Skip to content

fix: normalize complete native tool bundles - #47

Merged
Soheilbz merged 1 commit into
mainfrom
codex/fix-mafft-bundle-readability
Sep 13, 2026
Merged

Soheilbz merged 1 commit into
mainfrom
codex/fix-mafft-bundle-readability

Conversation

@Soheilbz

@Soheilbz Soheilbz commented Sep 13, 2026 •

Copy link
Copy Markdown
Owner

Root cause

The v1.0.4 fix normalized only the top-level MAFFT launcher. Inspection of its production image as UID 10001 found 64 nested MAFFT files unreadable or non-executable, including helpers under mafftdir/libexec and mafftdir/bin. The release builder did not run its toolchain smoke as the service UID before publishing the OCI bundle.

Changes

  • Normalize complete extracted BLAST and MAFFT runtime trees for service read/traverse access while preserving executable semantics and removing group/other write plus setuid/setgid/sticky bits. Original upstream archive SHA-256 pins remain unchanged; the normalized MAFFT tree digest is recorded after normalization.
  • Add nested-file/directory permission regression coverage, and smoke API and runner images as UID 10001 with networking disabled before release assets are published.
  • Prepare the required immutable SemVer patch release v1.0.5 and regenerate release evidence/manifests.

Verification

  • scripts/check-linux-bootstrap.py: PASS
  • scripts/qualify-source.py --no-write: PASS
  • Release manifests, source attestation, current static audit, SBOM, and verify-release.py: PASS
  • CI scope is targeted release contracts only. Production image builds and service-UID smoke run once in the official v1.0.5 release workflow after merge.

@Soheilbz
Soheilbz merged commit e4786f9 into main Sep 13, 2026
11 checks passed
@Soheilbz
Soheilbz deleted the codex/fix-mafft-bundle-readability branch September 13, 2026 13:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant