Skip to content

Retry an existing release without building a new ZIP - #17

Merged
nicodes merged 1 commit into
mainfrom
fix/gdam-release-recovery
Sep 27, 2026
Merged

nicodes merged 1 commit into
mainfrom
fix/gdam-release-recovery

Conversation

@nicodes

@nicodes nicodes commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Add a protected-main retry path to the release workflow so a failed GDAM publish can reuse an existing immutable GitHub release.
  • Retry requires retry-tag and retry-sha256 together. It checks that the tag commit is the current main commit or an ancestor, that plugin.cfg matches at the tag and on main, that the GitHub release target matches the tag, and that the downloaded @aviorstudio_gd-network.zip digest matches the pin. It does not build a package or create a tag or release.
  • Pin GDAM install to v0.0.8, verify that version, publish @aviorstudio/gd-network asset @aviorstudio_gd-network.zip, and drop the unsupported version input. The normal bump path is unchanged aside from those publish inputs.
  • Negative controls cover a bad tag, digest, target, partial retry inputs, a non-ancestor tag, plugin mismatch, and duplicate release creation.

Recovery dispatch (do not run from this PR)

Dispatch only from protected main after GDAM_SECRET_KEY selected-repo visibility includes this repository, and only when explicitly authorized:

gh workflow run Release --repo aviorstudio/gd-network --ref main \
  -f bump=patch \
  -f retry-tag=v0.0.4 \
  -f retry-sha256=85e7dc926971ee210af309e577c816300f83cfdef64ca131c4be5e785450c047

bump is ignored when both retry inputs are set. This does not move tag v0.0.4 or replace its asset. Expected release target remains 5db6b7fcafe79cc3809cd9cb27438ff5b64f6ea9.

Test plan

  • shellcheck on the recovery script and negative-control test
  • ./tests/release_recovery_test.sh (controls=26 reached=11)
  • Read-only plan/recheck/recover against the existing v0.0.4 release and ZIP digest 85e7dc926971ee210af309e577c816300f83cfdef64ca131c4be5e785450c047
  • Bump dispatch against current plugin.cfg 0.0.4 is refused (v0.0.5 is not created)
  • Exact-head ci on this PR

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

A failed registry publish must be able to reuse the immutable GitHub
release. Retry checks protected main, tag ancestry, plugin version,
release target, and ZIP digest, then refuses to create another release.
@nicodes
nicodes merged commit 49fd510 into main Sep 27, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant