feat(release): channel records name the attempt archive

Stable archives live under the attempt ref, but channel records only
carried releaseTag, so the protected prefix check rejected the bytes the
pipeline actually writes. An optional archiveRef on the request names the
attempt archive; validators and readers use it for the releases/tag/
prefix and fall back to releaseTag, which fails closed for stable
records without it. Canary records never write the field.
This commit is contained in:
ethernet
2026-09-23 12:20:26 -04:00
parent b37f37b692
commit 3f2e40f07d
8 changed files with 193 additions and 6 deletions

View File

@@ -373,7 +373,8 @@ def publish_release(policy: str, env: dict, root: Path) -> dict:
source_version = payload_tag[1:].split("+", 1)[0]
request = publisher.allocate_protected(name, commit, source_version, release_tag=payload_tag,
version=payload_tag[1:], windows_version=windows["version"],
identity=identity, policy=policy, release_gate=release_gate)
identity=identity, policy=policy, release_gate=release_gate,
archive_ref=tag if parsed else None)
manifest, feeds = assemble(request, native, root, artifact_prefix=f"releases/tag/{tag}/")
if accepted is not None:
match_accepted_packages(manifest, accepted)

View File

@@ -214,12 +214,15 @@ class ChannelPublisher:
def allocate_protected(self, name: str, commit: str, source_version: str, *,
release_tag: str, version: str, windows_version: str,
identity: dict, policy: str, release_gate) -> dict:
identity: dict, policy: str, release_gate,
archive_ref: str | None = None) -> dict:
"""Reserve accepted legacy bytes, never authorize a custom build as stable."""
facts = {"schema": 1, "channel": name, "repository": self.repository, "commit": commit,
"sourceVersion": source_version, "version": version, "windowsVersion": windows_version,
"releaseTag": release_tag, "identity": deepcopy(identity), "bundleEnv": {},
"publicBase": self.public_base}
if archive_ref is not None:
facts["archiveRef"] = archive_ref
build_id = hashlib.sha256(canonical_json(facts)).hexdigest()[:32]
key = build_prefix(build_id) + "request.json"
for _ in range(16):