Skip to content

feat(release): publish manifest for development releases - #3445

Closed
shiju-nv wants to merge 1 commit into
NVIDIA:mainfrom
shiju-nv:feat/2946-core-runtime-identity-manifest/shiju-nv
Closed

shiju-nv wants to merge 1 commit into
NVIDIA:mainfrom
shiju-nv:feat/2946-core-runtime-identity-manifest/shiju-nv

Conversation

@shiju-nv

@shiju-nv shiju-nv commented Sep 18, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Development releases have no single published record of what a build contains. This PR publishes an attested openshell-release-manifest.json with each development release. It ties the standalone CLI, gateway, sandbox and supervisor archive checksums and the gateway, sandbox and supervisor image digests to one source commit and workflow run. Publication stops before development release assets are replaced if any input is missing, duplicated or inconsistent. RFC 0014 says each development release identifies its source commit and artifact manifest; the release has no such manifest today.

Related Issue

Closes #3458

Changes

  • Record each image's source commit, workflow run, OCI index and platform digests, and staged executable hashes in the job that produced it.
  • Validate the complete standalone CLI, gateway, sandbox and supervisor archive inventory: checksums, archive contents, target architecture, and agreement with the staged image executables.
  • Reject malformed, missing, duplicated or mismatched records before publishing. A retry of downstream assembly may reuse completed image jobs from the same source and workflow run.
  • Assemble and attest the manifest before development assets are replaced, then publish it with the archives. Release Tag is unchanged.
  • Document what the manifest covers in the installation page, and update the release-diagnostic skills to separate manifest verification from canary coverage.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated
  • E2E tests added/updated (if applicable)

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

@drew
drew requested a review from SDAChess September 18, 2026 05:52
@shiju-nv
shiju-nv force-pushed the feat/2946-core-runtime-identity-manifest/shiju-nv branch from acca946 to 2a95ab6 Compare September 18, 2026 17:32
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown

This pull request has had no activity for 14 days and is now marked stale. It may be closed in 7 days if there is no further activity.

@github-actions github-actions Bot added the state:stale Inactive item at risk of automatic closure. label Oct 3, 2026
Bind standalone core archives and container images to their producing source
commit and workflow run. Verify archive bytes, executable architecture and
image executable hashes before assembling and attesting the development
release manifest.

Preserve same-run retry support while rejecting inconsistent identities.
Document the inventory limits, installation workflow and release diagnostics.

Related to NVIDIA#2946. Cross-workflow artifact resolution and packaging reuse
remain separate work.

Signed-off-by: Shiju <shiju@nvidia.com>
@shiju-nv
shiju-nv force-pushed the feat/2946-core-runtime-identity-manifest/shiju-nv branch from 2a95ab6 to 57a16a3 Compare October 4, 2026 15:29
@shiju-nv shiju-nv changed the title feat(release): publish immutable core runtime identity manifest feat(release): publish manifest for development releases Oct 4, 2026
@drew

drew commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

This is too much extra CI infra. We already carry the dev version of each release.

@drew drew closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state:stale Inactive item at risk of automatic closure.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Know which OpenShell binaries and images belong to a development build

2 participants