Skip to content

feat(msix): allocate monotonic package versions - #1448

Merged
RomneyDa merged 4 commits into
openclaw:mainfrom
natalie-aguinaldo:user/natalie-aguinaldo/msix-release-versioning
Sep 19, 2026
Merged

RomneyDa merged 4 commits into
openclaw:mainfrom
natalie-aguinaldo:user/natalie-aguinaldo/msix-release-versioning

Conversation

@natalie-aguinaldo

@natalie-aguinaldo natalie-aguinaldo commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • allocate a monotonic MSIX package version independently from normal GitVersion output
  • reserve official versions as immutable annotated Git tags under msix-package/<app-base>/<counter>
  • keep PR, main, and fork builds read-only by previewing the next number on the latest published stable Windows release line
  • pass one shared allocation result to Store and Dev x64/ARM64 package builds and validate it through package metadata and alpha staging
  • show the four-part package identity version in packaged App info while preserving GitVersion for unpackaged builds and binary metadata
  • keep ordinary local Dev MSIX builds upgrade-compatible by reusing a higher installed three-part package base

For app version X.Y.Z, MSIX uses the third-component range Z00-Z99.
2026.9.400.0 is imported as already used and 2026.9.401.0 now has a live
canonical reservation. The next unreserved package on the 2026.9.4 line is
therefore 2026.9.402.0. A future official v2026.9.5 release starts at
2026.9.500.0.

PR and ordinary main builds do not consume numbers. They resolve the canonical
upstream Latest release and reservation ledger. Assemblies, EXE/ZIP versions,
release tags, package identities, and signing policy remain GitVersion-owned
and unchanged. Packaged Settings App info shows the Windows package identity
version; unpackaged builds continue to show the normal GitVersion display
string.

Only canonical upstream v* tag builds from push or workflow_dispatch run
the separate contents: write reservation job. Reservations use atomic ref
creation, reruns reuse the same source tag/commit reservation, competing runs
retry after validating the winning record, failed builds keep consumed
numbers, and range/UInt16 exhaustion fails closed.

Allocator adoption and live proof

The canonical allocator was run twice against v2026.9.4 at source commit
3c43751b2bace876de3febe478ebabeca172e3ac using this PR's production script.

  • First run created refs/tags/msix-package/2026.9.4/401 and returned Store
    version 2026.9.401.0, revision 1, allocation reserved.
  • The annotated tag object is
    014be340b05e7a0e53734906f009c62ee74c48f9.
  • An identical second run returned the exact same record/ref and did not consume
    another number, proving same-source idempotency.
  • A subsequent read-only lookup returns preview 2026.9.402.0, revision 2.

The active repository tag ruleset Protect MSIX package reservations
(ruleset 23709396) covers refs/tags/msix-package/**/* and blocks deletion
and non-fast-forward updates. Reservation tags are permanent release records;
alpha cleanup must not delete them.

Maintainer decision: the canonical reservation ledger is adopted as an
intentional fail-closed release dependency. Authentication, permission,
allocation, malformed-ledger, exhaustion, or retry-limit failures stop the
tagged workflow before EXE/ZIP publication. The remedy is to repair and rerun
the same source tag, not bypass allocation or publish a partial release.

Imported floor provenance

.github/msix-version-baseline.json now records the independent provenance for
the already-used 2026.9.400.0 floor:

  • workflow run: https://github.com/natalie-aguinaldo/openclaw-windows-node/actions/runs/35303248183
  • workflow head: 01f2bf7ef407f8b9125f40bf1a4638c0361818c2
  • package source: ded1d4aed4d1a69859a817dc57087f2c6142deab
  • x64 artifact 10531666502, package SHA-256
    4612ff57a12489584a853a5eed38f687d6a8ac2f89836eb74c4eab8b1514d4db
  • ARM64 artifact 10531117192, package SHA-256
    febd4c4db99d153eea85c97000dd3583364ce671c3e8598bd7bf972a89cc788d

Both manifests were independently inspected as 2026.9.400.0 with identity
OpenClawFoundation.OpenClaw and publisher
CN=4BA40A7A-B719-4C40-BF91-84AF4F1136FC; metadata hashes matched the package
bytes.

Real behavior proof

Fresh install from CI-produced signed Dev MSIX:

Fresh install Packaged app Packaged app version

Retained-settings upgrade proof at implementation head dc19c513:

  • installed Dev package upgraded from 2026.9.401.3286 to
    2026.9.401.3287 without uninstalling
  • settings file SHA-256 remained
    1AFBA36378E84FB164C6DAEC84A9445FE04FF01D25B6FABE49F9EB11B3903325
  • selected non-sensitive settings (AppTheme, EnableMcpServer, and
    ShowCompletedSessions) remained identical
  • Settings App info showed Version 2026.9.401.3287 and
    Install type Packaged (MSIX)
  • installed EXE/DLL file version remained 2026.9.5.0, proving the override is
    MSIX-only

Validation

Current head: 5fd42205523c7360b5c445acc1caff079b6bf429

Current-head focused validation:

  • scripts/test-msix-versioning.ps1: 212 cases, 3,521 assertions, 591 mocked HTTP requests
  • scripts/test-msix-preview-source-version.ps1: passed
  • scripts/test-msix-alpha-release.ps1: passed
  • scripts/test-ci-workflow-contract.ps1: passed
  • live read-only canonical allocator lookup: preview 2026.9.402.0
  • JSON parse and git diff --check: passed

The prior implementation head passed the repository's Windows build, both full
test projects, all focused MSIX/workflow suites, and both architecture artifact
jobs. The current fix only adds migration provenance and updates operational
documentation; the new-head Windows CI is authoritative for those host-specific
gates.

Reserve immutable per-release MSIX package versions while keeping PR and main previews read-only on the latest published stable release line.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: cb0e5a80-d2cf-41b0-9fb0-21eb32623526
@clawsweeper

clawsweeper Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Sep 18, 2026
@clawsweeper

clawsweeper Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codex review: blocked before merge. Reviewed September 19, 2026, 4:46 PM ET / 20:46 UTC (Revision 10).

ClawSweeper review

What this changes

Adds persistent Windows package-version allocation shared across architectures, preserves local development-package upgrades, and displays the installed package version in Settings.

Merge readiness

⛔ Blocked before merge - 1 item remains

Keep open for landing. Current main still lacks durable package-version allocation. The prior authentication, proof, migration-floor, retention, and release-policy concerns are addressed; no blocking patch defect remains.

Priority: P2
Reviewed head: 5fd42205523c7360b5c445acc1caff079b6bf429

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A coherent, well-covered implementation whose prior proof and operational blockers are resolved.
Proof confidence 🐚 platinum hermit (4/6) Sufficient (live_output): The production allocator's reported create/reuse run is corroborated by the live canonical annotated reservation and active retention ruleset. Inspected install/Settings screenshots and recorded retained-settings upgrade results exercise the package builder and display paths; those production files are unchanged since the demonstrated implementation head.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Verified Sufficient (live_output): The production allocator's reported create/reuse run is corroborated by the live canonical annotated reservation and active retention ruleset. Inspected install/Settings screenshots and recorded retained-settings upgrade results exercise the package builder and display paths; those production files are unchanged since the demonstrated implementation head.
Evidence reviewed 10 items Current main still needs this capability: At fetched main, the manifest target derives its base from the application version and gives Store packages revision zero. Current-main release documentation explicitly says same-base prerelease and correction tags can produce the same Store version. The allocator script is absent from that tree.
Live durable reservation verified: GitHub returns reservation msix-package/2026.9.4/401, targeting annotated tag object 014be340b05e7a0e53734906f009c62ee74c48f9. Its allocation JSON records Store version 2026.9.401.0 and source commit 3c43751. The captured body and maintainer comment report identical production-script reuse and subsequent preview 2026.9.402.0.
Reservation retention safeguard verified: Ruleset 23709396 is active for refs/tags/msix-package/**/* and includes deletion and non-fast-forward protections.
Findings None None.
Security None None.

How this fits together

The Windows packaging pipeline converts application releases into Store and development MSIX packages. The new allocator supplies package versions while GitVersion continues to control application and binary versions.

flowchart TD
  A[Release tag or preview build] --> B{Official upstream release?}
  B -->|Yes| C[Reserve or reuse protected Git tag]
  B -->|No| D[Read next preview version]
  C --> E[Shared package version metadata]
  D --> E
  E --> F[Store and Dev packages for both architectures]
  F --> G[Windows install and Settings version]
Loading

Before merge

  • Resolve merge risk (P1) - Allocator authentication, ledger corruption, permission failures, or counter exhaustion will stop the entire tagged release, including EXE/ZIP publication. The maintainer explicitly accepted this operational dependency; recovery requires repair and rerun while preserving reservation tags.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Production and test growth Production net +713 lines; tests net +1,287 lines Production growth implements durable allocation and package integration, with larger regression coverage for state, races, boundaries, and artifacts.
Release workflow scope 1 new write-scoped reservation job; 2 architectures share its output Central allocation prevents architecture builds from consuming different package versions.

Merge-risk options

Maintainer options:

  1. Retain the approved release gate (recommended)
    Proceed with the maintainer-approved dependency and repair allocator failures before rerunning the same release source.

Technical review

Best possible solution:

Land the shared allocator with the adopted fail-closed release contract, permanent reservation protection, and preserved application-version and settings behavior.

Do we have a high-confidence way to reproduce the issue?

Not applicable as a new allocation capability; current-main source directly confirms that same-base release tags can reuse a Store package version.

Is this the best way to solve the issue?

Yes. One durable allocation shared by both architectures avoids competing counters, while package-only overrides preserve application versioning and demonstrated local upgrades.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 3fc8372bfaa6.

Labels

Label changes:

  • add proof: sufficient: Contributor real behavior proof is sufficient. The production allocator's reported create/reuse run is corroborated by the live canonical annotated reservation and active retention ruleset. Inspected install/Settings screenshots and recorded retained-settings upgrade results exercise the package builder and display paths; those production files are unchanged since the demonstrated implementation head.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (live_output): The production allocator's reported create/reuse run is corroborated by the live canonical annotated reservation and active retention ruleset. Inspected install/Settings screenshots and recorded retained-settings upgrade results exercise the package builder and display paths; those production files are unchanged since the demonstrated implementation head.
  • remove status: 📣 needs proof: Current PR status label is status: 👀 ready for maintainer look.
  • remove merge-risk: 🚨 compatibility: Current PR review merge-risk labels are merge-risk: 🚨 automation.
  • remove rating: 🦐 gold shrimp: Current PR rating is rating: 🐚 platinum hermit, so this older rating label is no longer current.

Label justifications:

  • P2: This is a bounded packaging improvement with demonstrated installation and upgrade behavior, not an observed emergency.
  • merge-risk: 🚨 automation: The introduced reservation dependency can stop all tagged-release publication on allocator failure, a tradeoff explicitly accepted by the maintainer.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (live_output): The production allocator's reported create/reuse run is corroborated by the live canonical annotated reservation and active retention ruleset. Inspected install/Settings screenshots and recorded retained-settings upgrade results exercise the package builder and display paths; those production files are unchanged since the demonstrated implementation head.
  • proof: sufficient: Contributor real behavior proof is sufficient. The production allocator's reported create/reuse run is corroborated by the live canonical annotated reservation and active retention ruleset. Inspected install/Settings screenshots and recorded retained-settings upgrade results exercise the package builder and display paths; those production files are unchanged since the demonstrated implementation head.

Evidence

What I checked:

  • Current main still needs this capability: At fetched main, the manifest target derives its base from the application version and gives Store packages revision zero. Current-main release documentation explicitly says same-base prerelease and correction tags can produce the same Store version. The allocator script is absent from that tree. (src/OpenClaw.Tray.WinUI/OpenClaw.Tray.WinUI.csproj:255, 3fc8372bfaa6)
  • Live durable reservation verified: GitHub returns reservation msix-package/2026.9.4/401, targeting annotated tag object 014be340b05e7a0e53734906f009c62ee74c48f9. Its allocation JSON records Store version 2026.9.401.0 and source commit 3c43751. The captured body and maintainer comment report identical production-script reuse and subsequent preview 2026.9.402.0. (3c43751b2bac)
  • Reservation retention safeguard verified: Ruleset 23709396 is active for refs/tags/msix-package/**/* and includes deletion and non-fast-forward protections.
  • Maintainer accepted release dependency: RomneyDa explicitly confirmed intentional fail-closed adoption in feat(msix): allocate monotonic package versions #1448 (comment). Release documentation now records that allocation failures stop EXE/ZIP publication and require repair and rerun. (docs/RELEASING.md:254, 5fd42205523c)
  • Prior implementation proof remains applicable: The current commit changes only the baseline's provenance section and two documentation files relative to dc19c51. GitHub commit inspection confirmed unchanged production implementation. A local full historical diff encountered an unavailable blob; the API supplied the complete three-file commit patch. (.github/msix-version-baseline.json:6, 5fd42205523c)
  • Installation, display, and retained-settings proof: Inspected all three prepared screenshots: the installer and running Settings show package version 2026.9.401.3296 and packaged identity. The captured body separately records an installed upgrade from 2026.9.401.3286 to 2026.9.401.3287, unchanged settings hash and selected settings, and binary version 2026.9.5.0. The screenshots support visible installation and display; the recorded upgrade observations support settings preservation. (src/OpenClaw.Tray.WinUI/Pages/SettingsPage.xaml.cs:122, dc19c513db17)

Likely related people:

  • natalie-aguinaldo: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • RomneyDa: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (9 earlier review cycles; latest 8 shown)
  • reviewed 2026-09-19T00:00:01.061Z sha 0d94bd6 :: needs real behavior proof before merge. :: none
  • reviewed 2026-09-19T00:06:04.160Z sha 0d94bd6 :: needs real behavior proof before merge. :: none
  • reviewed 2026-09-19T00:14:19.043Z sha 0d94bd6 :: needs real behavior proof before merge. :: none
  • reviewed 2026-09-19T00:22:28.807Z sha 0d94bd6 :: needs real behavior proof before merge. :: none
  • reviewed 2026-09-19T02:03:43.109Z sha dc19c51 :: needs real behavior proof before merge. :: none
  • reviewed 2026-09-19T02:10:51.592Z sha dc19c51 :: needs real behavior proof before merge. :: none
  • reviewed 2026-09-19T02:16:40.739Z sha dc19c51 :: needs real behavior proof before merge. :: none
  • reviewed 2026-09-19T02:30:31.511Z sha dc19c51 :: needs real behavior proof before merge. :: none

Use the supplied GitHub token for both latest-release preview lookup and reservation-ledger requests, with focused leakage and header coverage.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: cb0e5a80-d2cf-41b0-9fb0-21eb32623526
@natalie-aguinaldo

Copy link
Copy Markdown
Contributor Author

@clawsweeper re-review

Fixed the P2 authentication finding in 0d94bd6. Both GitHub API clients now construct the Authorization header from the supplied token. Focused PowerShell 7/5.1 tests and full required validation pass. Live redacted proof returned HTTP 200 for v2026.9.4 with the authenticated 5,000-request quota. The PR body now includes refreshed current-head x64/ARM64 Store and signed Dev package hashes.

@clawsweeper

clawsweeper Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

🦞🧹
ClawSweeper re-review requested.

I asked ClawSweeper to review this item again.
Action: item re-review queued (workflow sweep.yml, event exact_review_queue).
Result: when the review finishes, ClawSweeper will create the durable review comment if needed or update the existing comment in place.

@natalie-aguinaldo
natalie-aguinaldo marked this pull request as ready for review September 19, 2026 00:11
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: cb0e5a80-d2cf-41b0-9fb0-21eb32623526
@RomneyDa RomneyDa added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 19, 2026
@RomneyDa

Copy link
Copy Markdown
Member

@clawsweeper re-review

The six operational blockers from the prior review are now addressed on head
5fd42205523c7360b5c445acc1caff079b6bf429:

  1. The production allocator created canonical reservation
    refs/tags/msix-package/2026.9.4/401; an identical rerun reused the exact
    same record instead of consuming another number.
  2. Maintainer decision is recorded: the ledger is an intentional fail-closed
    dependency, so allocator/auth/permission failures stop the entire tagged
    release before EXE/ZIP publication.
  3. The imported 2026.9.400.0 floor now includes workflow, commit, artifact,
    and independently verified package-hash provenance in the baseline file.
  4. Active ruleset Protect MSIX package reservations (23709396) blocks
    deletion and non-fast-forward updates under
    refs/tags/msix-package/**/*.
  5. The PR body and release docs now contain the live proof, owner decision, and
    permanent-retention contract.
  6. Read-only production lookup after the reservation returns the expected next
    preview 2026.9.402.0.

Focused current-head allocator, preview-source, alpha-release, and workflow
contract suites pass. Windows CI is running for the new head.

@clawsweeper

clawsweeper Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

🦞🧹
ClawSweeper re-review requested.

I asked ClawSweeper to review this item again.
Action: item re-review queued (workflow sweep.yml, event exact_review_queue).
Result: when the review finishes, ClawSweeper will create the durable review comment if needed or update the existing comment in place.

Re-review progress:

@clawsweeper clawsweeper Bot added proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. and removed status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. labels Sep 19, 2026
@RomneyDa
RomneyDa merged commit 8ed7c56 into openclaw:main Sep 19, 2026
27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. P2 Normal priority bug or improvement with limited blast radius. proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants