Recover Flow 9.1.0 publication from the sealed artifact - #134
Conversation
The tag workflow repacked file modes differently on GitHub and stopped before publication. A manual dispatch on main restores the sealed qualified tarball after comparing rebuilt package contents, then reuses the release record and publication convergence with pinned tag and ancestry checks.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Recovery now rechecks tag ancestry even when main fast-forwards after npm publication. Only the exact checkout equality relaxes for the final GitHub release update.
|
Independent read-only review of current head The recovery remains pinned to annotated tag object Notes: the private Actions release-state artifact uploads before the runtime ref proof. Tests cover the recovery predicate and durable mode guard, while the exact restore and live Git ref proof were exercised locally. A real OIDC publication remains untested until the guarded workflow runs. |
The
v9.1.0tag workflow stopped before publication. GitHub's checkout packed files with mode644, while the qualified tarball contains group-writable packed files; the payload is the same, but the tarball hash differs. Reproducing the runner's file modes locally produced its exact SHA-173d0183b87171d49ed7050b1911a226b902887cf.This adds a one-time
workflow_dispatchrecovery path to the existingrelease.yml, preserving its npm trusted-publisher workflow identity and the immutable tag. The recovery path rebuilds the package, compares its unpacked content with the committed sealed artifact, restores the exact qualified tarball SHA-2560b7f7a66bf1910b5d0da3a235f891d532b4aa352a2dbd25e398325c18e051b24, and runs strict release evidence checks. Publication still uses the existing release record, GitHub/npm reconciliation, and persisted receipts. Before publication mutations it verifies a dispatch from current main, the pinned annotated tag object and commit, and tag ancestry. The private Actions release-state artifact is uploaded before the runtime ref proof so a failed run can retain its record. The ordinary tag-push path is unchanged.Validation: actionlint passed; the restore step turned a mode-different tarball into the exact qualified bytes; the real local tag/main ref proof passed; strict release metadata remained
VERIFIEDat 38/38; and the clean-worktree push preflight passed 1,614 tests with no failures. This PR does not dispatch recovery or publish.