Repository navigation
improve(ci): overlap release asset preparation with validation - #1616
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed October 2, 2026, 8:19 PM ET / October 3, 2026, 00:19 UTC (Revision 2). ClawSweeper reviewWhat this changesThe PR moves installer signing and portable ZIP preparation into an earlier job, then hands those assets to the publisher after full validation succeeds. Merge readiness✅ Ready for maintainer review The optimization remains useful and is not implemented on the pinned main revision. No actionable defect was found, and exact-head Windows CI passed. Priority: P3 Review scores
Verification
How this fits togetherThe release workflow turns tagged Windows builds into signed installers, portable ZIPs, and Dev MSIX downloads. Validation gates control when those artifacts become a public GitHub release. flowchart TD
A[Release tag] --> B[Builds and early tests]
B --> C[Sign and prepare installers and ZIPs]
B --> D[Remaining validation]
C --> E[Prepared asset artifact]
D --> F[Full CI gate]
E --> G[Gated release publisher]
F --> G
G --> H[Public release downloads]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Keep one signing runner and a same-run artifact handoff while preserving full validation and release-ordering checks at publication. Do we have a high-confidence way to reproduce the issue? Not applicable to a bug reproduction: the existing serial dependency is visible in the pinned main workflow. Is this the best way to solve the issue? Yes. Splitting preparation from publication is a focused scheduling change that preserves asset paths, signing policy, and the final CI gate. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against f879af8a5661. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (1 earlier review cycle)
|
What Problem This Solves
Release signing and packaging currently wait for the full CI gate, leaving several minutes of serial work on the release critical path.
User Impact
User impact: tagged Windows releases can finish sooner with no change to published artifacts or release gating.
Why This Change Was Made
This moves the existing serial signing and packaging steps into an early
prepare-release-assetsjob after the release-critical contract, core, tray, and architecture build jobs pass. The final publisher still waits forci-gate, revalidates stable release ordering, stages the MSIX bundle, and creates the GitHub release.The change keeps a single preparation runner and uses an uncompressed artifact handoff, reducing critical-path latency without duplicating signing compute.
Evidence
ReleaseSigningWorkflowTestspassed at commitca1edf07.Change Type
Scope
winnodeRequired proof pools
none: this changes the GitHub Actions release DAG and artifact handoff only; no capacity-dependent product behavior is affected.Validation
pwsh -NoProfile -File ./scripts/test-ci-workflow-contract.ps1: passed.dotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --filter FullyQualifiedName~ReleaseSigningWorkflowTests --no-restore --verbosity minimal: 5 passed, 0 failed, 0 skipped../build.ps1: blocked on managed Windows capacity. Azure provisioning did not yield a usable lease; brokered AWS leasecbx_50cdfa494ca4lacked .NET and the Windows SDK.dotnet test ./tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj --no-restore: not verified on Windows due to the same capacity blocker.dotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore: not verified on Windows due to the same capacity blocker.Real Behavior Proof
ca1edf07ci-gate, publication requires bothprepare-release-assetsandci-gate, and the prepared artifact is handed off at unchanged release paths.Yes/No/N/A): N/ASecurity Impact
Yes/No): NoYes/No): NoYes/No): NoYes/No): NoYes/No): NoYes, explain the risk and mitigation: N/ACompatibility and Migration
Yes/No): YesYes/No): NoYes/No): NoReview Conversations