Repository navigation
ci: verify exact headless qualification receipts in result job - #299
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
The advisory headless result job downloads only this run/attempt's seven exact final artifacts (never bootstrap handoffs). A bounded verifier checks the actual release binary and Cargo.lock hashes against the build manifest, checks source/run/attempt/nonce commitments and role pairing, rejects missing/malformed/stale/failed-cleanup receipts, and validates completed public/private, Linux-managed and MCP journeys. MCP emits source and binary only; its run/attempt and lock binding comes from the exact artifact and successful job rather than fictitious receipt fields. Browser, per-byte direct-path and independent-NAT qualification remain explicitly unclaimed.
Checks
8 new verifier tests; 20 public, 29 private and 19 measurement tests passed locally.
actionlint .github/workflows/headless-qualification.ymland stagedgit diff --checkpassed. Full local discovery is blocked by this macOS sandbox's denial of test-created/tmpdirectories; the hosted Ubuntu build job executed it.Required passed at PR head 792a059 (run 37874440144) and at merged main 4aab282 (run 37875429376). The exact-head advisory workflow through
.herd-live(request headless-result-792a0596-20261009, run 37875227613) passed every role and the aggregate result; host receipt says completed/success, cost $0. This is not browser, per-byte direct-path or independent-NAT qualification.CI timing
Previous slowest
Rust/Requiredworkflow median: 10m41s over five recent successful main runs (created/updated timestamps). New observed median: ~10m37s across the two exact-change Required runs (PR 11m55s, merged main 9m18s); sample size two, no >1m median regression. Advisory headless workflow remains outside Required.Scope
Only
.github/workflows/headless-qualification.ymland its new result verifier and focused tests changed. No browser/Iroh transport, Railway or production code changed.