Skip to content

ci(p3): seal canonical Windows package and reuse exact tested bits - #445

Merged
masarray merged 3 commits into
mainfrom
ci/p3-canonical-windows-package
Oct 7, 2026
Merged

masarray merged 3 commits into
mainfrom
ci/p3-canonical-windows-package

Conversation

@masarray

@masarray masarray commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Closes #444

CI-P3

Establishes a sealed Windows package artifact so installer validation can consume the exact bytes produced after canonical Build ARSAS regression instead of rebuilding the application.

Canonical Build ARSAS

  • resolves exact ARIEC61850 + ArdIrec locks;
  • builds/tests one pinned native ArdIrec bridge;
  • publishes installer-input and portable outputs from the same bridge bytes;
  • runs managed native bridge/locus tests against the packaged bridge;
  • smoke-tests portable;
  • seals canonical TRX/proof + portable + installer-input + prebuilt test runtime + fixtures in ARSAS-windows-package-input;
  • manifest records exact source/engine/ArdIrec/run identity and SHA-256 for every payload file.

Installer PR/main

  • verifies the package ZIP before extraction;
  • requires exact source, engine, ArdIrec, run ID/attempt/event and all-pass canonical TRX;
  • verifies every payload SHA-256;
  • does not restore/build/test/publish the application again;
  • still verifies Smart Discovery route, compiles Inno Setup, silently installs/uninstalls, rejects removed Qt/Desktop fallback, and executes native bridge/locus tests against installed files.

Manual workflow_dispatch

Historical local-build fallback remains available.

Authority

The package explicitly has no release-promotion authority. Stable release workflow is unchanged in this milestone. This is exact-byte reuse, not an assumption of reproducible rebuilds.

Static P0 budget

Manual fallback remains visible in YAML, so static restore/build counts intentionally remain unchanged. Net static change: dotnet-test 13→12, setup-python 17→18, upload-artifact 34→35 for the new sealed payload.

@masarray
masarray force-pushed the ci/p3-canonical-windows-package branch from 5bdced4 to 820c7c4 Compare October 7, 2026 09:16

masarray commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

CI-P3 final acceptance on exact head babbc698c789db0521f956e06b1e081b03e88d25 / synthetic merge adf0f0c6a91c595b202dae9a41d8eb950f9aacaa:

  • 11/11 triggered workflows SUCCESS after rebasing conflict-aware onto P3A main c5946a215b97e0285fed6e698fbf87ecce96cdd4.
  • P3A reproducibility protections retained: Windows packaging PowerShell syntax guard, deterministic publish identity, portable build-identity artifact.
  • CI-P0 package security fixtures PASS, including Windows case-insensitive/trailing-dot path alias rejection added during review.
  • Canonical Build ARSAS run 37599746406/1 PASS:
    • exact application regression 1323 passed / 0 failed / 0 notExecuted;
    • one pinned ArdIrec bridge built and tested;
    • installer-input and portable produced from the same native bridge bytes;
    • packaged bridge managed integration PASS;
    • portable smoke PASS;
    • sealed artifact uploaded as ARSAS-windows-package-input artifact 11472775750, digest sha256:61be622fef033bed5f56d0f7330b92beeedfa010f6436d1fa501cd9608fa4bd2.
  • Installer run 37599746591 consumed that exact sealed artifact before Build ARSAS completed:
    • source adf0f0c6a91c595b202dae9a41d8eb950f9aacaa
    • ARIEC61850 648124097621046f5f127ceb1cf853fea54db730
    • ArdIrec 7dbc7149db668126a493ce338264363a6ec5ec00
    • native bridge SHA256 fa8efcaf26e8ebb0a29808a2e52ad5c9f466ec2df146945d29c5d662987c41ce
    • portable SHA256 f3b5eaacd7db1ef439fa191d3f754041e4a3804c2824acebc2ffe5519855f165
    • 588 sealed payload files / 287,446,427 bytes
    • proofStage=sealed-package-artifact-ready
    • releasePromotionAuthority=false
  • Installer PR lane explicitly skipped ARIEC61850/ArdIrec manual checkouts, ARSAS restore/build/test, source publish and native bridge staging.
  • It independently compiled Inno Setup from sealed bytes, ran pre-install bridge/locus tests, silent install, installed bridge/locus tests, silent uninstall, checksums, and uploaded installer artifact 11472461931, digest sha256:b22aa45259d3755978a357747883dfe3f8c41197dc97f9f87ef76e22be498965.
  • Smart Discovery Field Capture independent publish/smoke PASS; physical/field authority unchanged.
  • Stable release workflow is intentionally unchanged in CI-P3. Sealed package has no release promotion authority.

This establishes the P3 boundary: build/test once, seal exact bytes, package many; verify before materialization; do not infer release authority from CI package reuse.

@masarray
masarray marked this pull request as ready for review October 7, 2026 09:28
@masarray
masarray merged commit fd25836 into main Oct 7, 2026
16 checks passed
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T09:32:24.633598Z babbc69 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI-P3: seal canonical Windows package payload and reuse exact tested bits in installer validation

1 participant