Skip to content

release: package visibility 404 strands immutable manager tag #88

Description

@sixtoad

Defect

The first real coherent release after #85/#87 published the immutable multi-architecture manager tag, then failed while making the new GHCR package public:

#43 pushing manifest for ghcr.io/sixtoad/leash-manager:native-v0.3.4@sha256:b2c03d7acf8b... done
INFO: Docker tags created ...
gh: Not Found (HTTP 404)

scripts/release.sh invokes:

gh api --method PUT "/user/packages/container/leash-manager/visibility" -f visibility=public

After the failure, both package endpoints resolve and report the package as private. No GitHub release or Git tag was created. A normal retry is then refused because the immutable manager tag exists, so the verified manager-first pipeline cannot recover without deleting or overwriting an immutable artifact.

Exact state

  • source commit: ea0d7df5ca7b5a9e1265dfe3ef742438d8011d38
  • requested release: native-v0.3.4
  • manager: ghcr.io/sixtoad/leash-manager:native-v0.3.4
  • manager index digest: sha256:b2c03d7acf8b34645b4a91b14394f6fbea84a7d177a99a1f746e2ddb2e81f746
  • runnable children: linux/amd64 and linux/arm64
  • package API visibility: private
  • GitHub release/tag native-v0.3.4: absent
  • no Walk workload or credential was involved

Expected

The release uses the supported package-visibility operation and can safely resume after manager publication without deleting, retagging, or overwriting the immutable manager.

Acceptance

  • use the correct GitHub Packages API method/endpoint for an authenticated user-owned container package
  • bound and clearly diagnose visibility mutation/verification
  • verify anonymous pull before CLI stamping/release creation
  • add an explicit safe resume path for an existing manager tag when the Git tag and GitHub release are absent
  • resume only after deep verification of the existing index: exact required platforms, distinct child manifests, architectures, full source revision, release version/channel, and manager contract labels
  • resolve and embed the existing immutable digest; never push, delete, mutate, or retag it during resume
  • refuse resume on any provenance, platform, label, contract, tag, or release mismatch
  • focused tests cover fresh publication, visibility failure, matching resume, mismatched resume, and existing Git tag/release refusal
  • the real native-v0.3.4 recovery completes from the existing digest and publishes matching CLI archives/GitHub release

Blocks completion of native-v0.3.4 and the Leash #78 full Walk/BME/Codex ACP dogfood.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions