Repository navigation
Build deterministic Pylon Prime release artifacts #28
Description
Activity
- addedpkg:coding-agentAffects packages/coding-agentAffects packages/coding-agentpkg:aiAffects packages/aiAffects packages/aipkg:agentAffects packages/agentAffects packages/agentpkg:tuiAffects packages/tuiAffects packages/tui
on Aug 31, 2026 Implementation is complete in PR #32 at exact head
5276b14fe370071e1315669f3a40f37ccf3537a9.Local exact-head validation covered the pinned Node/npm install, release-contract and package/config tests,
npm run check, pack/verify, POSIX daemon smoke, forced ACP smoke, authenticated timeout cleanup, two isolated byte-identical packs, and negative dirty/ignored/stale/SRI/internal-binding probes. Two independent adversarial reviews found no remaining blocker.Hosted CI has already passed both isolated pack jobs, byte-for-byte reproducibility, Ubuntu and macOS installed-artifact checks, and the normal build/test jobs. The Windows installed-artifact check and a small number of ordinary coding-agent jobs are still running at the time of this receipt.
PR #32 does not publish artifacts, create tags/releases, request attestations, or add publication permissions. Those remain owned by #29.
PR #32 advanced to exact head
7d4f4a7530d6bb6d9ab92740f1ba207a06e301e6after hosted Windows reproduced the prior 180-second local-install timeout twice. The correction is Windows-only (360 seconds), retains the 180-second POSIX bound, adds live npm diagnostics, and does not change artifacts, publication scope, permissions, or the 15-minute job cap. Fresh exact-head CI is running.PR #32 is fully green and cleanly mergeable at exact head
7d4f4a7530d6bb6d9ab92740f1ba207a06e301e6. Reproducibility and installed-artifact checks passed on Ubuntu, macOS, and Windows; Windows finished its install in about 196 seconds under the 360-second cap. Issue #28 now awaits recorded maintainer approval and merge. Publication remains exclusively in #29.
Problem
The Pylon fork has no reproducible or provenance-bearing release artifact.
scripts/pack-prime-agent-release.mjscan build npm-compatible tarballs and checksums, but no protectedpylonworkflow invokes it. Its current output retains upstream repository identity, runs through build paths that may refresh live model catalogs, and has no fork build identity, integrity-locked internal dependency graph, double-build proof, or signed provenance.Pylon therefore cannot offer a truthful fork install/update path or supply exact stock/fork artifacts to its bridge CI.
Required artifact contract
Keep runtime compatibility:
prime-agent;prime-agent;Give release assets distinct Pylon identity:
pylon-prime-agent[-ai|-core|-tui]-<npmVersion>.tgz;pylon-prime-agent-release-v1.jsonwith source repository/commit/tree, build id, recipe revision, channel-neutral package assets, sizes, SHA-256/SHA-512, minimum Node, and attestation subjects;pylonDistributioncontaining only immutable build provenance fields, plus the fork repository URL;npm-shrinkwrap.jsonintegrity entries tied to the immutable build release.Neither versions, tags, manifests, nor package metadata enable daemon features. Pylon must continue to require the exact SDK token and post-attach negotiated proof.
Reproducibility requirements
Acceptance coverage
prime-agent --versionon Ubuntu, macOS, and Windows;Scope and dependencies
This issue owns the deterministic artifact recipe, packer, tests, self-update guard, and artifact documentation only. It grants no publication permission and creates no GitHub release. Publishing/attestation is a separate follow-up.
Coordinate with #1 and Pylon #114. Base release work on the merged
pylonbranch after #21 / PR #19. Comet and #20 are not dependencies.