Docs: record native build provenance - #9
Merged
Merged
Conversation
why: Native docs need the same source and artifact verification as shared builds before the publisher receives AWS credentials. what: - Keep source, native exporter and shared docs checkouts separate. - Record clean input revisions before generation and upload an exact artifact descriptor for the reviewed shared publisher. - Disable executable caches for selected source builds and cover the snapshot, descriptor and paired workflow pins in focused regressions.
why: Ruby MCP discovery queries a live server. The previous shared generator created a private socket directory but did not start its daemon, so an isolated hosted build failed before publication. what: - Pin both the docs checkout and publisher to the reviewed generator fix - Keep source selection and artifact publication contracts unchanged - Verify the four workflow cases and full outer gate in 37.05 seconds The publisher revision is approved in all 12 live IAM trust policies. Hosted publication remains to be checked at this caller revision.
tony
marked this pull request as ready for review
September 30, 2026 01:36
tony
added a commit
that referenced
this pull request
Sep 30, 2026
what: - Record source, native exporter, and shared docs revisions - Describe the exact uploaded artifact before publication - Build from sibling checkouts without executable caches why: The publisher needs to verify that native Ruby documentation came from the selected clean source and reviewed build tools before it requests credentials or uploads to the site.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The native docs build now records the selected source, native exporter and shared docs revisions before generation. The uploaded content has an exact artifact descriptor, which the shared publisher verifies before requesting AWS credentials.
The three checkouts are siblings, and selected-source builds restore no executable caches. Existing source-ref selection, release aliases, fork build-only behavior and PR preview cleanup remain unchanged. Both shared docs pins use
42dd5b71e6eefd785b9bf8ce11d34e8f1a058a22.Validation:
The hosted preview run will establish the complete native-build-to-publication chain.