Skip to content

fix(release): gate Windows publication on signing configuration - #132

Merged
steipete merged 1 commit into
mainfrom
fix/optional-signed-windows-releases
Oct 5, 2026
Merged

steipete merged 1 commit into
mainfrom
fix/optional-signed-windows-releases

Conversation

@steipete

@steipete steipete commented Oct 5, 2026 •

Copy link
Copy Markdown

Publishing currently requires six targets, so missing Azure signing configuration blocks Darwin/Linux prereleases too. Make Windows publication an explicit, default-off repository opt-in while preserving the rule that unsigned Windows binaries are never published.

The plan job captures OPENCLAW_RELEASE_WINDOWS_SIGNED once and enables it only for the literal value true. Planning and manifest assembly share the resulting target policy: four Darwin/Linux targets by default; all six targets, both Windows signature receipts and the existing signer/hash checks when enabled. An off-mode manifest rejects Windows archives, including orphan profile archives, before the workflow can upload them. PR and non-publishing dry runs retain all six default targets and both test-only Windows compatibility lanes.

The release guide documents Azure setup and the federated credential subject repo:openclaw/bun:environment:release-signing. The manifest schema and consumer pins work with both shapes. This PR changes no repository variable, secret, environment, Azure resource or release tag. This is fork-specific release policy following #128; upstream search found no applicable release-switch fix.

Validation on 326b7aa663a25d127413587b635ad05336fdb53d:

  • Final Codex P2 review with ultrafast service: scoped-clean. Release tooling: 9 tests / 91 assertions; full source-lints: 202 tests / 515 assertions; actionlint, Prettier, JavaScript lint and build/CI-script typechecks pass. The actual Plan shell accepts only lowercase true among empty/false/true/True/TRUE/1. Baseline 695dda4942 rejects four-target publication; the candidate accepts both manifest shapes.
  • Native fork run 37372144833: Linux 16/16 and Darwin 12/12 result rows, with every selected file present, including release-tooling tests. Tested merge b171816fa803c16a40aff154460b4b71df5a7041 has exactly the reviewed head's tree. Source and JavaScript lint CI also passed after infrastructure retries; format passed.
  • Standard Windows dry run 37372159644, first attempt, exact source/head: x64 and ARM64 each pass 31/31 result rows (29 selected files plus dependency checks), both native smokes and manifest assembly pass. Downloaded archive/executable/profile hashes, source and WebKit identity, PE architectures and test-only flags were independently verified. Publishing was disabled.
  • Unmodified OpenClaw pin projections handle both generated shapes; actual Tauri admission rejects missing Windows entries. Its unchanged staging/admission suite passes 22 tests, including absent/unsigned Windows, both signed architectures, identity and checksum failures. No OpenClaw source change is needed.

CI context: GitHub Actions reported a major outage. The full PR release run's Plan job was cancelled twice without a runner or executed steps; those runs do not provide build evidence. The successful standard Windows run above provides the required Windows gates. A separately reviewed, non-landing qualification branch using existing Blacksmith Linux runners also passed both builds/smokes and x64 compatibility, but its ARM64 run hit the unchanged fs.createReadStream offset test's 100 ms callback deadline at 522 ms. That failed run is retained and is not the qualifying result. Runtime, test, harness, build, runner, selection and lockfile inputs are identical to 695dda4942; no assertions, deadlines or test selection changed, and this PR does not claim to fix that timeout. The unrelated duplicate-PR bot failed before review because its credentials are not configured.

@steipete
steipete merged commit 667c4ab into main Oct 5, 2026
36 of 41 checks passed
@steipete
steipete deleted the fix/optional-signed-windows-releases branch October 5, 2026 21:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant