Skip to content

Fix GDAM publish input contract and prepare v0.0.3 - #16

Merged
nicodes merged 1 commit into
mainfrom
fix/168-publish-input-contract
Sep 16, 2026
Merged

nicodes merged 1 commit into
mainfrom
fix/168-publish-input-contract

Conversation

@nicodes

@nicodes nicodes commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

Summary

Tracks aviorstudio/fieldsofrevik#168 (kept open until the new release and production registry installation are verified).

  • Remove only the unsupported GDAM publish version input; keep the valid exact tag publication contract.
  • Pin the existing install action's valid version input to checksum-verified CLI v0.0.8, without changing the action revision.
  • Check actual release callers against verbatim SHA-256-verified immutable upstream action metadata in the shared CI/Release test action.
  • Include positive install.version, negative publish.version reinjection and typos, restored controls, required tag and unknown revision coverage.
  • Prepare approved patch v0.0.3; preserve v0.0.2 and all version-resolution, deterministic ZIP, tested-byte, and lifecycle controls.

CLI v0.0.8 commit ac84c9c5b5d6845e0de8335c9d0c46552ad8b7db internal/commands/publish.go derives @aviorstudio_gd-gesture.zip from GITHUB_REPOSITORY when asset is omitted. ZIP plus checksum is therefore not an asset-selection defect; no unrelated contract change is made.

Verification

  • Actual on-disk release workflow mutation reintroducing publish.version: canonical regression FAILED on undeclared input; restored suite PASS (6 tests).
  • Immutable metadata fresh-download byte comparison: PASS.
  • Package controls: PASS (2 tests); release-version controls: PASS (4 tests); resolver reports next patch v0.0.3.
  • Deterministic package SHA256: 869efdfad61d829fc3bfed8eb3ee074e0289de01f383c009f5a06f271e95242d.
  • Python compile, shell syntax, and git diff --check: PASS; no configured project formatter.
  • Full Godot/lifecycle checks will run in PR CI; local full suite is queued behind the shared heavy-test lease.

No gesture behavior/API or consumer repository changes. No independent review requested under the authorized workflow.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@nicodes
nicodes merged commit 59aafeb into main Sep 16, 2026
3 checks passed
@nicodes

nicodes commented Sep 16, 2026

Copy link
Copy Markdown
Member Author

Verification update: full canonical local suite also PASS with stock Godot 4.7.2 and source-pinned SHA512-verified archives, isolated HOME/XDG/TMPDIR. Package (2), release-version (4), action-contract (6), runner (12), Godot behavior (31 assertions), packaged editor enable/restart/smoke/web-export/disable/cleanup and consumer ownership all passed. Exact PR-head CI run 35045398926 and merge CI run 35045535652 are successful. Merge commit 59aafeb5b9fe75bc6f9e8403d775a11fa079a979 has the identical tested tree. Release run 35045553224 is pending terminal verification; tracking issue remains open.

@nicodes

nicodes commented Sep 16, 2026

Copy link
Copy Markdown
Member Author

#168 acceptance verified — gd-gesture v0.0.3

Verification and scope

Actual on-disk publish.version reinjection made the canonical new test fail, then restored suite passed. Six contract controls include valid install.version, invalid publish.version/typos, unknown revision and required tag. Immutable fixture files were fresh-byte-compared with the pinned upstream revision and their SHA256 values are enforced. Shared CI and Release run the regression without a skip guard.

Local full canonical package/resolver/input/runner tests (2/4/6/12), Godot behavior (31 assertions), packaged enable/restart/smoke, web export, disable/cleanup and consumer ownership checks all PASS with stock source-pinned SHA512-verified Godot 4.7.2/tools. Shell syntax, Python compilation, and diff whitespace checks PASS. No configured formatter. Self-inspected diff; no independent review gate.

User-visible effect: future releases reject invalid GDAM action inputs and use a reproducible CLI pin; v0.0.3 is installable. No gesture behavior/API changes, shared action edits, or consumer repository edits. Omitted asset was confirmed valid through CLI v0.0.8's repository-derived ZIP default; it was not mislabeled a defect. No production-game rollout, browser interaction test, or performance soak was performed; web export and packaged headless/editor lifecycle were verified. No remaining blocker for this bounded issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant