fix(release): publish signed MSIX downloads - #1600
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed October 2, 2026, 6:25 AM ET / 10:25 UTC (Revision 3). ClawSweeper reviewWhat this changesThe branch publishes signed development MSIX installer archives for x64 and ARM64 on tagged releases, validates their provenance and signatures, and retains unsigned Store submission packages in Actions. Merge readiness✅ Ready for maintainer review This PR remains necessary: main still publishes unsigned Store submission assets. No blocking defect was found, and the previously requested Windows validation is now recorded with passing checks for the exact head. Priority: P2 Review scores
Verification
How this fits togetherThe release pipeline turns Windows build artifacts into public GitHub downloads. It separates development-signed sideloading packages for testers from unsigned packages intended for Microsoft Store submission. flowchart TD
A[Tagged source] --> B[Windows package builds]
B --> C[Signed development packages]
B --> D[Unsigned Store packages]
C --> E[Provenance and signature checks]
E --> F[Public release ZIPs]
D --> G[Actions submission artifacts]
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Technical reviewBest possible solution: Keep signed tester downloads clearly separated from Store submission inputs, with provenance and signer validation before publication. Do we have a high-confidence way to reproduce the issue? Yes, from source: main attaches unsigned Store submission packages instead of the existing signed Dev tester packages. No target code was executed during this read-only review. Is this the best way to solve the issue? Yes. Reusing the existing signed artifacts and replacing the release stager avoids a competing build or signing path while preserving Store submission output. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against d090a8110fa3. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
History |
|
@clawsweeper re-review |
|
🦞👀 Re-review progress:
|
Summary
OpenClaw-Dev-x64.zipandOpenClaw-Dev-arm64.zipRequired proof pools
none: this changes release artifact selection and validation, not product runtime, UI, gateway, node-command, or installer behavior requiring a custom host class.Validation
pwsh -NoProfile -File ./scripts/test-dev-msix-release.ps1(pass)pwsh -NoProfile -File ./scripts/test-ci-workflow-contract.ps1(pass)dotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore --filter FullyQualifiedName~ReleaseSigningWorkflowTests(4 passed).agents/skills/autoreview/scripts/autoreview --mode branch --base origin/main(clean after the signature-validation repair)Local macOS note:
./build.ps1correctly refuses a non-Windows host, and the full Windows-specific test projects fail on macOS-only APIs/path semantics. The exact-head native Windows CI results above provide the required closeout.Real behavior proof
v2026.9.5-alpha.9throughv2026.9.5-alpha.84) to verified signed x64/ARM64 Dev MSIX ZIPsArchitecture handoff
Stage-StoreMsixReleaseAssets.ps1published unsigned Partner Center inputs.Stage-DevMsixReleaseAssets.ps1publishes validated signed Dev tester archives.