Skip to content

ci(msix): align Store and Dev PR artifact version bases - #1441

Closed
natalie-aguinaldo wants to merge 4 commits into
openclaw:mainfrom
natalie-aguinaldo:user/natalie-aguinaldo/msix-ci-artifacts-versioning
Closed

natalie-aguinaldo wants to merge 4 commits into
openclaw:mainfrom
natalie-aguinaldo:user/natalie-aguinaldo/msix-ci-artifacts-versioning

Conversation

@natalie-aguinaldo

Copy link
Copy Markdown
Contributor

Summary

  • Rename MSIX downloads and matching metadata references to OpenClaw-<arch>.msix and OpenClaw-Dev-<arch>.msix. Keep EXE filenames, package identities, UI branding, capabilities, and signing unchanged.
  • Add validated one-off build-version overrides, and temporarily select base 2026.9.4 only for pull_request runs from natalie-aguinaldo/openclaw-windows-node:user/natalie-aguinaldo/msix-ci-artifacts-versioning.
  • Produce unsigned Store packages at 2026.9.4.0 and Dev-signed tester packages at 2026.9.4.<github.run_number>, with actual package-version validation before metadata export.
  • Preserve normal GitVersion, EXE/ZIP versions, alpha tags, and alpha package-version checks. This PR generates Actions artifacts; it does not publish an alpha release or submit anything to Partner Center.

Draft, artifact-generation only. Remove the temporary branch exception and its documentation note before merge. A 2026.9.4.* Dev package is older than an installed 2026.9.5.* package; no uninstall, downgrade, or data migration has been performed.

Required proof pools

  • none: CI artifact filenames and explicit per-build version selection only. No architecture-specific runtime code, native dependencies, package identity, installation logic, UI, permissions, or gateway behavior changes. Normal hosted CI provides x64 and native ARM64 packaging jobs. No native ARM64 launch or clean-install/upgrade compatibility claim is made.

Validation

Local validation passed on the final source tree on this branch immediately before commit:

  • .\build.ps1: passed for all projects.
  • dotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --no-restore: 3,983 passed, 33 skipped, 0 failed.
  • dotnet test .\tests\OpenClaw.Tray.Tests\OpenClaw.Tray.Tests.csproj --no-restore: 2,978 passed, 0 failed.
  • .\scripts\test-msix-ci-artifacts.ps1: passed. Covers matching and nonmatching branches/events, both architectures, Store/Dev argument construction, version bounds, actual metadata validation, and signature rejection.
  • .\scripts\test-ci-workflow-contract.ps1: passed.
  • .\scripts\test-msix-alpha-release.ps1: passed, including unchanged alpha version matching and unsigned-only release staging.
  • .\scripts\validate-docs.ps1: passed.
  • git diff --check: passed.

Tests used isolated tray settings and an environment-only official NuGet source configuration. No tracked dependencies or global NuGet configuration were changed.

Real behavior proof

  • Local pre-commit unsigned Store builds for x64 and ARM64 produced validated packages at 2026.9.4.0.
  • The actual Dev build path produced a signed x64 package at 2026.9.4.123 using the existing local development certificate, without changing certificate trust or installing the app.
  • The real Dev exporter verified the signature, identity, architecture, package version, and public-only export. The packaged app assembly and file versions were 2026.9.4.123.
  • These local packages correctly record an uncommitted source tree based on 19da0469; they are not presented as hosted artifacts from this PR head. Current-head hosted x64/ARM64 packages and their sidecars are pending CI.

Not verified / blocked

  • Structured review was attempted with python .agents\skills\autoreview\scripts\autoreview --mode local; the bundle was generated, but the Codex executable is unavailable. No clean automated-review result is claimed.
  • Current-head hosted CI, native ARM64 Dev signing/export, Store submission, install/upgrade behavior, and public alpha publication are not yet verified.
  • UI/MCP/gateway runtime proof is not applicable because those behaviors are unchanged. No new runFullTrust capability was added.

natalie-aguinaldo and others added 4 commits September 15, 2026 14:25
Build verified x64 and ARM64 workflow downloads through the existing packaging scripts. Bound Dev CI revisions, stage only public signing material, and gate selected MSIX jobs without enabling MSIX release publishing.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cb0e5a80-d2cf-41b0-9fb0-21eb32623526
Keep Dev-signed packages as workflow artifacts and stable assets unchanged. Add manual default-branch alpha dispatch with existing tag gates, validate Store staging provenance, and document submission/version constraints.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cb0e5a80-d2cf-41b0-9fb0-21eb32623526
Update Store and Dev package filenames, provenance references, CI uploads, alpha release staging, documentation, and tests. Preserve package identities, versions, app display names, and EXE installer filenames.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cb0e5a80-d2cf-41b0-9fb0-21eb32623526
Use base 2026.9.4 only for PRs from the versioning branch. Keep Store revision zero and Dev revision tied to the CI run number. Validate explicit build overrides and preserve normal GitVersion and alpha release behavior. Remove the temporary branch exception before merge.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cb0e5a80-d2cf-41b0-9fb0-21eb32623526
@clawsweeper

clawsweeper Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Sep 18, 2026
@clawsweeper

clawsweeper Bot commented Sep 18, 2026

Copy link
Copy Markdown

Codex review: needs real behavior proof before merge. Reviewed September 17, 2026, 9:00 PM ET / September 18, 2026, 01:00 UTC.

ClawSweeper review

What this changes

The branch builds Windows MSIX package artifacts, updates their download names, and adds explicit Store and Dev version overrides with a temporary branch-specific version selection.

Merge readiness

⛔ Blocked before merge - 3 items remain

Keep open: the merged MSIX pipeline covers the foundation, but the filename changes and validated version overrides remain distinct useful work. No blocking code defect was established.

Priority: P3
Reviewed head: 9211ce081907727dd892563095f41f9fe81499ee

Review scores

Measure Result What it means
Overall readiness 🦐 gold shrimp (3/6) The implementation is focused and covered by useful contract tests, but the reported real builds lack inspectable supporting evidence.
Proof confidence 🦐 gold shrimp (3/6) Needs stronger real behavior proof before merge: The body reports real local Store builds and Dev x64 signing/export through the changed builders, but provides no inspectable output tying package versions, filenames, and signatures to the reviewed source; ARM64 Dev export remains explicitly unverified. Redacted terminal output or linked package metadata is appropriate proof for this change. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Needs proof Needs stronger real behavior proof before merge: The body reports real local Store builds and Dev x64 signing/export through the changed builders, but provides no inspectable output tying package versions, filenames, and signatures to the reviewed source; ARM64 Dev export remains explicitly unverified. Redacted terminal output or linked package metadata is appropriate proof for this change. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
Evidence reviewed 8 items Pinned introduction and remaining contribution: Inspected the merge-base-to-head changes across all 17 paths, then compared relevant paths with fetched main as behavioral context. The filename changes and explicit version overrides remain absent from main; base-only UI changes were not attributed to this PR.
Verified merged foundation: GitHub verifies #1403 (chore(ci): build MSIX artifacts and publish Store alpha assets) merged as 3383997. It supplies the existing artifact pipeline, not this branch's remaining filename and version-override changes.
Explicit version selection and package validation: Store overrides disable GitVersion property and assembly rewriting, preserve revision zero, and reject an actual package-version mismatch. Dev overrides preserve the selected revision. The temporary CI selector requires the exact pull-request event, repository, and branch.
Findings None None.
Security None None.

How this fits together

The Windows packaging pipeline turns repository builds into unsigned Store submission packages and signed Dev tester downloads. Package validators check versions, identities, signatures, and metadata before artifacts reach testers or alpha releases.

flowchart LR
  A[Source and build event] --> B[Select package version]
  B --> C[Unsigned Store build]
  B --> D[Signed Dev build]
  C --> E[Validate packages and metadata]
  D --> E
  E --> F[Workflow downloads]
  E --> G[Alpha Store submission assets]
Loading

Before merge

  • Add real behavior proof - Needs stronger real behavior proof before merge: The body reports real local Store builds and Dev x64 signing/export through the changed builders, but provides no inspectable output tying package versions, filenames, and signatures to the reviewed source; ARM64 Dev export remains explicitly unverified. Redacted terminal output or linked package metadata is appropriate proof for this change. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
  • Resolve merge risk (P1) - The conflicting branch has no verified merge result, so final integration with the already-merged packaging pipeline remains unreviewed.
  • Complete next step (P2) - Resolve the conflicts, remove the temporary workflow exception and matching documentation/tests, and attach inspectable package-version and export evidence for the final source. Redact private paths, endpoints, and credentials. Updating the PR body should trigger re-review; otherwise ask a maintainer to comment @clawsweeper re-review.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Introduced production and test lines Production/tooling +509/-68; tests +719/-11 These merge-base-to-head totals include the packaging foundation already merged separately; the remaining growth supports explicit version selection and artifact naming.

Merge-risk options

Maintainer options:

  1. Decide the mitigation before merge
    Retain the existing packaging owners and default version policy, with explicit validated overrides and consistent filenames, while excluding the temporary contributor-branch exception from the landed workflow.
  2. Pause or close
    Do not merge this PR until maintainers decide whether the risk is worth taking.

Technical review

Best possible solution:

Retain the existing packaging owners and default version policy, with explicit validated overrides and consistent filenames, while excluding the temporary contributor-branch exception from the landed workflow.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this adds packaging controls and changes download names rather than repairing an established runtime failure.

Is this the best way to solve the issue?

Yes, extending the existing builders is a focused approach; the temporary branch exception is explicitly unsuitable for the final merged workflow.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 0246e33f6e8f.

Labels

Label changes:

  • add P3: The remaining contribution improves packaging ergonomics without establishing an urgent user-facing failure.
  • add rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🦐 gold shrimp and patch quality is 🐚 platinum hermit.
  • add status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs stronger real behavior proof before merge: The body reports real local Store builds and Dev x64 signing/export through the changed builders, but provides no inspectable output tying package versions, filenames, and signatures to the reviewed source; ARM64 Dev export remains explicitly unverified. Redacted terminal output or linked package metadata is appropriate proof for this change. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.

Label justifications:

  • P3: The remaining contribution improves packaging ergonomics without establishing an urgent user-facing failure.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🦐 gold shrimp and patch quality is 🐚 platinum hermit.
  • status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs stronger real behavior proof before merge: The body reports real local Store builds and Dev x64 signing/export through the changed builders, but provides no inspectable output tying package versions, filenames, and signatures to the reviewed source; ARM64 Dev export remains explicitly unverified. Redacted terminal output or linked package metadata is appropriate proof for this change. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.

Evidence

What I checked:

  • Pinned introduction and remaining contribution: Inspected the merge-base-to-head changes across all 17 paths, then compared relevant paths with fetched main as behavioral context. The filename changes and explicit version overrides remain absent from main; base-only UI changes were not attributed to this PR. (.github/workflows/ci.yml:853, 9211ce081907)
  • Verified merged foundation: GitHub verifies chore(ci): build MSIX artifacts and publish Store alpha assets #1403 (chore(ci): build MSIX artifacts and publish Store alpha assets) merged as 3383997. It supplies the existing artifact pipeline, not this branch's remaining filename and version-override changes. (.github/workflows/ci.yml:821, 33839971e315)
  • Explicit version selection and package validation: Store overrides disable GitVersion property and assembly rewriting, preserve revision zero, and reject an actual package-version mismatch. Dev overrides preserve the selected revision. The temporary CI selector requires the exact pull-request event, repository, and branch. (scripts/Build-StoreMsix.ps1:138, 9211ce081907)
  • Focused supplemental coverage: Tests cover override bounds, matching and nonmatching events, both architectures, argument construction, actual metadata writing, mismatched versions, and signature rejection. Builds and signatures are stubbed in these tests, so they supplement real package evidence. (scripts/test-msix-ci-artifacts.ps1:177, 9211ce081907)
  • Contributor validation and proof boundary: The complete supplied body, captured under context sourceRevision ce9d8cf8419a3027926b917bec608a673687e99bfd4e0da94613da11a416acfa, reports final-source local build success, 3,983 shared tests passed with 33 skipped, and 2,978 tray tests passed. It reports real Store x64/ARM64 packages at 2026.9.4.0 and signed Dev x64 at 2026.9.4.123, but supplies no inspectable transcript or package sidecars. It explicitly leaves current-head hosted artifacts and ARM64 Dev export unverified. No media files were supplied in the proof scratch directory. (9211ce081907)
  • Release boundary: The latest supplied release, v2026.9.4, still disables the MSIX CI job. No local tag contains the merged artifact-pipeline commit; its timestamp is 2026-09-17T14:16:59-07:00. Neither this release nor current main establishes completion of the remaining PR changes. (.github/workflows/ci.yml:810, 3c43751b2bac)

Likely related people:

  • natalie-aguinaldo: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Attach source-linked package metadata or redacted build/export output showing the renamed artifacts, selected versions, and Dev signatures for both architectures.
  • Remove the temporary branch exception and its documentation, update the associated tests, and resolve conflicts with main.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@natalie-aguinaldo

natalie-aguinaldo commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor Author

Closing this in favor of this PR in my fork because this 1441 PR will not be on the same base as the other MSIX artifact that was the candidate to be uploaded to the store. The merge conflicts are blocking the CI run.

Using the run from this PR run instead: natalie-aguinaldo#1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant