Enforce an executable release freeze barrier - #1622
Conversation
…558-true-idle-boundary
…558-true-idle-boundary
…558-true-idle-boundary
…58-true-idle-boundary
…558-true-idle-boundary # Conflicts: # .github/scripts/check-workflow-policy.test.mjs
…558-true-idle-boundary
Independent verifier repair — workflow execution context authenticatedHead: The rejected manifest authenticated the four The v2 manifest now authenticates the canonical parsed Executed hostile mutationsEach mutation was applied to the real workflow, accepted by actionlint, rejected by workflow policy with
The persistent generated matrix also mutates workflow triggers, token permissions, concurrency, name, a new Exact-head focused verification
No broad source proof, calibration, package proof, hardware proof, merge, or release action was started. The PR remains draft and remains a parallel nonblocking lane for 0.16.3. |
|
Exact-head fixture repair pushed: The canonical evidence evaluator regenerated Focused verification on this repair:
No broad source proof, calibration, package proof, hardware proof, merge, or release was dispatched. |
|
Independent exact-head acceptance completed at
No broad source proof, calibration, package proof, or hardware proof was dispatched for this support PR. |
Closes #1621
Context
Broad release proof could start before all source work was integrated, later source changes did not immediately cancel obsolete work, and “independently accepted exact head” had no executable definition.
PR #1597 owns calibration, the generated constant-set freeze, and qualification for 0.16.3. This PR is a nonblocking follow-up that owns executable freeze receipts, hostile/native acceptance, cancellation, and proof-trigger policy.
Because this branch contains #1597 head
c72c87a963b81c626530958078b9f54f8f47efc5plus later workflow/source changes, merging it before release would revoke that frozen candidate. It must stay out of the 0.16.3 lineage and may land after release.What changed
AGENTS.md;.github/scripts/release-freeze-acceptance-jobs.json;release-claims.json.The complete-job manifest replaces the rejected command substring scanner. Any command, shell, environment, condition, permission-relevant field, dependency, output, step, or step-order change changes the authenticated job digest.
Exact support head
d94e8e6c55a970aab72bf31aee76e6be3df72a730a8740bef070ff290580afbff9836e6ae246cd1bc72c87a963b81c626530958078b9f54f8f47efc5Both the current #1597 merge tree and the explicit integration-base merge tree are conflict-free.
Adversarial revisions
The first review rejected
d79c298ebecause arbitrary Ubuntu and Windows acceptance jobs could run broad tests, the receipt ordered source proof before calibration, and the branch conflicted with #1597.The second review rejected
4e63f63dbecause approved step bodies could still hide broad work through variables, aliases, functions, delegated scripts, command chaining, and alternate shells.This revision authenticates the entire parsed job bodies. Executed regressions cover:
In a disposable clone of this exact pushed head, actionlint accepted syntactically valid Ubuntu and Windows variable mutations while workflow policy exited 1 and named both changed canonical jobs.
Focused verification
git diff --check, and both merge-tree checks: passed.No broad source, package, calibration, qualification, hardware, or release workflow was dispatched from this PR.
Release handoff
c72c87a963b81c626530958078b9f54f8f47efc5, owned by Make embedding calibration GPU-only and measure true idle correctly #1597; this support head is not part of it.30564679306onc72c87a963b81c626530958078b9f54f8f47efc5. No Auto Release run is in flight.The PR remains draft and unmerged. It does not block 0.16.3, and its focused PR checks are not release evidence.
Risk
The manifest intentionally makes acceptance-job changes explicit and reviewable. Updating one of those jobs requires updating the manifest, its claim-graph digest, policy tests, and exact-head hostile evidence together.