chore: checkpoint #129 SDK runtime evidence WIP - #145
Conversation
Signed-off-by: Danil Silantyev <danilsilantyevwork@gmail.com>
|
Additional #129 recovery lineage verified after the primary checkpoint:
The stash was inspected and pushed without apply, drop, rewrite, merge, or test execution. The only secret-pattern match was the literal consumer reference |
Applies the PR #145 checkpoint (7cbd1e8) on top of the track-M fixes merged as PR #146. Conflicts were unions: the Python execution surface carries both track-M's subjects and this branch's. This is the unverified WIP baseline; every defect it carries is fixed in the commits that follow. One fix is folded in here rather than applied after: `gitleaks` flags the sample cache identity on line 238 as `generic-api-key`, and `secret-scan.yml` scans the history of the checked-out ref, so leaving the literal in an ancestor commit would fail the scan on `main` for good. The value is a Flutter action cache key in a negative-self-test sample, not a credential, so nothing needs rotating -- but the line really did read like one, and the fix is to stop the sample looking like a secret rather than to teach the scanner to skip the file. The identities are built from parts, with the version read from `sdk-runtime-spec.yml` instead of written out three more times.
Applies the PR #145 checkpoint (7cbd1e8) on top of the track-M fixes merged as PR #146. Conflicts were unions: the Python execution surface carries both track-M's subjects and this branch's. This is the unverified WIP baseline; every defect it carries is fixed in the commits that follow. One fix is folded in here rather than applied after: `gitleaks` flags the sample cache identity on line 238 as `generic-api-key`, and `secret-scan.yml` scans the history of the checked-out ref, so leaving the literal in an ancestor commit would fail the scan on `main` for good. The value is a Flutter action cache key in a negative-self-test sample, not a credential, so nothing needs rotating -- but the line really did read like one, and the fix is to stop the sample looking like a secret rather than to teach the scanner to skip the file. The identities are built from parts, with the version read from `sdk-runtime-spec.yml` instead of written out three more times.
|
Superseded by #151, merged as 0ddd121. That PR rebased this checkpoint onto It also fixed three defects that stopped the estate running at all — the observers never installed The branch is kept, not deleted: it is the checkpoint record. |
Checkpoint only — incomplete and unverified
Links #129 and parent #126.
This Draft PR is a workstation-evacuation checkpoint. It must not be merged as-is. It preserves the safe source, documentation, workflow, validator, and minimal fixture state from SDK Recovery Final Attempt3 on the exact ancestry below.
Identity
mainat2d25598ec9efb39ffafba73845619b9a2d8ab25a7cbd1e85490e87c684a4d796276328ea1681c3b9checkpoint/2026-08-13-ci-workflows-129-sdkIncluded scope
Downloaded SDK/Gradle caches, build outputs, logs, temporary process state, credentials, secrets, and local issue-receipt files were audited out and are not committed.
Final Attempt3 local evidence
Passed once on this exact WIP before checkpoint:
.venv/bin/python -I -B scripts/check_python_syntax.py→check_python_syntax: OK.venv/bin/python -I -B scripts/check_python_execution_contract.py→check_python_execution_contract: OK(CPython 3.13.13, hash-pinned PyYAML 6.0.3).venv/bin/python -I -B scripts/check_python_execution_contract.py --launch check_sdk_runtime_fixtures.py -- --static→check_sdk_runtime_fixtures: OKInterrupted for workstation handoff, not pass/fail:
env PATH=/opt/homebrew/opt/openjdk@21/bin:/opt/homebrew/bin:/usr/bin:/bin:/usr/sbin:/sbin .venv/bin/python -I -B scripts/check_python_execution_contract.py --launch generate_android_fixture_provenance.py --./gradlew buildgeneration, and provenance construction completed inside the atomic command. The separate fresh-home strict replay was still running when owner orchestration intentionally interrupted it after more than 23 minutes. Its generated outputs were not published into the worktree, so they are not checkpoint evidence.NOT_RUN / NOT_PROVEN:
validate_allcore/full, actionlint, pinned tokenized zizmorAttempt lineage and holds
Recovery A1 terminal receipt: issue comment
5284524027.Recovery A2 terminal receipt: issue comment
5284601179.This Final Attempt3 was superseded by the owner checkpoint/handoff override; the interrupted Android command is not classified as a product failure.
No external consumer, repository settings, credentials, release, deployment, or merge mutation is authorized. The queued private fleet-routing migration is unrelated and must remain separate.
Deterministic resume
On the next workstation, first create the repository
.venvfrom hash-pinnedrequirements-ci.txtand ensure the clean explicit PATH resolves JDK 21 andsdkmanager. Then run exactly:Do not infer success from this checkpoint or from the interrupted command. Continue the ordered #129 evidence chain only under fresh owner/dispatcher authority.
Additional recovery lineage
stash@{0}was inspected without applying it. It is a unique pre-hermetic-Python split tree based on00546f1c601a106d560d92e316f332891ac6f840, with stash commit0215cf260000084598de3fefe9f44980093bbbb4and tree66c556a9ba2a1dcd045070a981e687691de4ef95. It was pushed exactly, without rewriting, asarchive/2026-08-13-ci-workflows-sdk-pre-python-split; bothls-remoteand the GitHub ref API resolve that branch to0215cf260000084598de3fefe9f44980093bbbb4. The apparent API-key match is only the public${{ secrets.ANTHROPIC_API_KEY }}consumer expression, not secret material.fix/hermetic-python-executionis already remotely recoverable atf60c08894eb3c865b99d23a14685c52926bf8935and was merged separately; no duplicate archive was created.fixtures/sdk-runtime-evidenceremains dirty and untouched, and the stash remains present. It contains diagnostic pre-split combinations and generated SDK manifest state; the exact stash lineage above plus this primary checkpoint are the portable recovery boundaries. No local worktree, stash, branch, cache, or generated state was deleted.