Skip to content

Recover Flow 9.1.0 publication from the sealed artifact - #134

Merged
vriesd merged 2 commits into
mainfrom
fix/release-9-1-0-exact-artifact-recovery
Sep 27, 2026
Merged

vriesd merged 2 commits into
mainfrom
fix/release-9-1-0-exact-artifact-recovery

Conversation

@vriesd

@vriesd vriesd commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

The v9.1.0 tag workflow stopped before publication. GitHub's checkout packed files with mode 644, while the qualified tarball contains group-writable packed files; the payload is the same, but the tarball hash differs. Reproducing the runner's file modes locally produced its exact SHA-1 73d0183b87171d49ed7050b1911a226b902887cf.

This adds a one-time workflow_dispatch recovery path to the existing release.yml, preserving its npm trusted-publisher workflow identity and the immutable tag. The recovery path rebuilds the package, compares its unpacked content with the committed sealed artifact, restores the exact qualified tarball SHA-256 0b7f7a66bf1910b5d0da3a235f891d532b4aa352a2dbd25e398325c18e051b24, and runs strict release evidence checks. Publication still uses the existing release record, GitHub/npm reconciliation, and persisted receipts. Before publication mutations it verifies a dispatch from current main, the pinned annotated tag object and commit, and tag ancestry. The private Actions release-state artifact is uploaded before the runtime ref proof so a failed run can retain its record. The ordinary tag-push path is unchanged.

Validation: actionlint passed; the restore step turned a mode-different tarball into the exact qualified bytes; the real local tag/main ref proof passed; strict release metadata remained VERIFIED at 38/38; and the clean-worktree push preflight passed 1,614 tests with no failures. This PR does not dispatch recovery or publish.

The tag workflow repacked file modes differently on GitHub and stopped before publication. A manual dispatch on main restores the sealed qualified tarball after comparing rebuilt package contents, then reuses the release record and publication convergence with pinned tag and ancestry checks.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T07:39:13.472119Z 2f81bda PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Recovery now rechecks tag ancestry even when main fast-forwards after npm publication. Only the exact checkout equality relaxes for the final GitHub release update.
@vriesd

vriesd commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Independent read-only review of current head f9b07649: PASS+NOTES.

The recovery remains pinned to annotated tag object c629deb583185b977908f2203fab0caee69484a9, tag commit 727308d2ccd5761f03024341328cff06887ebae1, and sealed artifact SHA-256 0b7f7a66bf1910b5d0da3a235f891d532b4aa352a2dbd25e398325c18e051b24. The reviewer verified the existing tag-push path remains intact. The review-driven fix now checks tag ancestry against current main before each publication mutation; after npm succeeds it permits a main fast-forward while retaining that ancestry check.

Notes: the private Actions release-state artifact uploads before the runtime ref proof. Tests cover the recovery predicate and durable mode guard, while the exact restore and live Git ref proof were exercised locally. A real OIDC publication remains untested until the guarded workflow runs.

@vriesd
vriesd merged commit d9f9688 into main Sep 27, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants