Skip to content

fix: preflight real optimized fork publication without unused debuginfo - #9

Merged
moomooskycow merged 3 commits into
mainfrom
fix/optimized-fork-publication
Oct 1, 2026
Merged

moomooskycow merged 3 commits into
mainfrom
fix/optimized-fork-publication

Conversation

@moomooskycow

@moomooskycow moomooskycow commented Oct 1, 2026 •

Copy link
Copy Markdown

Purpose

Repair the real first automatic fork publication failure and make ordinary PR CI exercise the genuine native production compiler path before merge. This does not restore a human release gate.

Observed unsuccessful publication and bounded hypothesis

PR #8 merged normally as eb7ca4b191dcca92f9d932d73fdfafe55177c8af. Main CI 36809970889 passed. Its automatic publication 36811119394 prepared the real fork signing trust root and built the Windows installer successfully, but the Apple Silicon job reached the 90-minute platform deadline. Mac dependencies compiled through 03:48:44, followed by silence until cancellation at 05:05:47; an orphan rustc remained. Native provider conclusions are cancelled, not failure/timed_out. No candidate or healthy channel was published. Actual intake has no receipt for this run because the existing cancellation-noise policy excludes it.

The workspace release profile enables fat LTO, one codegen unit, size optimization and full debuginfo. Existing native cache's release step is cargo check --release, not optimized binary/link compilation. [INFERENCE] unused full debuginfo adds unacceptable compiler/link pressure on bounded native runners. A subsequent real successful artifact, not this hypothesis, is required as completion evidence.

Change and boundaries

  • One real scripts/build-fork.sh entrypoint runs cap-setup, the actual release muxer sidecar and actual Tauri optimized build with the production config. Both PR CI and trusted-main production use it.
  • Omit embedded release debuginfo while retaining fat LTO, the single codegen unit, size optimization, target triples, standard native runners and 90-minute limit.
  • An 80-minute real process deadline runs the shared producer inside the unchanged 90-minute native job. Overdue compiler trees are stopped and the command exits124 before platform cancellation, allowing the normal failure intake to process a genuine failed run. No cancellation classifier broadening, direct webhook emission, new grant or fake probe.
  • Every native desktop CI job now uses the actual optimized production compile, with --no-bundle only for its credential-free preflight. It uses existing public runtime defaults, no repository-secret references and only a read-only checkout token. No fake signing keys, new PR credentials, publication or remote trust substitution.
  • Real updater signing, installer packaging, immutable publication, downloaded-installed native smoke and healthy-channel promotion still happen only after successful same-repository main push CI. The preflight cannot prove those private/published surfaces.
  • Preserve updater signing identity, real privacy/OS-consent boundaries and normal review/CI/merge. No timeout bump, paid runner, scanner/admin bypass or hand-published rescue.
  • Existing README documents the preflight limitation, release-symbol choice and actual signed intake receipt plus natural agent triage instead of requesting new hook-administration permissions.

Exercised verification

  • bash -n scripts/build-fork.sh apps/desktop/scripts/verify-fork-artifacts.sh apps/desktop/scripts/smoke-fork-macos.sh: passed.
  • Both modified workflows parsed as YAML.
  • Throwaway actual Cargo consumer: with the same release profile and CARGO_PROFILE_RELEASE_DEBUG=0, rustc retained -C opt-level=s -C lto -C codegen-units=1, omitted full debuginfo and used -C strip=debuginfo; its compiled executable ran successfully. Fixture removed. This does not substitute for native CI/deployment.
  • Actual subprocess regression covers nonzero compiler exit propagation and forced deadline termination of a nested compiler before it can write its artifact. The same tests run on both genuine native CI targets.
  • Strict System One staged diff gate passed; source-text/wiring test advisories are not addressed with tautological permanent tests. Real native CI and actual publication are the required behavioral proof.

Agent-facing alert evidence

The existing deliberate probe 36810011277 has actual signed intake receipt r90group:fd6995e9d57be7d2e153875c557703bccffb8f808de7b53a91d97294cd638d59, received 2026-10-01T03:20:02.324Z and naturally triaged done/test 2026-10-01T03:23:03.609Z without a ticket or human inbox. It preceded the later exact alert_route_probe: yes directive: observed marker/name classification is not proof of that exact emitted tag. Hook-delivery HTTP 200 was not independently observed; the signed stored receipt was. No further probes emitted.
The real unsuccessful publication36811119394 has no native intake receipt: its conclusion was cancelled and the policy intentionally excludes cancelled runs. The bounded real producer deadline repairs that signal boundary without emitting a new probe or classifying real incidents as tests.

Existing real default-branch failure CI36784226990 has complete native intake receipt r90group:8491cdcba50dcf458cda8afe22d47c28f6c72380677240d877e4faf8b4e57004, rule .github/workflows/ci.yml, received2026-09-30T22:19:51.405Z and naturally triaged done/incident→INF100 at2026-09-30T22:23:15.049Z. Fresh native Habitat read confirmed INF100 Done revision2, id fe1bdc1c-d709-4d3e-985d-fa43ba8a01c6, with its independently owned repair PR7 preserved. The native CLI returned no UI URL, so none is guessed. This is loud real agent-incident route evidence, not a receipt for the cancelled publisher run.

Models

Implementation requested Sol/high; actual parent task route was openai-codex/gpt-6.1-sol / max, without fallback. Fresh exact-head native independent review for 288dbecbb52a057a0fab7c48367b7237835b487c used actual anthropic/claude-sonnet-5-5 / high, resolvedModelIsFallback=false, and returned APPROVE/no concrete blockers; primary model/thinking metadata observed2026-10-01T05:53:28.721Z. Durable exact-head review. Earlier05e1/PR8 approvals are not reused. Actual native CI and subsequent publication/smoke/promotion remain required, not inferred.

Deadline implementation uses documented Node detached process groups on POSIX and Windows taskkill /T /F for the actual producer tree. It does not introduce a new release approval.

@moomooskycow

Copy link
Copy Markdown
Author

Fresh exact-head independent model review

Reviewed head: 288dbecbb52a057a0fab7c48367b7237835b487c.
Verdict: APPROVE — no concrete code blockers.
Actual native model route: anthropic/claude-sonnet-5-5 / high, resolvedModelIsFallback=false, machine-parsed from the primary review session model/thinking metadata (2026-10-01T05:53:28Z). Author session is a separate Sol implementation session. Earlier05e1 approval is not reused.

The reviewer specifically examined actual shared production-config argument forwarding, Bash3.2/Windows execution, real process-tree deadline expiry/exit124 and child failure propagation, release optimization preserved with debuginfo0, private signing key excluded from cap-setup/muxer, read-only credential-free native preflight and unchanged trusted-main signing/publication gate. No blocker found.

Non-blocking limits: the1s local nested-compiler test start marker may be timing-sensitive on a cold Windows host; actual native CI is authoritative. Runner-initiated cancellation can still discard an orphaned group; intended cancellation remains excluded, not reclassified. Native minimal-env preflight, Mac optimized artifact, private signing/provider publication, downloaded-installed native startup/screenshot and healthy-channel promotion must still be observed. Neither this review nor local tests claim a completed deployment or prove the debuginfo hypothesis.

Normal required/scanner/native CI must be green on this exact head before normal --match-head-commit merge. No admin/bypass/release-approval gate.

@moomooskycow

Copy link
Copy Markdown
Author

Exact-head normal CI and real publisher preflight

CI36821733710 completed success on reviewed head 288dbecbb52a057a0fab7c48367b7237835b487c. All normal format, typecheck, Clippy, native build and Rust-cache jobs passed; the existing path-filtered plugin verifier was legitimately skipped.

Actual credential-free shared production publisher-path preflight passed on both genuine targets/images:

  • Apple Silicon aarch64-apple-darwin / macos-14 job110238655261:31m23s.
  • Windows x64 x86_64-pc-windows-msvc / windows-2022 job110238655283:31m31s.
    Both ran and passed the actual subprocess failure/deadline regressions, then completed the real optimized sidecar/Tauri production-config --no-bundle compile under the bounded shared entrypoint. Minimal public-default .env and native Windows process launch/tree termination consumers are now exercised, not merely plausible. No private signing key or provider publication was used by preflight.

Fresh exact-head independent Sonnet5.5/high approval is metadata-verified/no fallback. Normal exact-head merge is authorized; no admin, scanner/check bypass, paid runner or human per-release release gate.

The Apple Silicon optimized compile is now observed complete without the previous silent90minute cancellation. This is not yet private signing, installer packaging, published candidate, downloaded-installed startup/screenshot or healthy-channel promotion proof: the subsequent real automatic default-branch publication remains mandatory.

@moomooskycow
moomooskycow merged commit dc0e922 into main Oct 1, 2026
13 checks passed
@moomooskycow

Copy link
Copy Markdown
Author

Completed real automatic fork desktop deployment

Source: dc0e92208e5a8c5944033117be3fc12cc71aa858 — repair PR9 merged normally from exact independently reviewed head 288dbecbb52a057a0fab7c48367b7237835b487c; fresh Sonnet5.5/high review, no fallback, and normal native PR CI36821733710 passed before merge. Main push CI36824645589 passed and automatically triggered the real publication, without a dispatch or human release approval.

Deploy: publish36827618997 completed success for that exact source; native version 0.4.3091.

  • Apple Silicon real optimized/ad-hoc-signed bundle build110257046042:25m39s.
  • Windows x64 real installer/updater-signing build110257045938:37m31s.
  • Actual updater signatures and signed checksum inventory verified; complete immutable candidate release110268307334 published.
  • Downloaded-published-candidate install/launch smoke passed: Mac110268609593/43s and Windows110268609569/54s.
  • Published bytes re-downloaded and authenticated against pinned existing fork signing root, then healthy-channel promotion110268899872 passed/42s. Reject correctly skipped.

Immutable deployment: release id 400740299, public/non-draft prerelease internal-dc0e92208e5a8c5944033117be3fc12cc71aa858, target_commitish exactly the source above. Real Mac DMG and signed Cap.app.tar.gz, Windows Cap_0.4.3091_x64-setup.exe plus signature, source/target manifests, public fork key, authenticated SHA256SUMS and immutable latest.json are published.

Post-deploy readback: unauthenticated plain healthy updater endpoint returned version:0.4.3091, source_revision:dc0e92208e5a8c5944033117be3fc12cc71aa858, both real immutable native updater URLs and signatures. Parent independently observed this same run/readback.

Real native surface proof: downloaded both smoke artifacts and visually inspected their actual screenshots: macOS and Windows each rendered the real blue-cloud Welcome to Cap / Get Started onboarding window, not just a title or log. Both installed-app result.json records bind version0.4.3091 and the exact source; Mac additionally confirms arm64/ad-hoc codesign and updater archive's exact installed-binary/version match. Startup logs confirm executable-adjacent real cap-muxer. Mac artifact 11147346067 smoke-aarch64-apple-darwin-1; Windows artifact 11147243475 smoke-x86_64-pc-windows-msvc-1, retained on the deploy run. Windows runner logged a software-renderer warning but displayed the actual surface; no warning was suppressed.

Loud agent-facing failure evidence: existing real default-branch CI36784226990 has native signed intake receipt r90group:8491cdcba50dcf458cda8afe22d47c28f6c72380677240d877e4faf8b4e57004, received2026-09-30T22:19:51.405Z, naturally triaged done/incident→INF100 at2026-09-30T22:23:15.049Z. Native Habitat confirmed INF100 Done/revision2, id fe1bdc1c-d709-4d3e-985d-fa43ba8a01c6, independently owned PR7 preserved. No UI URL was returned, so none is guessed. The earlier deliberate probe36810011277 also has signed receipt and done/test triage, but predates the exact-tag directive and does not prove an emitted alert_route_probe: yes or separately observed hook HTTP200.

The previous unsuccessful publisher36811119394 concluded cancelled and had no intake receipt; it is not claimed alerted. The shared80minute actual process deadline now exits124 before the unchanged90minute native job cancellation boundary. Actual local Bash smoke and nested compiler regression proved failure classification/tree termination; both genuine native CI platforms also passed those tests. No classifier broadening, new grant, direct webhook or new probe.

Preserved boundaries/limits: existing fork updater identity unchanged; Mac ad-hoc, not notarized/DeveloperID; Windows not Authenticode-signed. Smoke used disposable fresh install and exercised startup, not private recordings/authenticated uploads/Railway runtime or end-user OS-consent flows. Mac runner already reported OS grants; workflow did not grant them. Legacy upstream-trust clients still need one explicit fork-installer install. No paid runner, timeout bump, scanner/admin bypass or fake key.

Implementation requested Sol/high; actual implementation route Sol/max without fallback was disclosed. Actual independent exact-head review is Sonnet5.5/high/no fallback. Existing README/AGENTS define the clean automatic-publication procedure; no harness source was modified. Owned cleanup follows this observed complete deployment, while foreign canonical fix/native-rust-ci is preserved.

@moomooskycow
moomooskycow deleted the fix/optimized-fork-publication branch October 1, 2026 07:56
@moomooskycow

Copy link
Copy Markdown
Author

Owned resource/session closure after observed deployment

Native CD deliverable is complete, with actual signed deploy/native surface/channel receipts.

Removed only owned, completed resources normally: /home/phaedrus/development/r90group/Cap-cd worktree (without force), local and origin ci/fork-cd and fix/optimized-fork-publication refs, and the matching owned worktree lease. Owned temporary proof/review-input scaffolds were removed after receipts became durable. Native exact-head reviewer primary sessions for final PR8/PR9 are retained as non-live provenance evidence, not worktrees/leases. No owned background process or temporary VM remains.

Preserved foreign canonical /home/phaedrus/development/r90group/Cap on original fix/native-rust-ci at78913; no force/reset/delete/default-repository change. Its native gh default points upstream CapSoftware/Cap, while actual PR/deploy commands explicitly targeted r90group/Cap. The landing checker uses gh without --repo, so its old merged-head negatives were wrong-target facts; this tool limitation was reported, not worked around by changing harness/source or erasing records. Historicalbb78 rebase checkpoint remains recorded as superseded owned history.

Supported session-close park scopes all records by commonDir and canonical-alignment blockers affect each; it cannot selectively park one record. With parent authorization, all4 Cap landing records are honestly parked/unverified, with an explicit note that the CD implementation/deploy is complete and only the original foreign owner's canonical-alignment/context decision is retained. Safe resume: original owner inspect/preserve foreign state, then authorize normal alignment to fetched origin/main. Do not rerun old cancelled publisher36811119394 or claim it alerted.

Final session-close check --json returned exit0/statusparked, no owned Cap lease, and absence of the owned CD worktree verified. This is not a selective-landed or globally-clean claim. session-close review reported18 uncertain expired foreign resources; they were left untouched.

@moomooskycow

Copy link
Copy Markdown
Author

Independent signing/redelivery and real failure-route proof

The initial ping for existing hook689911713 returned401 on2026-09-30T22:11:05.066Z. A subsequent signed ping on the SAME hook returned200 at22:12:06.638Z. No rotation of the currently working secret was performed.

The original failed ping GUID d3f8f8d2-bd1b-11f1-9693-59265a80ee3b was redelivered through GitHub, not a forged direct POST. Actual redelivery3845805612669599744 at2026-10-01T08:19:52.318Z returned HTTP200 / {"status":"pong"}, redeliverytrue. The GitHub scheduling response202 is not confused with the observed Worker200. Signature verification precedes the pong branch.

Real failure proof is separate from that ping: actual delivery3845728301295337472 at2026-09-30T22:19:51.444Z was completed workflow_run36784226990, repositoryr90group/Cap, branchmain, conclusionfailure. Worker returnedHTTP200 with accepted alert id r90group:8491cdcba50dcf458cda8afe22d47c28f6c72380677240d877e4faf8b4e57004. Fresh fully paginated pending+done ledger read returned exactly one corresponding row: projectCap/resourcegithub_workflow_run/rule.github/workflows/ci.yml, naturallydone/incident→INF-100 at22:23:15.049Z. Not dismissed as test, noise or duplicate. No new failure probe or ticket/ack mutation.

Duplication/ownership: native repository inventory contains exactly ONE intake webhook689911713, eventsworkflow_run+deployment_status, activeJSON/SSLverificationenabled, /github/r90group. The other hook is a foreign pull_request/Vulcan route, not an intake duplicate. The existing LIVE route guard excludes forks in _active_repo; native GitHub identifies r90group/Cap forktrue, so this hook fills a fork gap rather than duplicating a guard-created route. No additional hook/cron/direct emission was created. Organization-hook enumeration is not claimed: current native token lacks admin:org_hook; no scope grant requested.

Previous publisher36811119394 concludedcancelled and is still NOT claimed to have alerted. New source/current healthy-channel proof is unchanged. These receipts supplement the completed deployment evidence, not a claim that a successful publication generated an incident.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant