Skip to content

ci: bootstrap trusted publisher before feature runner adoption - #5175

Merged
ktechmidas merged 1 commit into
dashpay:chore/bump-rust-dashcore-secp-033from
infraclaw-dash:ci/secp-publisher-bootstrap-20260929
Sep 29, 2026
Merged

ktechmidas merged 1 commit into
dashpay:chore/bump-rust-dashcore-secp-033from
infraclaw-dash:ci/secp-publisher-bootstrap-20260929

Conversation

@infraclaw-dash

Copy link
Copy Markdown
Contributor

Summary

Install only the vetted trusted image-publisher caller on the exact chore/bump-rust-dashcore-secp-033 target before enabling candidate-dependent consumers in #5167. This is infraclaw's CI infrastructure repair, not application-code propagation.

Independent live inspection at base 49ad468a215fc4935eb43d74e4e8662a52b73f69 confirms that both the requirements manifest and runner-image-candidate.yml are absent, and #5167 current head 8251ef7a38469a2af00a0f04f19abf91f253e4b3 has no candidate publisher run. The review's bootstrap finding is valid: a publisher added only in an unmerged consumer PR cannot be treated as installed trusted orchestration on its target branch.

Scope and trust

  • One file, 33 lines: .github/workflows/runner-image-candidate.yml, byte-for-byte the already reviewed caller in ci: align secp feature-base workflows with provisioned runner images #5167.
  • Both controller references remain immutable 7d901150bd3d0789d50c46f365b058f2f5f1f52d; adoption of the newly merged reuse controller is separate.
  • pull_request_target loads trusted base orchestration. No PR checkout, inline job shell, self-hosted runner, new runner registration, or credential in source.
  • Existing manifest-only path filtering, draft/merge guards, isolated builder/publisher, and explicit registry secrets are preserved. Only the exact feature branch is added to the existing vetted branch patterns; no chore/* wildcard or expanded fork admission.
  • No requirements manifest, selector, consumer workflow, application code, application test, or live host is changed by this prerequisite.

Validation

12 focused structural checks pass: exact vetted caller content, trusted event/path, exact branch scope, both immutable controller pins, minimal permissions, explicit secrets, no untrusted checkout/shell, no consumer activation, draft/merge guards, and no new worker authority. YAML parsing and git diff --check pass. These checks do not claim actual candidate publication, compatible worker execution, or target adoption.

Ordered rollout / merge hold

  1. Obtain real independent reviews and ordinary owner/protected merge approval for this bootstrap.
  2. Verify this PR is MERGED, its exact merge SHA, and that the publisher file is installed on the live target branch.
  3. Only then synchronize ci: align secp feature-base workflows with provisioned runner images #5167 with that installed base through an ordinary reviewed update and verify fresh exact-head candidate publication. Existing fork worker skips remain intentional; do not bypass them to manufacture execution.
  4. Keep ci: align secp feature-base workflows with provisioned runner images #5167 on hold until its own latest-head reviews and applicable protected checks clear. Validate admitted downstream Rust/Kotlin execution after normal adoption.

Checklist

  • I have performed a self-review of my own code
  • I have added or updated relevant unit/integration/functional/e2e tests (12 focused bootstrap-contract checks recorded with this repair)
  • I have made corresponding changes to the documentation if needed (ordered bootstrap boundary documented above)
  • Required independent owner/bot review and ordinary merge gates complete
  • Exact target installation and downstream candidate execution verified

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: dashpay/platform/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 645e16fc-91ab-4f22-87d4-bd0eb2203617

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ktechmidas
ktechmidas requested a review from shumkov September 29, 2026 05:19
@thepastaclaw

thepastaclaw commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Final review complete — no blockers (commit 7b63fc6) · triage: low

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Final validation — Phase 1 + Phase 2

Verified the exact head 7b63fc6 against the supplied base: the change adds only the 33-line trusted publisher caller, matching the locally available v4.2-dev caller except for the exact feature-branch filter. YAML parsing, structural assertions, and diff whitespace checks passed; no in-scope defects were identified. External controller isolation, live target installation, candidate publication, and downstream execution were not independently verified here and remain separate rollout validations.

Review provenance

Source: reviewer 1: glm-5.3-flash (agent: phase1-reviewer, role: general); reviewer 2: glm-5.3-flash (agent: phase1-reviewer, role: architecture-layering); reviewer 3: glm-5.3-flash (agent: phase1-reviewer, role: security-auditor); reviewer 4: gpt-6-astra (agent: phase2-reviewer, role: general); reviewer 5: gpt-6-astra (agent: phase2-reviewer, role: architecture-layering); reviewer 6: gpt-6-astra (agent: phase2-reviewer, role: security-auditor); final verifier: gpt-6-astra (agent: astra-verifier, role: final-verifier)

  • Triage: low by gpt-6-astra (effort low) — The diff adds a small, self-contained 33-line CI caller with pinned controller references and explicit event, branch, permission, and secret boundaries, making correctness straightforward to verify without changing application logic or a qualifying critical surface.
  • Phase 1 reviewers: glm-5.3-flash — general (completed, effort high); agent phase1-reviewer, glm-5.3-flash — architecture-layering (completed, effort high); agent phase1-reviewer, glm-5.3-flash — security-auditor (completed, effort high); agent phase1-reviewer
  • Phase 1 model: glm-5.3-flash — zai quota: 5h 86% left, weekly 90% left; passed over gemini-3.8-flash-high (antigravity below 15% reserve: weekly 13% left, 5h 100% left)
  • Fresh verifier: gpt-6-astra — final-verifier; agent astra-verifier
  • Phase 2 reviewers: gpt-6-astra — general (completed, effort medium); agent phase2-reviewer, gpt-6-astra — architecture-layering (completed, effort medium); agent phase2-reviewer, gpt-6-astra — security-auditor (completed, effort medium); agent phase2-reviewer

@ktechmidas
ktechmidas merged commit e2fd47d into dashpay:chore/bump-rust-dashcore-secp-033 Sep 29, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants