Skip to content

Docs: record native build provenance - #11

Merged
tony merged 1 commit into
masterfrom
docs-site-provenance
Sep 30, 2026
Merged

tony merged 1 commit into
masterfrom
docs-site-provenance

Conversation

@tony

@tony tony commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

The native docs build now records the selected source, native exporter and shared docs revisions before generation. The uploaded content has an exact artifact descriptor, which the shared publisher verifies before requesting AWS credentials.

The three checkouts are siblings, and selected-source builds restore no executable caches. Existing source-ref selection, release aliases, fork build-only behavior and PR preview cleanup remain unchanged. Both shared docs pins use 42dd5b71e6eefd785b9bf8ce11d34e8f1a058a22.

Validation:

  • Full outer gate passed in 34.05s on Lua 5.5.1, tmux 3.7c and Neovim 0.12.5.
  • Four workflow regressions passed; missing-snapshot and missing-digest mutations fail.
  • The native exporter produced 114 declarations from a clean selected source checkout.
  • The local gate used Python 3.13 and removed the WSL-only inherited PROGRAMFILES(X86) variable.

The hosted native build and preview publication passed. Ordinary public GETs returned the guide and build record with bytes matching the uploaded artifact. The build record identifies clean source, native exporter and shared docs revisions. PR previews do not write a release manifest receipt; production publication remains to be verified after merge.

why: Native docs need the same source and artifact verification as shared
builds before the publisher receives AWS credentials.

what:
- Keep source, native exporter and shared docs checkouts separate.
- Record clean input revisions before generation and upload an exact
  artifact descriptor for the reviewed shared publisher.
- Disable executable caches for selected source builds and cover the
  snapshot, descriptor and paired workflow pins in focused regressions.
@tony
tony deployed to docs-preview September 30, 2026 00:10 — with GitHub Actions Active
@tony
tony marked this pull request as ready for review September 30, 2026 00:23
@tony
tony merged commit 407844d into master Sep 30, 2026
24 checks passed
@tony
tony deployed to docs-preview-cleanup September 30, 2026 00:23 — with GitHub Actions Active
tony added a commit that referenced this pull request Sep 30, 2026
what:
- Record source, native exporter, and shared docs revisions
- Describe the exact uploaded artifact before publication
- Build from sibling checkouts without executable caches

why:
The publisher needs to verify that native Lua documentation came from
the selected clean source and reviewed build tools before it requests
credentials or uploads to the site.

This branch was successfully deployed

2 active deployments
docs-preview-cleanup — c03e3233 Deployed Sep 30, 2026 by tony via cleanup #7
docs-preview — c03e3233 Deployed Sep 30, 2026 by tony via publish (pr-11, pr, false, docs-preview, true) / publish #19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant