Skip to content

feat(msix): publish Store assets on every release - #1453

Merged
bkudiess merged 1 commit into
mainfrom
dallin/publish-msix-on-all-releases
Sep 21, 2026
Merged

bkudiess merged 1 commit into
mainfrom
dallin/publish-msix-on-all-releases

Conversation

@RomneyDa

@RomneyDa RomneyDa commented Sep 20, 2026 •

Copy link
Copy Markdown
Member

Summary

  • attach the validated unsigned Store MSIX bundle and standalone packages to every stable, correction, and prerelease tag
  • keep Dev-signed tester packages Actions-only
  • extend staging coverage beyond alpha versions while preserving reservation, provenance, hash, and bundle-byte validation
  • update release documentation and workflow contract tests

Required proof pools

  • none: this is packaging-only GitHub Actions publication. It does not change installed runtime behavior, UI, architecture-specific payload composition, signing policy, or Store submission behavior, so no capacity-dependent custom Windows pool applies.

Validation

Passed on PR head e1270d3d5b94c95900ac6442eee9064fc633e88a:

  • pwsh -NoLogo -NoProfile -File scripts/test-msix-alpha-release.ps1
  • pwsh -NoLogo -NoProfile -File scripts/test-ci-workflow-contract.ps1
  • dotnet test tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --filter FullyQualifiedName~ReleaseSigningWorkflowTests (4 passed, 0 failed)

Host-limited on macOS:

  • pwsh -NoLogo -NoProfile -File ./build.ps1 stops at the repository Windows prerequisite.
  • scripts/validate-docs.ps1 treats existing Windows backslash proof-pool entry points as literal macOS paths.
  • The full shared/tray Windows suites use Windows paths and DLLs; exact-head Windows CI is authoritative and running.

Real Behavior Proof

  • Environment tested: macOS local contract tests plus GitHub-hosted Windows PR CI
  • PR head or commit tested: e1270d3d5b94c95900ac6442eee9064fc633e88a
  • Exact steps or command run: focused commands listed above; CI run https://github.com/openclaw/openclaw-windows-node/actions/runs/35527563556
  • Evidence after fix: workflow contracts require Store artifact download and staging without an alpha-only condition; stable, numeric correction, beta, and alpha fixture staging exercises the shared stager.
  • Observed result: focused staging, workflow contract, and release-signing workflow tests pass. The real x64, ARM64, and multi-architecture bundle jobs pass on the PR head.
  • Screenshot or artifact links verified?: N/A
  • Not verified or blocked: actual stable/correction GitHub Release publication cannot be exercised safely from an unmerged PR head. The next canonical tag after merge is the production proof.

Security Impact

  • New permissions or capabilities?: No
  • Secrets or tokens handling changed?: No
  • Signing behavior changed?: No. Store submission assets remain unsigned for Partner Center, and release-signing OIDC scope is unchanged.

@clawsweeper

clawsweeper Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 20, 2026
@clawsweeper

clawsweeper Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Codex review: blocked before merge. Reviewed September 20, 2026, 2:21 PM ET / 18:21 UTC (Revision 3).

ClawSweeper review

What this changes

Publish validated unsigned Microsoft Store packages, their multi-architecture bundle, and metadata on stable, correction, and prerelease GitHub releases.

Merge readiness

⛔ Blocked before merge - 1 item remains

Still useful: current main limits Store release attachments to alpha tags. No blocking correctness or security defect was found in this focused extension.

Priority: P2
Reviewed head: e1270d3d5b94c95900ac6442eee9064fc633e88a

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) Focused reuse of the existing pipeline, preserved safeguards, and passing exact-head CI support normal mergeable quality.
Proof confidence 🌊 off-meta tidepool Not applicable: The MEMBER-authored PR is exempt from the external-contributor proof gate. Exact-head Windows CI builds both package architectures and their bundle; synthetic staging tests cover the added version classes, while actual release publication remains explicitly unverified.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The MEMBER-authored PR is exempt from the external-contributor proof gate. Exact-head Windows CI builds both package architectures and their bundle; synthetic staging tests cover the added version classes, while actual release publication remains explicitly unverified.
Evidence reviewed 8 items Pinned introduced change: Read all six introduced file diffs between the pinned main and PR head. The change removes alpha-only publication selection, reuses the existing stager, and updates documentation and contract tests.
Main does not provide the requested publication: The pinned main workflow still conditions Store downloads and staging on isMsixAlpha. The merged bundle work supplies the packaging foundation, not publication for every release.
Validation safeguards remain intact: The stager requires the exact reserved allocation and source commit, verifies unsigned package identity and hashes, checks embedded bundle bytes, and validates the complete set before copying. Shared version validation still enforces canonical SemVer.
Findings None None.
Security None None.

How this fits together

The release pipeline builds Windows packages, validates their reserved versions and provenance, and stages them for GitHub Releases. These unsigned assets support manual Partner Center submission; they are not end-user installers.

flowchart LR
  A[Official release tag] --> B[Reserved package version]
  B --> C[x64 and ARM64 packages]
  C --> D[Multi-architecture bundle]
  C --> E[Provenance and hash validation]
  D --> E
  E --> F[GitHub release attachments]
  F --> G[Manual Partner Center submission]
Loading

Before merge

  • Resolve merge risk (P1) - Actual stable/correction release attachment publication remains unobserved because the PR run skips the release job.
Agent review details

Security

None.

Review metrics

None.

Merge-risk options

Maintainer options:

  1. Decide the mitigation before merge
    Use the existing validated staging path for every official tag while preserving unsigned-submission labeling and the separate Store-distribution rollout gates.
  2. Pause or close
    Do not merge this PR until maintainers decide whether the risk is worth taking.

Technical review

Best possible solution:

Use the existing validated staging path for every official tag while preserving unsigned-submission labeling and the separate Store-distribution rollout gates.

Do we have a high-confidence way to reproduce the issue?

Not applicable as a bug reproduction: this extends an intentional alpha-only publication policy visible on current main.

Is this the best way to solve the issue?

Yes. Reusing the existing stager avoids a competing publication path and retains the established package validation contract.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 67f6aa5882db.

Labels

Label justifications:

  • P2: This is a bounded release-packaging improvement that preserves existing installer and portable distribution.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The MEMBER-authored PR is exempt from the external-contributor proof gate. Exact-head Windows CI builds both package architectures and their bundle; synthetic staging tests cover the added version classes, while actual release publication remains explicitly unverified.

Evidence

What I checked:

  • Pinned introduced change: Read all six introduced file diffs between the pinned main and PR head. The change removes alpha-only publication selection, reuses the existing stager, and updates documentation and contract tests. (.github/workflows/ci.yml:1299, e1270d3d5b94)
  • Main does not provide the requested publication: The pinned main workflow still conditions Store downloads and staging on isMsixAlpha. The merged bundle work supplies the packaging foundation, not publication for every release. (.github/workflows/ci.yml:1304, 67f6aa5882db)
  • Validation safeguards remain intact: The stager requires the exact reserved allocation and source commit, verifies unsigned package identity and hashes, checks embedded bundle bytes, and validates the complete set before copying. Shared version validation still enforces canonical SemVer. (scripts/Stage-StoreMsixReleaseAssets.ps1:34, e1270d3d5b94)
  • Publication permissions and rollout boundary: The release-signing environment, official reservation prerequisite, CI gate, action references, and token permissions are unchanged. Release documentation retains the Store-distribution pause tracked by Enable Microsoft Store distribution (lift the MSIX publish pause) #1375 (Enable Microsoft Store distribution (lift the MSIX publish pause)). (docs/RELEASING.md:194, e1270d3d5b94)
  • Exact-head validation: GitHub run 35527563556 completed successfully at the reviewed head. Core/CLI, tray/setup/integration, both MSIX architecture jobs, and bundle composition succeeded; the release job was skipped. The supplied body reports passing focused staging and workflow tests and explicitly defers actual tag publication. No builds or tests were executed during this read-only review. (e1270d3d5b94)
  • Latest release check: The latest release, v2026.9.4, contains only the two EXE installers and two portable ZIPs; the requested Store assets are not shipped there. (3c43751b2bac)

Likely related people:

  • RomneyDa: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • natalie-aguinaldo: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (2 earlier review cycles)
  • reviewed 2026-09-20T18:01:24.213Z sha e1270d3 :: needs changes before merge. :: none
  • reviewed 2026-09-20T18:14:33.663Z sha e1270d3 :: needs maintainer review before merge. :: none

@RomneyDa RomneyDa added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 20, 2026
@RomneyDa

Copy link
Copy Markdown
Member Author

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

🦞🧹
ClawSweeper re-review requested.

I asked ClawSweeper to review this item again.
Action: item re-review queued (workflow sweep.yml, event exact_review_queue).
Result: when the review finishes, ClawSweeper will create the durable review comment if needed or update the existing comment in place.

Re-review progress:

@RomneyDa RomneyDa removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 20, 2026
@bkudiess bkudiess added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 21, 2026
@bkudiess
bkudiess merged commit e7d8c05 into main Sep 21, 2026
29 of 30 checks passed
@bkudiess
bkudiess deleted the dallin/publish-msix-on-all-releases branch September 21, 2026 18:25
@bkudiess bkudiess removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants