned: true, signerSubject: record.signerSubject, testOnly: false }; + } + return { authenticodeSigned: false, testOnly: true }; } export function sha256File(path: string): string { @@ -461,6 +527,8 @@ export function manifest(input: ManifestInput) { existsSync(join(dist, `${targets[name].triplet}.zip`)), ); if (!names.length) throw new Error(`no release zips in ${dist}`); + if (input.publish && releaseTargets.some(name => !names.includes(name))) + throw new Error("published manifest must include every release target"); const assets = names.map(name => { const t = targets[name]; const archive = join(dist, `${t.triplet}.zip`); @@ -476,7 +544,11 @@ export function manifest(input: ManifestInput) { url: `${download}/${basename(archive)}`, size: statSync(archive).size, sha256: sha256File(archive), - executable: { path: `${t.triplet}/${t.exe}`, ...executable }, + executable: { + path: `${t.triplet}/${t.exe}`, + ...executable, + ...(t.os === "windows" ? windowsSigning(input, name, archive, executable.sha256, profile) : {}), + }, ...(existsSync(profile) ? { debugSymbols: { @@ -521,7 +593,7 @@ export function manifest(input: ManifestInput) { function minimumFor(t: Target): string { if (t.os === "darwin") return "macOS 13.0"; - if (t.os === "windows") return "Windows 10 1809"; + if (t.os === "windows") return t.arch === "arm64" ? "Windows 11 ARM64" : "Windows 10 1809"; const cpu = t.arch === "x64" ? "x86-64 with SSE4.2 (Nehalem)" : "ARMv8.0-A"; return t.abi === "musl" ? `musl libc with libstdc++ and libgcc, ${cpu}` : `glibc 2.17, ${cpu}`; } @@ -549,7 +621,12 @@ export function checksums(files: readonly string[]): string { export function releaseNotes(m: ReturnType): string { const rows = m.assets.map(a => { - const signing = a.signing ? ` ${a.signing.kind}${a.signing.notarized ? ", notarized" : ""} |` : " — |"; + const signing = + a.os === "windows" + ? ` ${a.executable.authenticodeSigned ? `Authenticode (${a.executable.signerSubject})` : "unsigned, test-only"} |` + : a.signing + ? ` ${a.signing.kind}${a.signing.notarized ? ", notarized" : ""} |` + : " — |"; return `| \`${a.target}\` | \`${a.name}\` | ${a.size.toLocaleString("en-US")} | \`${a.sha256}\` |${signing}`; }); const unsigned = m.assets.filter(a => a.signing && a.signing.kind !== "developer-id").map(a => `\`${a.target}\``); @@ -560,7 +637,7 @@ export function releaseNotes(m: ReturnType): string { m.repository + "`.", "", - "| Target | Archive | Bytes | SHA-256 | macOS signature |", + "| Target | Archive | Bytes | SHA-256 | Signature |", "| --- | --- | ---: | --- | --- |", ...rows, "", @@ -655,8 +732,19 @@ async function main(argv: string[]): Promise { if (values.publish && releaseTargets.some(name => !built.includes(name))) { throw new Error(`a published release has every release target: ${releaseTargets.join(", ")}`); } - output("matrix", JSON.stringify(matrix(built))); + output("matrix", JSON.stringify(matrix(built, values.publish))); output("darwin", String(built.some(name => targets[name].os === "darwin"))); + output("windows", String(built.some(name => targets[name].os === "windows"))); + output( + "windows-matrix", + JSON.stringify( + matrix( + built.filter(name => targets[name].os === "windows"), + values.publish, + ), + ), + ); + output("mtime", git(source, "log", "-1", "--format=%ct", facts.commit)); output("commit", facts.commit); output("tag", tag ?? tagFor(facts)); output("version", facts.version); @@ -684,10 +772,11 @@ async function main(argv: string[]): Promise { const out = resolve(values.out ?? dist); const facts = sourceFacts(source, values.commit ?? "HEAD"); const signing: ManifestInput["signing"] = {}; + const windowsSigning: NonNullable = {}; for (const file of readdirSync(dist).filter(f => f.endsWith(".signing.json"))) { - signing[file.slice(0, -".signing.json".length) as TargetName] = JSON.parse( - readFileSync(join(dist, file), "utf8"), - ); + const name = file.slice(0, -".signing.json".length) as TargetName; + const records = targets[name]?.os === "windows" ? windowsSigning : signing; + records[name] = JSON.parse(readFileSync(join(dist, file), "utf8")); } const m = manifest({ tag, @@ -697,6 +786,8 @@ async function main(argv: string[]): Promise { workflowRun: values["workflow-run"], dist, signing, + windowsSigning, + publish: values.publish, }); mkdirSync(out, { recursive: true }); writeFileSync(join(out, "manifest.json"), JSON.stringify(m, null, 2) + "\n"); diff --git a/test/internal/source-lints/openclaw-ci.test.ts b/test/internal/source-lints/openclaw-ci.test.ts index ddc6e4202e4c..b0f5db214420 100644 --- a/test/internal/source-lints/openclaw-ci.test.ts +++ b/test/internal/source-lints/openclaw-ci.test.ts @@ -3,7 +3,14 @@ import { bunExe, tempDir } from "harness"; import { execFileSync, spawnSync } from "node:child_process"; import { readFileSync, renameSync } from "node:fs"; import { join, resolve } from "node:path"; -import { broader, isTest, selectTests, smoke } from "../../../scripts/openclaw-ci/tests.ts"; +import { + assertSelectedTestResults, + broader, + isTest, + selectTests, + smoke, + windowsSmoke, +} from "../../../scripts/openclaw-ci/tests.ts"; const tracked = execFileSync("git", ["ls-files", "-z", "test"], { encoding: "utf8" }).split("\0").filter(Boolean); @@ -12,6 +19,33 @@ test("PR and nightly smoke lists exist and nightly includes every PR smoke file" expect(selectTests([], tracked, true)).toEqual([...smoke, ...broader].sort()); }); +test("both Windows architectures use the complete Windows compatibility selection", () => { + expect(selectTests([], tracked, false, "windows")).toEqual([...windowsSmoke].sort()); + expect(selectTests([], tracked, true, "windows")).toEqual([...windowsSmoke].sort()); + expect(windowsSmoke).toHaveLength(29); + for (const file of [...smoke, ...broader]) expect(windowsSmoke).toContain(file); + expect(windowsSmoke).toContain("test/js/bun/resolve/import-meta.test.js"); +}); + +test("native Windows result paths prove coverage without admitting failed or missing tests", () => { + const selected = ["test/js/node/fs/fs.test.ts", "test/js/node/process/process.test.js"]; + const results = selected.map(testPath => ({ testPath: testPath.replaceAll("/", "\\"), ok: true })); + expect(() => assertSelectedTestResults(selected, results, "win32")).not.toThrow(); + expect(() => assertSelectedTestResults(selected, results.slice(1), "win32")).toThrow(selected[0]); + expect(() => assertSelectedTestResults(selected, [{ ...results[0]!, ok: false }, results[1]!], "win32")).toThrow( + selected[0], + ); + // Backslashes remain literal filename characters on POSIX. + expect(() => assertSelectedTestResults(selected, results, "linux")).toThrow(selected[0]); + expect(() => + assertSelectedTestResults( + selected, + selected.map(testPath => ({ testPath, ok: true })), + "linux", + ), + ).not.toThrow(); +}); + test("macOS selection includes file, directory, recursive, process and child-process coverage", () => { const selected = selectTests([], tracked, false, "darwin"); expect(selected).toContain("test/js/node/watch/fs.watch.test.ts"); diff --git a/test/internal/source-lints/openclaw-release.test.ts b/test/internal/source-lints/openclaw-release.test.ts index ffd408c44b00..543c4faeb78f 100644 --- a/test/internal/source-lints/openclaw-release.test.ts +++ b/test/internal/source-lints/openclaw-release.test.ts @@ -26,9 +26,11 @@ import { tagMismatches, targets, webkitTagPart, + windowsSignerSubject, zip, type SourceFacts, type TargetName, + type WindowsSigning, } from "../../../scripts/openclaw-release/release.ts"; const facts: SourceFacts = { @@ -72,7 +74,25 @@ test("the zips carry upstream's artifact names", () => { const cfg = { os: t.os, arch: t.buildArch, abi: t.os === "linux" ? t.abi : undefined } as Config; expect(t.triplet).toBe(computeBunTriplet(cfg)); } - expect(releaseTargets).toEqual(["darwin-arm64", "darwin-x64", "linux-x64", "linux-arm64"]); + expect(releaseTargets).toEqual([ + "darwin-arm64", + "darwin-x64", + "linux-x64", + "linux-arm64", + "windows-x64", + "windows-arm64", + ]); + expect(matrix(["windows-x64", "windows-arm64"]).map(t => t.artifact)).toEqual([ + "test-only-windows", + "test-only-windows", + ]); + expect(matrix(["windows-arm64"], true)[0]).toEqual({ + target: "windows-arm64", + triplet: "bun-windows-aarch64", + runner: "windows-11-arm", + container: "", + artifact: "signed-windows", + }); expect(matrix(["darwin-x64", "linux-arm64"])).toEqual([ { target: "darwin-x64", @@ -91,6 +111,57 @@ test("the zips carry upstream's artifact names", () => { ]); }); +test("Windows manifest binds signature receipts to final archive and executable bytes", () => { + using dir = tempDir("openclaw-windows-manifest", {}); + const dist = String(dir); + const records: Record = {}; + for (const name of releaseTargets) { + const t = targets[name]; + const file = join(dist, t.exe); + writeFileSync(file, `${name} executable`); + zip(join(dist, `${t.triplet}.zip`), t.triplet, [file], 1790353014); + if (t.os !== "windows") continue; + const profile = join(dist, "bun-profile.exe"); + writeFileSync(profile, `${name} profile executable`); + zip(join(dist, `${t.triplet}-profile.zip`), `${t.triplet}-profile`, [profile], 1790353014); + records[name] = { + authenticodeSigned: true, + signerSubject: windowsSignerSubject, + executableSha256: sha256File(file), + profileExecutableSha256: sha256File(profile), + archiveSha256: sha256File(join(dist, `${t.triplet}.zip`)), + profileArchiveSha256: sha256File(join(dist, `${t.triplet}-profile.zip`)), + }; + } + const input = { tag: tagFor(facts), repository: "openclaw/bun", facts, dist, signing: {} }; + const unsigned = manifest(input).assets.filter(a => a.os === "windows"); + expect(unsigned.map(a => [a.executable.authenticodeSigned, a.executable.testOnly])).toEqual([ + [false, true], + [false, true], + ]); + expect(() => manifest({ ...input, publish: true })).toThrow("release requires Authenticode"); + const signed = manifest({ ...input, windowsSigning: records, publish: true }); + expect( + signed.assets + .filter(a => a.os === "windows") + .map(a => [a.executable.authenticodeSigned, a.executable.signerSubject, a.executable.testOnly]), + ).toEqual([ + [true, windowsSignerSubject, false], + [true, windowsSignerSubject, false], + ]); + for (const key of ["executableSha256", "profileExecutableSha256", "archiveSha256", "profileArchiveSha256"]) { + const changed = { ...records, "windows-arm64": { ...records["windows-arm64"]!, [key]: "0".repeat(64) } }; + expect(() => manifest({ ...input, windowsSigning: changed, publish: true })).toThrow("receipt does not match"); + } + expect(() => + manifest({ + ...input, + windowsSigning: { ...records, "windows-arm64": { ...records["windows-arm64"]!, signerSubject: "CN=Other" } }, + publish: true, + }), + ).toThrow("unexpected Authenticode signer"); +}); + test("the upstream build image still has every section the pipeline provisions", () => { using dir = tempDir("openclaw-release-image", {}); const image = images.find(image => imageKey(image) === "linux-aarch64-debian")!; diff --git a/test/internal/source-lints/windows-cross-config.test.ts b/test/internal/source-lints/windows-cross-config.test.ts index bbc87aeb09e3..ed86b902d0a4 100644 --- a/test/internal/source-lints/windows-cross-config.test.ts +++ b/test/internal/source-lints/windows-cross-config.test.ts @@ -14,7 +14,7 @@ import { describe, expect, test } from "bun:test"; import { isWindows } from "harness"; import { resolveConfig, type Config, type PartialConfig, type Toolchain } from "../../../scripts/build/config.ts"; -import { webkit } from "../../../scripts/build/deps/webkit.ts"; +import { webkit, WEBKIT_MANIFEST } from "../../../scripts/build/deps/webkit.ts"; import { computeFlags } from "../../../scripts/build/flags.ts"; import { rustTarget } from "../../../scripts/build/rust.ts"; @@ -140,9 +140,17 @@ describe.skipIf(isWindows)("Windows cross-compile LTO config (non-windows host)" expect(def.url).toContain("bun-webkit-windows-amd64-lto.tar.gz"); expect(def.destDir).toEndWith(`webkit-sha256-${def.sha256}`); - // The fork publishes Windows x64 LTO; other Windows variants must fail closed. + // The fork publishes Windows x64 LTO; x64 without LTO must still fail closed. expect(webkit.source(resolveWindowsCross({ lto: false })).kind).toBe("unavailable"); - expect(webkit.source(resolveWindowsCross({ arch: "aarch64" })).kind).toBe("unavailable"); + }); + + test("ARM64 selects the non-LTO WebKit prebuilt with a digest-keyed cache dir", () => { + const arm64 = webkit.source(resolveWindowsCross({ arch: "aarch64", lto: true })); + if (arm64.kind !== "prebuilt") throw new Error(`expected prebuilt WebKit source, got ${arm64.kind}`); + const artifact = WEBKIT_MANIFEST.artifacts["bun-webkit-windows-arm64.tar.gz"]!; + expect(arm64.url).toBe(artifact.url); + expect(arm64.sha256).toBe(artifact.sha256); + expect(arm64.destDir).toEndWith(`webkit-sha256-${artifact.sha256}`); }); test("rust side targets pc-windows-msvc triples", () => { diff --git a/test/js/node/process/process.test.js b/test/js/node/process/process.test.js index c22195085e94..376cb227da8e 100644 --- a/test/js/node/process/process.test.js +++ b/test/js/node/process/process.test.js @@ -3149,35 +3149,55 @@ setImmediate(() => parentPort.postMessage("worker-warned:" + warned));`, }); it("delete process.env.TZ invalidates existing Date instances", async () => { + // The runner need not be in UTC. Observe the same TZ-free startup zone as the fixture. + const defaultEnv = { ...bunEnv }; + for (const key of Object.keys(defaultEnv)) { + if (key.toUpperCase() === "TZ") delete defaultEnv[key]; + } + await using control = Bun.spawn({ + cmd: ["node", "-p", 'new Date("2024-01-15T12:00:00Z").getHours()'], + env: defaultEnv, + stdout: "pipe", + stderr: "pipe", + }); + const [controlOut, controlErr, controlExit] = await Promise.all([ + control.stdout.text(), + control.stderr.text(), + control.exited, + ]); + expect(controlOut.trim()).toMatch(/^(?:[0-9]|1[0-9]|2[0-3])$/); + expect({ stderr: controlErr, exitCode: controlExit }).toEqual({ stderr: "", exitCode: 0 }); + const defaultHour = Number(controlOut.trim()); + // A stale Date cache must also fail when the host is already in New York. + const overrideZone = defaultHour === 7 ? "Asia/Tokyo" : "America/New_York"; + const overrideHour = defaultHour === 7 ? 21 : 7; await using proc = Bun.spawn({ cmd: [ bunExe(), "-e", `const d = new Date("2024-01-15T12:00:00Z"); - process.env.TZ = "America/New_York"; - const ny = d.getHours(); + process.env.TZ = ${JSON.stringify(overrideZone)}; + const zoned = d.getHours(); delete process.env.TZ; const afterDelete = d.getHours(); const has = "TZ" in process.env; // set-after-delete must still fire the timezone side effect: Node's // RealEnvStore::Set name-matches TZ on every write, not via a // once-installed accessor. - process.env.TZ = "America/New_York"; + process.env.TZ = ${JSON.stringify(overrideZone)}; const afterReSet = d.getHours(); - console.log(JSON.stringify({ ny, afterDelete, has, afterReSet }));`, + console.log(JSON.stringify({ zoned, afterDelete, has, afterReSet }));`, ], - env: { ...bunEnv, TZ: "UTC" }, + env: defaultEnv, stdout: "pipe", stderr: "pipe", }); const [stdout, stderr, exitCode] = await Promise.all([proc.stdout.text(), proc.stderr.text(), proc.exited]); - // NY is UTC-5 in January; after delete the override is cleared so getHours - // reverts to the UTC start value (12) and the property is gone. expect({ ...JSON.parse(stdout), exitCode }).toEqual({ - ny: 7, - afterDelete: 12, + zoned: overrideHour, + afterDelete: defaultHour, has: false, - afterReSet: 7, + afterReSet: overrideHour, exitCode: 0, }); });