Skip to content

fix(release): publish signed MSIX downloads - #1600

Merged
RomneyDa merged 2 commits into
mainfrom
openclaw/download-store-ready-msix-from-github-actions
Oct 2, 2026
Merged

RomneyDa merged 2 commits into
mainfrom
openclaw/download-store-ready-msix-from-github-actions

Conversation

@RomneyDa

@RomneyDa RomneyDa commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

  • publish the existing signed Dev MSIX packages on every canonical GitHub release as OpenClaw-Dev-x64.zip and OpenClaw-Dev-arm64.zip
  • keep unsigned Store packages and the multi-architecture Store bundle in Actions for Partner Center submission
  • fail release staging unless both architectures match the tag source, reserved allocation, workflow run, Dev identity, package version, package/certificate hashes, and a valid Authenticode signature from the exact artifact certificate
  • update generated release notes, installation guidance, release documentation, and workflow contract coverage

Required proof pools

  • none: this changes release artifact selection and validation, not product runtime, UI, gateway, node-command, or installer behavior requiring a custom host class.

Validation

  • exact-head Windows CI: Build and Test run 36993252844 passed, including CI Gate
  • Windows Shared Tests: 4,256 passed, 1 skipped
  • Windows Tray Tests: 3,889 passed
  • Windows Connection Tests: 1,557 passed, 1 skipped
  • Windows Tray Integration Tests: 50 passed, 2 skipped
  • Windows SetupEngine Tests: 2,264 passed, 1 skipped
  • Windows WinNode CLI Tests: 129 passed
  • signed Dev MSIX artifact jobs passed for x64 and ARM64
  • unsigned multi-architecture Store MSIX bundle job passed and remains workflow-only
  • x64 release publish smoke, UI/accessibility, setup/connect E2E, network recovery E2E, revocation recovery E2E, proof-pool contracts, CodeQL, and C# security passed
  • pwsh -NoProfile -File ./scripts/test-dev-msix-release.ps1 (pass)
  • pwsh -NoProfile -File ./scripts/test-ci-workflow-contract.ps1 (pass)
  • dotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore --filter FullyQualifiedName~ReleaseSigningWorkflowTests (4 passed)
  • .agents/skills/autoreview/scripts/autoreview --mode branch --base origin/main (clean after the signature-validation repair)

Local macOS note: ./build.ps1 correctly refuses a non-Windows host, and the full Windows-specific test projects fail on macOS-only APIs/path semantics. The exact-head native Windows CI results above provide the required closeout.

Real behavior proof

  • migrated all 9 affected historical releases (v2026.9.5-alpha.9 through v2026.9.5-alpha.84) to verified signed x64/ARM64 Dev MSIX ZIPs
  • no signed source artifacts were missing or expired
  • verified each historical release contains both non-empty signed ZIP assets, no longer contains the unsigned Store MSIX release assets, and links its original Actions run for the retained unsigned submission artifacts
  • exact-head Windows CI built, validated, and uploaded signed x64 and ARM64 Dev artifacts while separately composing the unsigned Store submission bundle as a workflow artifact
  • the staging test creates exactly the two release ZIPs and rejects source, identity, run, allocation, hash, certificate, and Authenticode signer mismatches before producing partial output

Architecture handoff

  • Old owner: release job plus Stage-StoreMsixReleaseAssets.ps1 published unsigned Partner Center inputs.
  • New owner: release job plus Stage-DevMsixReleaseAssets.ps1 publishes validated signed Dev tester archives.
  • Preserved invariant: unsigned Store artifacts are still built, validated, bundled, and CI-gated, but remain workflow-only.

@clawsweeper

clawsweeper Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@RomneyDa RomneyDa added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Oct 2, 2026
@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Oct 2, 2026
@clawsweeper

clawsweeper Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed October 2, 2026, 6:25 AM ET / 10:25 UTC (Revision 3).

ClawSweeper review

What this changes

The branch publishes signed development MSIX installer archives for x64 and ARM64 on tagged releases, validates their provenance and signatures, and retains unsigned Store submission packages in Actions.

Merge readiness

✅ Ready for maintainer review

This PR remains necessary: main still publishes unsigned Store submission assets. No blocking defect was found, and the previously requested Windows validation is now recorded with passing checks for the exact head.

Priority: P2
Reviewed head: 252910ce43a1b825c73877717d778e21463063a3

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused release-pipeline repair with passing exact-head Windows validation and no identified blocking defect.
Proof confidence 🌊 off-meta tidepool Not applicable: The member-authored PR is exempt from ordinary contributor proof. Exact-head Windows jobs exercised real package building and export; public release metadata corroborates the historical download migration. Synthetic staging tests supplement those observations, while the tagged publishing job itself skipped on the PR event. No stored-data contract changes.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The member-authored PR is exempt from ordinary contributor proof. Exact-head Windows jobs exercised real package building and export; public release metadata corroborates the historical download migration. Synthetic staging tests supplement those observations, while the tagged publishing job itself skipped on the PR event. No stored-data contract changes.
Evidence reviewed 6 items Pinned introduced changes: Reviewed the introduced delta from d090a81 to 252910c. Main uses the Store release stager; this branch replaces it with development-package staging. Existing EXE and portable ZIP downloads remain.
Validation precedes publication: Both architectures must match the reserved allocation, clean source commit, workflow run, manifest identity, package version, package hash, public certificate hash, and valid Authenticode signer before output archives are created. The exact four-file allowlist excludes private-key and unrelated payload files.
Exact-head Windows validation: GitHub verifies that https://github.com/openclaw/openclaw-windows-node/actions/runs/36993252844 completed successfully for the pinned head. Job metadata confirms successful Windows build and full Shared/Tray test steps, both signed Dev package jobs, Store bundle construction, workflow contracts, and CI Gate. The captured PR body records 4,256 Shared tests passed with one skipped and 3,889 Tray tests passed, addressing the prior validation follow-up. Raw job-log retrieval was blocked by the reviewer network allowlist, so those counts were not independently extracted from logs.
Findings None None.
Security None None.

How this fits together

The release pipeline turns Windows build artifacts into public GitHub downloads. It separates development-signed sideloading packages for testers from unsigned packages intended for Microsoft Store submission.

flowchart TD
 A[Tagged source] --> B[Windows package builds]
 B --> C[Signed development packages]
 B --> D[Unsigned Store packages]
 C --> E[Provenance and signature checks]
 E --> F[Public release ZIPs]
 D --> G[Actions submission artifacts]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Keep signed tester downloads clearly separated from Store submission inputs, with provenance and signer validation before publication.

Do we have a high-confidence way to reproduce the issue?

Yes, from source: main attaches unsigned Store submission packages instead of the existing signed Dev tester packages. No target code was executed during this read-only review.

Is this the best way to solve the issue?

Yes. Reusing the existing signed artifacts and replacing the release stager avoids a competing build or signing path while preserving Store submission output.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against d090a8110fa3.

Labels

Label changes:

No label changes.

Label justifications:

  • P2: This improves public release downloads while preserving existing installer downloads and Store submission artifacts.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The member-authored PR is exempt from ordinary contributor proof. Exact-head Windows jobs exercised real package building and export; public release metadata corroborates the historical download migration. Synthetic staging tests supplement those observations, while the tagged publishing job itself skipped on the PR event. No stored-data contract changes.

Evidence

What I checked:

  • Pinned introduced changes: Reviewed the introduced delta from d090a81 to 252910c. Main uses the Store release stager; this branch replaces it with development-package staging. Existing EXE and portable ZIP downloads remain. (.github/workflows/ci.yml:1366, 252910ce43a1)
  • Validation precedes publication: Both architectures must match the reserved allocation, clean source commit, workflow run, manifest identity, package version, package hash, public certificate hash, and valid Authenticode signer before output archives are created. The exact four-file allowlist excludes private-key and unrelated payload files. (scripts/Stage-DevMsixReleaseAssets.ps1:45, 252910ce43a1)
  • Exact-head Windows validation: GitHub verifies that https://github.com/openclaw/openclaw-windows-node/actions/runs/36993252844 completed successfully for the pinned head. Job metadata confirms successful Windows build and full Shared/Tray test steps, both signed Dev package jobs, Store bundle construction, workflow contracts, and CI Gate. The captured PR body records 4,256 Shared tests passed with one skipped and 3,889 Tray tests passed, addressing the prior validation follow-up. Raw job-log retrieval was blocked by the reviewer network allowlist, so those counts were not independently extracted from logs. (.github/workflows/ci.yml:300, 252910ce43a1)
  • Historical public-download observations: GitHub release metadata confirms both non-empty Dev ZIP assets on all nine historical alpha releases from v2026.9.5-alpha.9 through v2026.9.5-alpha.84, with no raw Store MSIX release assets. This corroborates the reported migration of public downloads; it does not establish execution of the new tagged-release job, which correctly skipped on the PR event.
  • Signing and installation boundary: Release certificate trust is temporary, restricted to the current user's TrustedPeople store, and cleaned up using recorded newly imported thumbprints. Installation guidance explicitly describes development signing, requires user consent to certificate trust, and warns about upgrading the existing Dev identity. Package identity, persisted settings, and production signing policy are unchanged. This packages the Companion application, so the Gateway packaging dependency policy does not apply. (scripts/Export-DevMsixArtifact.ps1:127, 252910ce43a1)
  • Merged feature-history routing: Main history connects RomneyDa to Store bundle and every-release publication work, and Natalie Aguinaldo to the original artifact/export path and version allocation. GitHub independently confirms merged publication work at feat(msix): publish Store assets on every release #1453 and artifact work at chore(ci): build MSIX artifacts and publish Store alpha assets #1403. Historical blob retrieval failed during blame/show, so no source-line introduction attribution is asserted. (scripts/Export-DevMsixArtifact.ps1, d090a8110fa3)

Likely related people:

  • RomneyDa: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • natalie-aguinaldo: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (2 earlier review cycles)
  • reviewed 2026-10-02T10:01:21.211Z sha 39f9be3 :: needs changes before merge. :: none
  • reviewed 2026-10-02T10:06:47.989Z sha 252910c :: needs changes before merge. :: none

@RomneyDa

RomneyDa commented Oct 2, 2026

Copy link
Copy Markdown
Member Author

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🦞👀
Exact review queued.

Re-review progress:

@RomneyDa
RomneyDa merged commit 8d6da8a into main Oct 2, 2026
25 checks passed
@RomneyDa
RomneyDa deleted the openclaw/download-store-ready-msix-from-github-actions branch October 2, 2026 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant