Skip to content

chore: bump workspace version to 1.21.17 - #40

Merged
AlexMikhalev merged 1 commit into
mainfrom
task/bump-1.21.17
Oct 4, 2026
Merged

AlexMikhalev merged 1 commit into
mainfrom
task/bump-1.21.17

Conversation

@AlexMikhalev

Copy link
Copy Markdown
Contributor

Version bump for the first release cut from the reconciled canonical line.

Includes:

  • #81 RLM opt-in fix
  • #349 max_tokens/error-surfacing fixes
  • All GitHub CI/release infrastructure
  • #342 reconciliation (324 Gitea commits merged into canonical line)

Refs #342, #349

First release cut from the reconciled canonical line (#342).
Includes the #81 RLM opt-in fix, #349 max_tokens/error-surfacing
fixes, and all GitHub CI/release infrastructure.

Refs #342, #349
@AlexMikhalev
AlexMikhalev merged commit ed586fb into main Oct 4, 2026
0 of 2 checks passed
AlexMikhalev added a commit that referenced this pull request Oct 4, 2026
…8) (#45)

* ci(release): move Linux/macOS build lanes to self-hosted runners

GitHub-hosted runners cannot fetch from the Gitea cargo registry:
off-tailnet cargo access is Bearer-only (Gitea #341) and cargo omits
Bearer on .crate downloads whenever the registry advertises
auth-required:false, which Gitea computes from org visibility
(terraphim is public). The 2026-09-25 Caddy narrowing therefore only
works when cargo attaches credentials to every request.

Self-hosted runners on the Tailnet reach git.terraphim.cloud via the
box /etc/hosts mapping (100.106.66.7), so Caddy treats them as
on-network and no registry auth dance is needed at all.

- Linux lanes (gnu + both musl cross targets) -> release-linux label
  on the bigbox runner (terraphim-clients-runner-1)
- macOS lanes (x86_64 cross-compile + aarch64 native) -> release-macos
  label on the Apple Silicon runner (terraphim-clients-macos-1)
- Windows lane removed: restore it once the private terraphim crates
  are published to crates.io so GitHub-hosted runners can fetch them
- sign-and-notarize and create-universal stay on GitHub-hosted
  macos-15: they never touch the cargo registry and need sudo for
  Rosetta provisioning
- Remove the temporary cargo-auth debug echo block
- Contract tests updated to the five-lane self-hosted matrix; release
  version pin corrected to 1.21.17 (missed in #40); PKGVER comment
  documents the intentional mid-release PKGBUILD lag

Refs #348

* fix(release): address P0/P1/P2 from pi-rust structural review

P0: seal-release-stage still consumed the deleted Windows lane (artifact
download, zip assembly, = 20 asset assertions) which would fail every
release at the final gate. Removed the download step and zip block,
dropped dead .exe extension branches in build-binaries, and set the
asset counts to 17 (6 agent + 5 cli + 6 grep tar.gz).

P1: the x86_64-apple-darwin lane verifies by executing the cross-compiled
binary under Rosetta, but Rosetta was only provisioned in
sign-and-notarize-macos which runs on a different machine. Added a
guarded 'Prove Rosetta' step to the macOS build lane.

P2: documented host preconditions (sudo, docker, qemu-user-static,
readelf, rustup, Rosetta) next to the matrix comment; contract tests
now pin the absence of the Windows lane so it cannot be half-removed
again.

Review: pi-rust (kimi-for-coding/k2p5), posted on PR #45.

Refs #348

---------

Co-authored-by: Alex <alex@terraphim.cloud>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant