Defect
The first real coherent release after #85/#87 published the immutable multi-architecture manager tag, then failed while making the new GHCR package public:
#43 pushing manifest for ghcr.io/sixtoad/leash-manager:native-v0.3.4@sha256:b2c03d7acf8b... done
INFO: Docker tags created ...
gh: Not Found (HTTP 404)
scripts/release.sh invokes:
gh api --method PUT "/user/packages/container/leash-manager/visibility" -f visibility=public
After the failure, both package endpoints resolve and report the package as private. No GitHub release or Git tag was created. A normal retry is then refused because the immutable manager tag exists, so the verified manager-first pipeline cannot recover without deleting or overwriting an immutable artifact.
Exact state
- source commit:
ea0d7df5ca7b5a9e1265dfe3ef742438d8011d38
- requested release:
native-v0.3.4
- manager:
ghcr.io/sixtoad/leash-manager:native-v0.3.4
- manager index digest:
sha256:b2c03d7acf8b34645b4a91b14394f6fbea84a7d177a99a1f746e2ddb2e81f746
- runnable children:
linux/amd64 and linux/arm64
- package API visibility:
private
- GitHub release/tag
native-v0.3.4: absent
- no Walk workload or credential was involved
Expected
The release uses the supported package-visibility operation and can safely resume after manager publication without deleting, retagging, or overwriting the immutable manager.
Acceptance
- use the correct GitHub Packages API method/endpoint for an authenticated user-owned container package
- bound and clearly diagnose visibility mutation/verification
- verify anonymous pull before CLI stamping/release creation
- add an explicit safe resume path for an existing manager tag when the Git tag and GitHub release are absent
- resume only after deep verification of the existing index: exact required platforms, distinct child manifests, architectures, full source revision, release version/channel, and manager contract labels
- resolve and embed the existing immutable digest; never push, delete, mutate, or retag it during resume
- refuse resume on any provenance, platform, label, contract, tag, or release mismatch
- focused tests cover fresh publication, visibility failure, matching resume, mismatched resume, and existing Git tag/release refusal
- the real
native-v0.3.4 recovery completes from the existing digest and publishes matching CLI archives/GitHub release
Blocks completion of native-v0.3.4 and the Leash #78 full Walk/BME/Codex ACP dogfood.
Defect
The first real coherent release after #85/#87 published the immutable multi-architecture manager tag, then failed while making the new GHCR package public:
scripts/release.shinvokes:gh api --method PUT "/user/packages/container/leash-manager/visibility" -f visibility=publicAfter the failure, both package endpoints resolve and report the package as private. No GitHub release or Git tag was created. A normal retry is then refused because the immutable manager tag exists, so the verified manager-first pipeline cannot recover without deleting or overwriting an immutable artifact.
Exact state
ea0d7df5ca7b5a9e1265dfe3ef742438d8011d38native-v0.3.4ghcr.io/sixtoad/leash-manager:native-v0.3.4sha256:b2c03d7acf8b34645b4a91b14394f6fbea84a7d177a99a1f746e2ddb2e81f746linux/amd64andlinux/arm64privatenative-v0.3.4: absentExpected
The release uses the supported package-visibility operation and can safely resume after manager publication without deleting, retagging, or overwriting the immutable manager.
Acceptance
native-v0.3.4recovery completes from the existing digest and publishes matching CLI archives/GitHub releaseBlocks completion of
native-v0.3.4and the Leash #78 full Walk/BME/Codex ACP dogfood.