Skip to content

[4/4] feat(runtime): validate releases and finalize lifecycle safeguards - #124

Open
MarcStdt wants to merge 4 commits into
codex/runtime-accepted-release-updatesfrom
codex/runtime-release-descriptor-read
Open

MarcStdt wants to merge 4 commits into
codex/runtime-accepted-release-updatesfrom
codex/runtime-release-descriptor-read

Conversation

@MarcStdt

@MarcStdt MarcStdt commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Scope of this layer

Reproducible authored-release hashes using SOURCE_DATE_EPOCH and deterministic layer order; bounded read-only semantic validator and build packaging; final scoped runtime safeguards, protected ownership/glob handling, failure regression coverage and acceptance evidence.

Review order

Review reproducibility and validator tests, then the existing final safeguards commit e4aadf2 and real Docker ownership coverage. Baseline general ownership/queue/crash-recovery repairs remain deliberately outside this feature.

Native GitHub stack #126, bottom to top:

  1. [1/4] feat(registry): preserve release manifest #122 — feat(registry): preserve release manifest
  2. [2/4] fix(runtime): make backups restore-safe #123 — fix(runtime): make backups restore-safe
  3. [3/4] feat(runtime): apply accepted release digests #125 — feat(runtime): apply accepted release digests
  4. [4/4] feat(runtime): validate releases and finalize lifecycle safeguards #124 — feat(runtime): validate releases and finalize lifecycle safeguards

GitHub's Files changed tab is incremental against the preceding branch. Review the complete stack before landing: later layers contain final fixes and cleanup for earlier layers. The old consolidated/superseded descriptions and draft acceptance notes are historical and replaced by this reconstruction.

Unchanged implementation

Reconstructed from existing commits only: no source edits, rebases, squashes or force-pushes. The complete stack tip is e4aadf2816bfec4f4642cf2ae130ca82401b5fd9, tree 7d6c9fb61e07900ec756fef2437b495c230a4585, exactly the previously verified local tree. Existing commits, discussion and PR identities are retained; only the runtime update boundary needed a new PR.

Verification and rollout

Local verification recorded on October 3 for the complete final implementation: 112 lifecycle/UI tests (11 opt-in skips in the default run); separate real Harbor/Postgres integration (2 passed); authenticated publisher import/retry/publication; SPA type-check; full CLI and engine commands; uncached publisher/workflow checks; focused race runs; rebuilt Docker/Kubernetes acceptance. Browser/workload evidence is complementary and qualified, not one uninterrupted end-to-end run. Four legacy Core compilation failures and the documented baseline active-workload backup/queue issues remain outside scope. These results do not assert every historical intermediate layer independently passed the final suite or that fresh remote CI is green.

See the final local requirement audit for exact commands, qualifications and rollout order. Ready for review does not mean merged or deployed. Matching Core/engine/runtime contracts must ship together; configure the public runtime API URL when GAME_HOST is not that API. Protected Team publishing environments/identity/secrets must exist before activating the workflow cutover; its fail-closed gate remains intact.

Companion changes: monorepo stack, runtime stack, standalone publisher. No production mutation or merge is part of this reconstruction.

Honor SOURCE_DATE_EPOCH and sort discovered root layers. Identical

publisher retries otherwise conflict on creation times or map order.

Preserve immutable-tag checks; verify repeated pushes and live retries.
Reuse runtime validation through a bounded stdin protocol for Core.

Do not read config, expand host variables, execute commands, or echo

untrusted input. Reject invalid procedures, mounts and release metadata.
Build/install the read-only helper with the existing CLI workflow.

Record runtime parity tests and the pinned Core image smoke result.
@MarcStdt MarcStdt changed the title feat(runtime): apply accepted Scroll releases feat(runtime): unify Scroll release lifecycle Sep 28, 2026
@MarcStdt
MarcStdt changed the base branch from codex/scroll-runtime-backup-orchestration to master September 28, 2026 01:43
Preserve protected files during staged updates and keep failed maintenance stopped. Exclude the previously deferred general runtime repairs.

Recover the reviewed September 29 local state from session history into a durable workspace. Full Go suite and focused race tests pass.
@MarcStdt
MarcStdt changed the base branch from master to codex/runtime-accepted-release-updates October 4, 2026 16:21
@MarcStdt
MarcStdt marked this pull request as ready for review October 4, 2026 16:21
@MarcStdt
MarcStdt added this pull request to stack #126 October 4, 2026 16:21
@druid-infra

Copy link
Copy Markdown
Contributor
Error: This repo is not allowlisted for Atlantis.

@MarcStdt MarcStdt changed the title feat(runtime): unify Scroll release lifecycle [4/4] feat(runtime): validate releases and finalize lifecycle safeguards Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants