Skip to content

ci: regenerate exact-tag s390x release evidence - #79

Merged
loadingalias merged 1 commit into
mainfrom
fix/s390x-release-evidence
Aug 3, 2026
Merged

ci: regenerate exact-tag s390x release evidence#79
loadingalias merged 1 commit into
mainfrom
fix/s390x-release-evidence

Conversation

@loadingalias

Copy link
Copy Markdown
Owner

Summary

  • keep the s390x vector target environment visible to every CT subprocess
  • add a protected-main, immutable-tag dispatch for regenerating only the native s390x release artifact
  • accept replacement evidence only after exact workflow, commit, job, repository, and artifact validation
  • preserve the existing release bundle validator as the final authority

Validation

  • env -u BASH_ENV just check-actions
  • env -u BASH_ENV just check
  • env -u BASH_ENV just push-full
  • full workspace test run: 1,704 passed; one RSA Wycheproof case hit the 120-second local contention timeout
  • isolated timed-out case: passed in 102.328 seconds

Release recovery

After merge, dispatch ct.yaml from the merged main commit with platforms=ibm-s390x, raw artifacts, 90-day retention, and release_tag=v0.8.0. Then pass that validated run ID to the existing release.yaml recovery dispatch.

Keep the s390x vector target environment visible to every CT subprocess. Add a protected-main recovery dispatch that regenerates the native s390x artifact at an immutable release tag and accepts it only after workflow, commit, job, and artifact validation.
@loadingalias
loadingalias merged commit b1a8dc0 into main Aug 3, 2026
16 checks passed
@loadingalias
loadingalias deleted the fix/s390x-release-evidence branch August 3, 2026 23:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant