Skip to content

chore: add managed Bark qualification workflow - #49

Merged
orangeshyguy21 merged 3 commits into
mainfrom
bark-prep
Oct 6, 2026
Merged

orangeshyguy21 merged 3 commits into
mainfrom
bark-prep

Conversation

@orangeshyguy21

Copy link
Copy Markdown
Owner

New Features

  • Managed Bark qualification — a new CI workflow restores retained native Bark images (server, processor, CLN hold) on a clean runner. It verifies checksums, provenance and offline probes, then runs the bark-processor acceptance gate. It is dispatchable from component-images.yml with family=bark-qualification.
  • Bark xtask commands — bark-restore, bark-stage and bark-evidence handle restoring, staging and recording qualification evidence.
  • Acceptance cache inputs — proofstorm-acceptance --image-cache-inputs bark-processor prints the exact images the gate needs, without creating a runtime.

Changes

  • Platform-keyed Bark image pins — the Bark catalog reads its image digests from an embedded bark_images.json. Qualification can stage verified amd64 or arm64 images. Platforms with no entry stay out of the catalog.
  • Component images workflow — adds a candidate_run input and a read-only actions permission. Concurrency is now scoped per family and architecture, and only pull requests auto-cancel.
  • Release docs — new scripts/BARK-RELEASING.md covers qualification and the publication handoff. RELEASING.md now points to it.

Note

Green Checks do not qualify or publish the Bark images. Run the separate Bark handoff before a release that distributes them.

Testing

  • scripts/test-bark-qualification.sh is added and wired into scripts/check.sh, along with its shellcheck coverage.
  • New xtask unit tests cover the Bark restore and stage logic.

- Add a CI workflow and xtask commands (`bark-restore`, `bark-stage`, `bark-evidence`) that qualify retained native Bark images on a clean runner. Add the supporting scripts, a release handoff doc, and the acceptance `--image-cache-inputs` flag.
- Move the Bark catalog image pins into an embedded `bark_images.json` keyed by platform, so qualification can stage verified amd64 or arm64 images. Platforms with no entry stay out of the catalog.
- Resolve the outermost .app as the desktop bundle and probe the current nested CodexCLI.app layouts, not just Contents/Resources/codex.
- Add tests for old and current bundle layouts and for PATH symlinks into the nested CLI app.
- Check Cargo's JSON `fresh` field instead of grepping the human-readable "Fresh" log line.
- CI forces colored output, which broke the grep.
@orangeshyguy21
orangeshyguy21 merged commit c0b3166 into main Oct 6, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant