Files
Martin Vogel 07240cf45c fix(ci): publish VT evidence under the marker the gate actually writes
The v0.10.4 release (run 31755436916) failed at the very last step of `verify`,
after all 69 other jobs had passed — full test matrix, all eight builds, smoke
and soak:

  publish-vt-evidence: wrong evidence marker in binaries/vt-results.tsv

The results format was bumped to `cbm-virustotal-results-v2` in #1596, but
publish-vt-evidence.sh still demanded `-v1`. It was the only straggler: the
gate, the selector, the notes renderer and all three contract fixtures were
already on v2.

It survived because that PR had removed the script's only caller, leaving it
dead code that nothing exercised. Restoring the full-surface scan restored the
caller too, and the stale expectation surfaced in the worst possible place — at
the end of a real release rather than in a dry-run, since `verify` does not run
in dry-runs.

Also adds the guard that would have caught it: every marker publish-vt-evidence.sh
validates must be one the gate actually writes. Revert-checked — reintroducing
v1 fails with "publisher expects marker never written by the gate:
cbm-virustotal-results-v1".

The scan itself passed. This is purely the evidence-publishing step.

Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com>
2026-08-14 04:40:07 +02:00
..

scripts/ci/ — venue plumbing (single implementations)

Support scripts that keep the venues in the SAME shape. Each exists because the logic used to live inline in workflow YAML or was hand-duplicated between CI and the local infrastructure — both of which the venue-parity contract (tests/test_venue_parity_contract.sh) now forbids. Everything here answers --help (PowerShell: comment-based help, Get-Help <script>).

script job called by
new-protected-temp-root.ps1 Create the owner-stamped, inheritance-protected per-user TEMP root the daemon/install suites require (shared /tmp and default runner TEMP grant Authenticated-Users mutation rights, which the trust policy correctly refuses — running there produces security refusals, not signal). -ProtectDir stamps build dirs the same way. _test.yml, _soak.yml, vm-run-tests.sh
clean-test-residue.ps1 Sweep cbm-* residue from the Windows VM and assert runner-like free disk (default 14 GB — the GitHub runner's SSD). Long-path \\?\ fallback for the guard suites' adversarial trees; every removal VERIFIED (an earlier version counted attempts and reported 86 swept while 11 GB remained). BLOCKS below the floor: a disk that fills mid-run reads as a product bug. win.sh before every build/run
preflight-docker.sh Same idea for Colima/docker: prune runner-unlike residue, assert free space on the filesystem backing the docker data root (not the VM's /). Build cache + named volumes KEPT (the local analogue of actions/cache); --deep drops them. test-infrastructure/run.sh
check-glibc-compat.sh Run a linux binary in debian:bullseye (glibc 2.31) — the portable binary must start on old glibc. _smoke.yml portable legs
generate-sbom.py The release SPDX SBOM (vendored versions reviewable here, diffable by vendoring PRs — was inline YAML). release.yml
require-all-green.sh The aggregate gate: fail unless every needed job succeeded or legitimately skipped (was inline YAML). pr.yml ci-ok
verify-shard-union.sh Prove sharded test legs lost nothing: shard count agreement, indices 1..n, identical suite lists, union of slices == full list (was inline YAML). _test.yml shard-completeness
prepare-release-candidates.sh Copy one linker output into stripped/unstripped candidates, finalize signatures, composition-check them without execution, and record their hashes. _build.yml, local artifact smoke
stage-release-candidates.py Admit exactly eight candidate artifacts / sixteen byte-distinct binaries into the content-addressed VirusTotal scan set. _build.yml
select-release-candidates.py Apply the reviewed tuple-local VT truth table, or the explicit dry-run stripped default, and atomically copy one content-bound binary per target. _build.yml
verify-release-selection.py Recompute the selection policy and prove every executable member in all 14 public containers equals its selected SHA-256. _build.yml, release.yml final draft verification
check-virustotal.sh Poll and validate the exact candidate scan set, enforce engine coverage and the narrow documented Microsoft !ml policy, and emit content-bound results evidence. _build.yml