Skip to content

fix(release): publish certified crates with --no-verify; age out failed attempts #329

Description

@DecisionNerd

Objective

Finish the last v0.5.1 crates.io node (graphforge-cli) without moving tag dd1fd8c.

Evidence

  • Run: https://github.com/CurateLabs/graphforge/actions/runs/30717946991
  • Live crates.io: 14/15 at 0.5.1. Missing: graphforge-cli (404). graphforge-api accepted.
  • Exact crates-lane error after authorize/package of cli:
    • failed to verify package tarball
    • build.rs panic: read canonical project-skills directory: NotFound
    • path ../../project-skills is outside the packaged crate (certified .crate also lacks skills; RC packages with --no-verify)
  • Attempt orphan: v0.5.1-attempt-crates-graphforge-cli.json uploaded; no accepted receipt. Reconciliation classifies cli as indeterminate / write_attempt_outcome_unknown, which would block the next authorize even after a publisher fix.

Done when

  • publish_crates.py uses cargo publish --locked --no-verify so certified tag bytes (packaged with --no-verify) can upload; checksum gate unchanged.
  • observe-all ages out attempt-without-receipt after the visibility bound when live truth remains authoritative 404 (prior attempt did not land).
  • Recovery overlays release_registry.py from main on tag checkout.
  • Contract/unit tests cover both behaviors.
  • Tag v0.5.1 remains at dd1fd8cdeb75aba11948ed6e1871e98a46560be8.

Non-goals

  • Retagging or changing certified crate checksums.
  • Relocating project-skills into the crate for this tag (follow-up if cargo install graphforge-cli from crates.io must work).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions