Skip to content

fix: qualify runtime and release publication - #48

Open
Soheilbz wants to merge 3 commits into
mainfrom
codex/fix-mafft-runtime-contract
Open

Soheilbz wants to merge 3 commits into
mainfrom
codex/fix-mafft-runtime-contract

Conversation

@Soheilbz

@Soheilbz Soheilbz commented Sep 13, 2026 •

Copy link
Copy Markdown
Owner

Root causes fixed

  • The pinned MAFFT launcher requires Bash, but the API/runner scientific runtime had only BusyBox. Bash now comes from the existing pinned Debian snapshot and is included only in the scientific runtime; the migrator stays minimal.
  • Native provisioning accidentally returned the later PrimerPooler archive as MAFFT provenance. The archive identities are distinct and a focused regression covers this.
  • Production deployment previously started when a release was already published, so a failing image smoke could leave a public release without deployment assets. The workflow now accepts only an exact stable tag, verifies checkout identity, keeps the release draft during build and service-UID smoke, uploads the verified bundle, and publishes only after all gates pass.
  • The host was still running an obsolete storage guard that reserved 31 GiB on a 48 GiB VM and could stop the runner. Every normal bootstrap now installs the current 20 GiB policy before image operations and restarts the timer so existing schedules update immediately.
  • Current release notes and qualification docs are concise; historical version detail remains in the changelog. Capability truth checks use authoritative product docs instead of forcing unrelated historical prose into every patch release.

Focused verification

  • Source qualification: PASS, including focused source contracts and high-confidence secret scan.
  • Linux bootstrap and MAFFT archive provenance regression: PASS.
  • Current static audit, SBOM, source attestation, release manifests, and release verifier: PASS.
  • Exact Docker image builds and service-UID smoke are left to the single required production release workflow gate for v1.0.6.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant