Skip to content

improve(ci): overlap release asset preparation with validation - #1616

Merged
RomneyDa merged 1 commit into
mainfrom
openclaw/optimize-release-job-parallelization
Oct 3, 2026
Merged

RomneyDa merged 1 commit into
mainfrom
openclaw/optimize-release-job-parallelization

Conversation

@RomneyDa

@RomneyDa RomneyDa commented Oct 2, 2026

Copy link
Copy Markdown
Member

What Problem This Solves

Release signing and packaging currently wait for the full CI gate, leaving several minutes of serial work on the release critical path.

User Impact

User impact: tagged Windows releases can finish sooner with no change to published artifacts or release gating.

Why This Change Was Made

This moves the existing serial signing and packaging steps into an early prepare-release-assets job after the release-critical contract, core, tray, and architecture build jobs pass. The final publisher still waits for ci-gate, revalidates stable release ordering, stages the MSIX bundle, and creates the GitHub release.

The change keeps a single preparation runner and uses an uncompressed artifact handoff, reducing critical-path latency without duplicating signing compute.

Evidence

  • Focused workflow contract passed.
  • All 5 ReleaseSigningWorkflowTests passed at commit ca1edf07.
  • Structured autoreview completed with no accepted or actionable findings.
  • Exact-head GitHub Actions results will provide the authoritative Windows validation because managed Windows provisioning was unavailable locally.

Change Type

  • Bug fix
  • Feature
  • Refactor
  • Docs or instructions
  • Tests or validation
  • Security hardening
  • Chore or infrastructure

Scope

  • Tray or WinUI UX
  • Windows node capability
  • Local MCP or winnode
  • Gateway, connection, or pairing
  • Setup or onboarding
  • Permissions, privacy, or security
  • Tests, CI, or docs

Required proof pools

  • none: this changes the GitHub Actions release DAG and artifact handoff only; no capacity-dependent product behavior is affected.

Validation

  • pwsh -NoProfile -File ./scripts/test-ci-workflow-contract.ps1: passed.
  • dotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --filter FullyQualifiedName~ReleaseSigningWorkflowTests --no-restore --verbosity minimal: 5 passed, 0 failed, 0 skipped.
  • ./build.ps1: blocked on managed Windows capacity. Azure provisioning did not yield a usable lease; brokered AWS lease cbx_50cdfa494ca4 lacked .NET and the Windows SDK.
  • dotnet test ./tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj --no-restore: not verified on Windows due to the same capacity blocker.
  • dotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore: not verified on Windows due to the same capacity blocker.

Real Behavior Proof

  • Environment tested: macOS focused contract tests; GitHub-hosted Windows exact-head validation pending.
  • PR head or commit tested: ca1edf07
  • Exact steps or command run: workflow contract script and filtered release-signing workflow test command above.
  • Evidence after fix: contract assertions verify preparation excludes ci-gate, publication requires both prepare-release-assets and ci-gate, and the prepared artifact is handed off at unchanged release paths.
  • Observed result: focused contract and 5 tests passed.
  • Screenshot or artifact links verified? (Yes/No/N/A): N/A
  • Not verified or blocked: full native Windows closeout was blocked by managed-runner provisioning and prerequisites; GitHub Actions will validate the pushed head.

Security Impact

  • New permissions or capabilities? (Yes/No): No
  • Secrets or tokens handling changed? (Yes/No): No
  • New or changed network calls? (Yes/No): No
  • Command or tool execution surface changed? (Yes/No): No
  • Data access scope changed? (Yes/No): No
  • If any answer is Yes, explain the risk and mitigation: N/A

Compatibility and Migration

  • Backward compatible? (Yes/No): Yes
  • Config or environment changes? (Yes/No): No
  • Migration needed? (Yes/No): No
  • If yes, list the exact upgrade steps: N/A

Review Conversations

  • I replied to or resolved every bot review conversation addressed by this PR.
  • I left unresolved only conversations that still need maintainer judgment.

@clawsweeper

clawsweeper Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@RomneyDa RomneyDa added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Oct 2, 2026
@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Oct 2, 2026
@clawsweeper

clawsweeper Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed October 2, 2026, 8:19 PM ET / October 3, 2026, 00:19 UTC (Revision 2).

ClawSweeper review

What this changes

The PR moves installer signing and portable ZIP preparation into an earlier job, then hands those assets to the publisher after full validation succeeds.

Merge readiness

✅ Ready for maintainer review

The optimization remains useful and is not implemented on the pinned main revision. No actionable defect was found, and exact-head Windows CI passed.

Priority: P3
Reviewed head: ca1edf07c7b0ef02e672db8d97919cf35e8a9083

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused infrastructure change with passing exact-head validation and no actionable correctness findings.
Proof confidence 🌊 off-meta tidepool Not applicable: The MEMBER-authored PR is exempt from the external-contributor proof gate. Contracts and exact-head Windows CI passed, but preparation and publication were skipped on the PR event, so the new tag-only handoff has not been demonstrated. No stored-data contract changes.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The MEMBER-authored PR is exempt from the external-contributor proof gate. Contracts and exact-head Windows CI passed, but preparation and publication were skipped on the PR event, so the new tag-only handoff has not been demonstrated. No stored-data contract changes.
Evidence reviewed 6 items Introduced change and necessity: The pinned main workflow performs signing inside the release job after ci-gate. The introduced diff splits preparation from publication; it contains no base-only changes.
Publication and security boundaries: Preparation retains the release-signing environment and tag restriction, receives read-only contents permission, and uses the existing signing actions. Publication retains contents:write, requires both preparation and ci-gate success, and preserves stable-ordering and MSIX provenance checks.
Artifact layout contract: The workflow directly uses this dependency for the new handoff. Its documented multiple-path behavior uses the least common ancestor as the artifact root, preserving Output/ installers alongside root-level ZIPs: https://github.com/actions/upload-artifact#upload-using-multiple-paths-and-exclusions.
Findings None None.
Security None None.

How this fits together

The release workflow turns tagged Windows builds into signed installers, portable ZIPs, and Dev MSIX downloads. Validation gates control when those artifacts become a public GitHub release.

flowchart TD
  A[Release tag] --> B[Builds and early tests]
  B --> C[Sign and prepare installers and ZIPs]
  B --> D[Remaining validation]
  C --> E[Prepared asset artifact]
  D --> F[Full CI gate]
  E --> G[Gated release publisher]
  F --> G
  G --> H[Public release downloads]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Release pipeline scope 1 job split; 4 assets transferred Signing remains centralized while publication continues to wait for full validation.
Workflow and test delta workflow +40/-5; validation and tests +50/-2; application production +0 Growth supports the new job boundary and its contract coverage without changing application behavior.

Technical review

Best possible solution:

Keep one signing runner and a same-run artifact handoff while preserving full validation and release-ordering checks at publication.

Do we have a high-confidence way to reproduce the issue?

Not applicable to a bug reproduction: the existing serial dependency is visible in the pinned main workflow.

Is this the best way to solve the issue?

Yes. Splitting preparation from publication is a focused scheduling change that preserves asset paths, signing policy, and the final CI gate.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against f879af8a5661.

Labels

Label changes:

No label changes.

Label justifications:

  • P3: This is a bounded release-latency improvement with no demonstrated user-facing regression.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The MEMBER-authored PR is exempt from the external-contributor proof gate. Contracts and exact-head Windows CI passed, but preparation and publication were skipped on the PR event, so the new tag-only handoff has not been demonstrated. No stored-data contract changes.

Evidence

What I checked:

  • Introduced change and necessity: The pinned main workflow performs signing inside the release job after ci-gate. The introduced diff splits preparation from publication; it contains no base-only changes. (.github/workflows/ci.yml:1163, ca1edf07c7b0)
  • Publication and security boundaries: Preparation retains the release-signing environment and tag restriction, receives read-only contents permission, and uses the existing signing actions. Publication retains contents:write, requires both preparation and ci-gate success, and preserves stable-ordering and MSIX provenance checks. (.github/workflows/ci.yml:1370, ca1edf07c7b0)
  • Artifact layout contract: The workflow directly uses this dependency for the new handoff. Its documented multiple-path behavior uses the least common ancestor as the artifact root, preserving Output/ installers alongside root-level ZIPs: https://github.com/actions/upload-artifact#upload-using-multiple-paths-and-exclusions. (README.md)
  • Exact-head Windows validation: Run https://github.com/openclaw/openclaw-windows-node/actions/runs/37069164078 succeeded for the pinned head. Workflow contracts, Shared tests, Tray tests, UI/E2E suites, and MSIX builds passed. The changed tag-only preparation and release jobs were skipped, so this run does not demonstrate their execution. No build or test was executed by this read-only review. (.github/workflows/ci.yml, ca1edf07c7b0)
  • Merged release history: Git history identifies Dallin Romney's prior release-workflow changes, including signed MSIX publication and machine-wide certificate trust. GitHub verifies fix(release): trust downloaded Dev MSIX certificates machine-wide #1607 (fix(release): trust downloaded Dev MSIX certificates machine-wide) as merged; it addresses certificate trust rather than this scheduling optimization. (tests/OpenClaw.Tray.Tests/ReleaseSigningWorkflowTests.cs, 4e285bbc6595)
  • Review continuity and inspection limits: The prior completed review covered the same head and recorded no findings or published rank-up moves. Source and diff inspection succeeded, but deeper blame and historical blob reads encountered a promisor-object HTTP 403; no source-line introduction attribution is claimed. No applicable nested AGENTS.md or maintainer-notes directory was found. (ca1edf07c7b0)

Likely related people:

  • RomneyDa: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (1 earlier review cycle)
  • reviewed 2026-10-02T21:53:53.045Z sha ca1edf0 :: needs maintainer review before merge. :: none

@RomneyDa RomneyDa removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Oct 3, 2026
@RomneyDa
RomneyDa merged commit dcc6afe into main Oct 3, 2026
63 of 67 checks passed
@RomneyDa
RomneyDa deleted the openclaw/optimize-release-job-parallelization branch October 3, 2026 01:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant