Skip to content

ci(authoring): require native and packed acceptance - #172

Draft
777genius wants to merge 2 commits into
feat/authoring-private-npm-pairfrom
ci/authoring-packed-proof
Draft

ci(authoring): require native and packed acceptance#172
777genius wants to merge 2 commits into
feat/authoring-private-npm-pairfrom
ci/authoring-packed-proof

Conversation

@777genius

@777genius 777genius commented Sep 6, 2026

Copy link
Copy Markdown
Owner

Packed installer acceptance previously appeared in ordinary native discovery and skipped without its separate input, making the strict native gate fail. Move only that acceptance test behind an explicit packedci tag, retain the source harness on all four native hosts, and add a separate Linux amd64 job that builds the same-SHA candidate, packs both npm packages, runs 741 invocations, seals ten generated projects and checks thirty injected installer plans.

Depends on #170. The always-run aggregate requires native and packed success. Missing configuration, skipped or absent tests, incomplete evidence and identity mismatches fail. Existing Windows and writable macOS gates remain blocking; this PR does not establish release eligibility or publication. No YAML capabilities or production engine code are removed.

Independent medium review of ad08bff found no actionable new defects. All 28 structural tests and workflow controls passed. Actual new-SHA CI remains required; prior 070663 private Linux proof is not acceptance for this commit. Repository required-check settings are not configured by this workflow.

Scope: 1,033 additions and 110 deletions across ten files, including the mechanical Go test move. Native execution, artifact retention and packed runtime timings will be evaluated from this PR run. Keep draft until that evidence is reviewed, and retain upstream holds even if packed passes.

The first hosted workflow attempt (34060802874) was rejected before any test job: job-level env cannot reference runner.temp. Commit 9c8a779 moves path publication to the first runtime step through GITHUB_ENV and adds a regression control. Twelve focused tests passed; the original workflow is rejected by the new control. GitHub accepted the corrected workflow in run 34061130958 and created all four native jobs plus packed Linux amd64. Their execution results remain pending. This concrete defect was missed by the earlier structural review.

Run 34061130958 at 9c8a779 is terminal: packed Linux amd64, Linux amd64/arm64 and Windows amd64 jobs passed. Windows arm64 failed TestWindowsBootstrapStages/native-stages with source_changed while remembering the tmp directory; the aggregate correctly failed. All five source-harness leaves passed on all four hosts. Native artifacts were inspected. Packed artifact download/audit remains in progress, so the job result is not yet an independent artifact audit. No unchanged rerun or upstream hold waiver is requested.

Independent archived packed audit accepted (2026-09-08): this supersedes the earlier pending-audit note for exact head 9c8a779. The hosted reviewer independently matched original GitHub artifact 9997547467 to SHA256 28a28bf829ee047f76dd1c63eac553057a4ec99e1d664a7ea2fad6affcc52e97, all 7652 indexed files, frozen source and embedded build identities, both npm packs/SRI, raw phase logs, 741 wrapper invocations, ten projects, seals and 30 distinct injected installer plans. Archived Linux packed evidence is accepted with no code change or unchanged rerun needed.

This accepts only packed job 101561748483 in run 34061130958 attempt 1. The native+packed aggregate remains failed; current-main integration, supported-platform qualification and executable release remain unproven. Original hosted paths/tools are absent from the relocated archive, so the original checker was not rerun with rewritten provenance. Private release/platform/attestation flags remain false. Review receipt SHA256: ed49aee0f5f16db6e69686d3e533e2990566d70b1c77a38b98ebe9dc76fb7ea0.

@coderabbitai

coderabbitai Bot commented Sep 6, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant