From f44483df169fa5d54ac8967369f8d384b3ca6d32 Mon Sep 17 00:00:00 2001 From: 0xLeif Date: Wed, 29 Jul 2026 07:40:57 -0600 Subject: [PATCH] chore(specsync): archive release recovery change --- .../accepted-state.json | 37 ++++++ .../approvals.json | 14 +++ .../change.md | 2 +- .../context.md | 0 .../state.json | 5 +- .../tasks.md | 2 +- .../testing.md | 0 .../verification-attempts.json | 50 ++++++++ .../verification.json | 111 ++++++++++++++++++ 9 files changed, 217 insertions(+), 4 deletions(-) create mode 100644 .specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/accepted-state.json rename .specsync/{changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be => archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be}/approvals.json (60%) rename .specsync/{changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be => archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be}/change.md (97%) rename .specsync/{changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be => archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be}/context.md (100%) rename .specsync/{changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be => archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be}/state.json (94%) rename .specsync/{changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be => archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be}/tasks.md (86%) rename .specsync/{changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be => archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be}/testing.md (100%) create mode 100644 .specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/verification-attempts.json create mode 100644 .specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/verification.json diff --git a/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/accepted-state.json b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/accepted-state.json new file mode 100644 index 0000000..3d74cf0 --- /dev/null +++ b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/accepted-state.json @@ -0,0 +1,37 @@ +{ + "schema_version": 1, + "id": "CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be", + "slug": "fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be", + "title": "Fix release workflow fetch authentication so signed tags and attest notes can be fetched on GitHub-hosted runners", + "description": "Fix release workflow fetch authentication so signed tags and attest notes can be fetched on GitHub-hosted runners", + "kind": "bug_fix", + "state": "accepted", + "canonical_applied": true, + "base_commit": "7373d124ebb3823c1f7f19651dfffe4d7ed83f51", + "created_at": 1785303663, + "updated_at": 1785332430, + "affected_specs": [ + "aps-cli" + ], + "affected_paths": [ + ".github/workflows/release.yml", + "Scripts/test-release-distribution.sh", + "Scripts/test-release-provenance.sh", + ".specsync/change-sequence.json" + ], + "no_spec_change": true, + "no_spec_change_rationale": "This repairs CI authentication and checksum-generation plumbing without changing the aps CLI contract or release artifact semantics.", + "acceptance_criteria": [ + "Release fetches use one checkout-managed credential, the release distribution contract rejects manual duplicate Authorization headers, generated checksum sidecars begin with valid SHA-256 digests, and a v1.1.0 workflow dispatch passes through publication." + ], + "selected_artifacts": [ + "context", + "testing", + "tasks" + ], + "dependencies": [], + "answers": { + "architecture_risk": "no", + "public_contract": "no" + } +} diff --git a/.specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/approvals.json b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/approvals.json similarity index 60% rename from .specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/approvals.json rename to .specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/approvals.json index fbb934a..e68a6b8 100644 --- a/.specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/approvals.json +++ b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/approvals.json @@ -20,6 +20,20 @@ "timestamp": 1785331046, "digest": "bcc2722fe679c60135b60195f92a084146a758b34a1a1d38cebe7bebfb02d439", "note": "Refreshed after expanding the release recovery contract to validate checksum sidecars." + }, + { + "gate": "definition", + "actor": "codex", + "timestamp": 1785332275, + "digest": "e9cf36e22ba5c24c46985cf13d22af0918100b98395662a0eaa3bbf5d0d0fb34", + "note": "Release workflow, corrected assets, and Homebrew formula update completed successfully." + }, + { + "gate": "acceptance", + "actor": "codex", + "timestamp": 1785332430, + "digest": "219dc193013d771c252ef0a97798cf85d88d22ccaa6fd463072279d8321e75fc", + "note": "Accepted after v1.1.0 release recovery, asset checksum validation, and Homebrew formula convergence passed." } ], "reopenings": [] diff --git a/.specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/change.md b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/change.md similarity index 97% rename from .specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/change.md rename to .specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/change.md index eeeeab2..da662bb 100644 --- a/.specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/change.md +++ b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/change.md @@ -1,6 +1,6 @@ --- id: CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be -state: implementing +state: archived type: bug_fix base_commit: 7373d124ebb3823c1f7f19651dfffe4d7ed83f51 --- diff --git a/.specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/context.md b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/context.md similarity index 100% rename from .specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/context.md rename to .specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/context.md diff --git a/.specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/state.json b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/state.json similarity index 94% rename from .specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/state.json rename to .specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/state.json index d895027..3388add 100644 --- a/.specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/state.json +++ b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/state.json @@ -5,10 +5,11 @@ "title": "Fix release workflow fetch authentication so signed tags and attest notes can be fetched on GitHub-hosted runners", "description": "Fix release workflow fetch authentication so signed tags and attest notes can be fetched on GitHub-hosted runners", "kind": "bug_fix", - "state": "implementing", + "state": "archived", + "canonical_applied": true, "base_commit": "7373d124ebb3823c1f7f19651dfffe4d7ed83f51", "created_at": 1785303663, - "updated_at": 1785303960, + "updated_at": 1785332437, "affected_specs": [ "aps-cli" ], diff --git a/.specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/tasks.md b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/tasks.md similarity index 86% rename from .specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/tasks.md rename to .specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/tasks.md index 9c40677..54255ba 100644 --- a/.specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/tasks.md +++ b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/tasks.md @@ -9,4 +9,4 @@ artifact: tasks - [x] Add a regression contract for the release authentication configuration. - [x] Generate and validate complete SHA-256 sidecars for release assets. - [x] Run the local verification lane. -- [ ] Merge the repair and dispatch the existing v1.1.0 tag. +- [x] Merge the repair and dispatch the existing v1.1.0 tag. diff --git a/.specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/testing.md b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/testing.md similarity index 100% rename from .specsync/changes/CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/testing.md rename to .specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/testing.md diff --git a/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/verification-attempts.json b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/verification-attempts.json new file mode 100644 index 0000000..9f8727d --- /dev/null +++ b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/verification-attempts.json @@ -0,0 +1,50 @@ +{ + "schema_version": 1, + "attempts": [ + { + "timestamp": 1785332283, + "commit": "1c27f4f0477304071228b958e0c4cfdcf6a80713", + "contract_digest": "e9cf36e22ba5c24c46985cf13d22af0918100b98395662a0eaa3bbf5d0d0fb34", + "workspace_digest": "77792057c2c3d36dac81424c6a40034768023e246aa59a7a0562f22faf3eaceb", + "passed": false, + "commands": [ + { + "command": "fledge lanes run verify", + "success": false, + "exit_code": 1 + } + ], + "requirement_ids": [] + }, + { + "timestamp": 1785332293, + "commit": "1c27f4f0477304071228b958e0c4cfdcf6a80713", + "contract_digest": "e9cf36e22ba5c24c46985cf13d22af0918100b98395662a0eaa3bbf5d0d0fb34", + "workspace_digest": "77792057c2c3d36dac81424c6a40034768023e246aa59a7a0562f22faf3eaceb", + "passed": false, + "commands": [ + { + "command": "fledge lanes run verify", + "success": false, + "exit_code": 1 + } + ], + "requirement_ids": [] + }, + { + "timestamp": 1785332419, + "commit": "1c27f4f0477304071228b958e0c4cfdcf6a80713", + "contract_digest": "e9cf36e22ba5c24c46985cf13d22af0918100b98395662a0eaa3bbf5d0d0fb34", + "workspace_digest": "77792057c2c3d36dac81424c6a40034768023e246aa59a7a0562f22faf3eaceb", + "passed": true, + "commands": [ + { + "command": "fledge lanes run verify", + "success": true, + "exit_code": 0 + } + ], + "requirement_ids": [] + } + ] +} diff --git a/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/verification.json b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/verification.json new file mode 100644 index 0000000..c78eee1 --- /dev/null +++ b/.specsync/archive/changes/2026-07-29-CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be/verification.json @@ -0,0 +1,111 @@ +{ + "timestamp": 1785332419, + "commit": "1c27f4f0477304071228b958e0c4cfdcf6a80713", + "contract_digest": "e9cf36e22ba5c24c46985cf13d22af0918100b98395662a0eaa3bbf5d0d0fb34", + "workspace_digest": "77792057c2c3d36dac81424c6a40034768023e246aa59a7a0562f22faf3eaceb", + "acceptance_input_digest": "ecabd02776447c17eae1833a7cd200ac1b42473d4202694a2fb79f9c3e10887a", + "acceptance_manifest": { + "schema_version": 1, + "entries": [ + { + "path": ".github/workflows/release.yml", + "kind": "file", + "mode": 33188, + "payload_digest": "0d273ca287316a8b79d2c503055d2df5ce3e0bed68b039bcbef23bbb41c0825d", + "entry_digest": "b85e9701a484c212d8422746172182a9e124fa9dfc9e01d2adb5fde279d122a9", + "owners": [ + "@exact:delivery" + ] + }, + { + "path": ".specsync/change-sequence.json", + "kind": "file", + "mode": 33188, + "payload_digest": "3316e447068b12605eb1dfebe9ce81d6da9cde514f3afda6636ebe131346efab", + "entry_digest": "770fa59a871cb0e6dfd0065a883bfe0839ca930669b9384d5f8da0147db37098", + "owners": [ + "@exact:delivery" + ] + }, + { + "path": "Scripts/test-release-distribution.sh", + "kind": "file", + "mode": 33261, + "payload_digest": "c76a11572979f93b3ef0360f30818509786b7c48ad08332d0922c2920edf23ce", + "entry_digest": "29512d6d6bb58764d5612fff0acb1844c8b6d66ad9a1f336af2faf52d5392b91", + "owners": [ + "@exact:delivery" + ] + }, + { + "path": "Scripts/test-release-provenance.sh", + "kind": "file", + "mode": 33261, + "payload_digest": "e5a1aa2f99aa92be8c06a1e14ae5843cbbb257f35e2c86aff8ff862fa9c0eb6a", + "entry_digest": "0b928f0ad11577d09e8e2d4436a4686fa1972df4d1338252862645c0adfb8f10", + "owners": [ + "@exact:delivery" + ] + }, + { + "path": "specs/aps-cli/aps-cli.spec.md", + "kind": "file", + "mode": 33188, + "payload_digest": "6cc51c612445b96b9ad8314a1d60322749601edc1711afc2224fe2303b7c198d", + "entry_digest": "c56c9aa1007ceeb7ea1cfa011aa934fba624405b043512964ec334d4646cd65b", + "owners": [ + "aps-cli" + ] + }, + { + "path": "specs/aps-cli/context.md", + "kind": "file", + "mode": 33188, + "payload_digest": "b6b45cae19244f96b97854129adc5794b76623aa0547b5b5ba27fd20e522948f", + "entry_digest": "3d95dbf704bd5d40be4f8f4c95897cf6e5549152b4cdaab0adc43328febf8b90", + "owners": [ + "aps-cli" + ] + }, + { + "path": "specs/aps-cli/requirements.md", + "kind": "file", + "mode": 33188, + "payload_digest": "49fe2728a53958f51729fe450a942671a1f8218a2c7c02ca11126c6f8747af34", + "entry_digest": "4ffacf606390f2b8aa0efb0b0051966ed3e11365fdfd331d2965ab4a0ec00780", + "owners": [ + "aps-cli" + ] + }, + { + "path": "specs/aps-cli/tasks.md", + "kind": "file", + "mode": 33188, + "payload_digest": "83d2620192191bceccaa4a8758b8c7120300db800d7595309ddbc96ec6591525", + "entry_digest": "16ee871a59dd92753ba0d3be7f10aff13bd6a0d622abfada0d67073e6ccf0c90", + "owners": [ + "aps-cli" + ] + }, + { + "path": "specs/aps-cli/testing.md", + "kind": "file", + "mode": 33188, + "payload_digest": "adf0eef7df26d362d10062c886390a5fb518d457d84095fb3bf3e91ab7962fbc", + "entry_digest": "75ac0e1c823cbe6c2b5d97fd77e4e5f21176588ca6484893cc989c08e6d9b2cf", + "owners": [ + "aps-cli" + ] + } + ] + }, + "passed": true, + "commands": [ + { + "command": "fledge lanes run verify", + "success": true, + "exit_code": 0 + } + ], + "requirement_ids": [] +}