release: Qualify exact artifacts before publish - #52
BenWestgate wants to merge 2 commits into
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@claude review. |
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated review (Claude), posted at the maintainer's request.
Concept ACK f4f9a48. Two things before merge:
- Trigger: it still runs on
release: published, so the GitHub release and tag are public before any gate runs, and a failed qualification leaves a public release with no assets. For "qualify before publish", trigger onpush: tags: ['v*']and havepublishcreate the release, or publish a draft from the workflow. - 3.15 with #36: the matrix comes from classifiers, so once #36 lands it includes 3.15.
setup-pythonhere lacksallow-prereleases: true, so a release cut before 3.15.0 final fails that leg.
Smaller:
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated review, posted at the maintainer's request.
Concept ACK a653876. The release now qualifies on tag push, Core tests the built wheel, prerelease Python is supported, and GitHub stays draft until PyPI publication succeeds.
No remaining code blocker from my review. First tag remains the required end-to-end validation of the release workflow.
|
Release-gate sequencing: defer final review of this publication workflow until the prerequisite runtime/CI gates settle. In particular, merge #7 then #51 (wallet/Core qualification) and #50 then refreshed #47 (active test-workflow hardening/assurance), then refresh #52 once on the resulting |
|
Release-monitor refresh (2026-09-27/28): upstream |
|
Agent release-gate review at current head |
Build distributions once, qualify the exact wheel and sdist across the supported Python/OS matrix, run optimized/static/differential and real-Core checks, and publish only after those jobs pass. Record source SHA, dependency environments, Bitcoin Core version, artifact hashes, and qualification results in a release provenance bundle. Scrub PYTHONPATH and user-site imports in installed-artifact checks so the source checkout cannot satisfy the test accidentally. Security: release qualification uses pinned Bitcoin Core v32.0rc2 bytes and read-only permissions until the final publication job. Validation: 865 normal and 865 optimized tests passed; mypy, Ruff check/format, build and Twine passed; exact wheel and sdist both passed isolated installed-package verification with PYTHONPATH deliberately contaminated; workflow YAML parses successfully. Fixes #5.
a653876 to
9cf9f44
Compare
Fixes #5.
Build the wheel and sdist once, then qualify those exact bytes before anything becomes public.
Review stack
Base: #59 (
codex/4-security-boundary-docs). Current head:9cf9f44.The reviewed release-qualification patches were replayed onto the current stack. The second patch retains its stable patch ID. The first differs only because
import codex32is already present upstream; its remaining release-qualification changes are unchanged. All prior review threads remain resolved.Bitcoin Core v32 pin
bitcoin/bitcoinpublished the cryptographically verified annotated tagv32.0rc3on 2026-10-01 (verified: true,reason: valid). However, the official Bitcoin Core 32.0 binary index still publishes onlytest.rc2/;test.rc3/SHA256SUMScurrently returns 404. Therefore this workflow deliberately remains pinned to the available, hash-verified rc2 binary until official rc3 binaries are published. Do not invent or substitute an unofficial rc3 hash.Validation
On the stacked candidate:
python -O;git diff --checkpassed.The workflow-only tag-push publication path cannot execute on the PR itself; the first real release tag still requires the normal PyPI environment approval and exact-artifact checks.