Repository navigation
fix(release): gate Windows publication on signing configuration - #132
Merged
Merged
Conversation
This was referenced Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Publishing currently requires six targets, so missing Azure signing configuration blocks Darwin/Linux prereleases too. Make Windows publication an explicit, default-off repository opt-in while preserving the rule that unsigned Windows binaries are never published.
The plan job captures
OPENCLAW_RELEASE_WINDOWS_SIGNEDonce and enables it only for the literal valuetrue. Planning and manifest assembly share the resulting target policy: four Darwin/Linux targets by default; all six targets, both Windows signature receipts and the existing signer/hash checks when enabled. An off-mode manifest rejects Windows archives, including orphan profile archives, before the workflow can upload them. PR and non-publishing dry runs retain all six default targets and both test-only Windows compatibility lanes.The release guide documents Azure setup and the federated credential subject
repo:openclaw/bun:environment:release-signing. The manifest schema and consumer pins work with both shapes. This PR changes no repository variable, secret, environment, Azure resource or release tag. This is fork-specific release policy following #128; upstream search found no applicable release-switch fix.Validation on
326b7aa663a25d127413587b635ad05336fdb53d:trueamong empty/false/true/True/TRUE/1. Baseline695dda4942rejects four-target publication; the candidate accepts both manifest shapes.b171816fa803c16a40aff154460b4b71df5a7041has exactly the reviewed head's tree. Source and JavaScript lint CI also passed after infrastructure retries; format passed.CI context: GitHub Actions reported a major outage. The full PR release run's Plan job was cancelled twice without a runner or executed steps; those runs do not provide build evidence. The successful standard Windows run above provides the required Windows gates. A separately reviewed, non-landing qualification branch using existing Blacksmith Linux runners also passed both builds/smokes and x64 compatibility, but its ARM64 run hit the unchanged
fs.createReadStreamoffset test's 100 ms callback deadline at 522 ms. That failed run is retained and is not the qualifying result. Runtime, test, harness, build, runner, selection and lockfile inputs are identical to695dda4942; no assertions, deadlines or test selection changed, and this PR does not claim to fix that timeout. The unrelated duplicate-PR bot failed before review because its credentials are not configured.