Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
138 commits
Select commit Hold shift + click to select a range
5e4b799
fix(drive-abci): verify vote extensions against the withdrawals of th…
QuantumExplorer Sep 27, 2026
39e7850
feat(platform)!: documents with a time to live, deleted by the platfo…
QuantumExplorer Sep 27, 2026
0abaa0b
fix(drive-abci): sign and verify vote extensions of a block accepted …
QuantumExplorer Sep 27, 2026
fb73ef8
perf(drive-abci): read shielded encrypted notes in one chunk-aligned …
QuantumExplorer Sep 27, 2026
b43b030
chore: open every pr-description output with a basic explanation sect…
QuantumExplorer Sep 27, 2026
298f013
fix(sdk): don't panic in DapiClient::new on an empty address list (#4…
PastaPastaPasta Sep 27, 2026
52cd646
chore: sync the pr-description skill with the PR template and title c…
QuantumExplorer Sep 27, 2026
f4426b2
fix(drive-abci)!: cap a contest at 1,000 contenders and tally every o…
QuantumExplorer Sep 27, 2026
dc42371
ci: build release SDKs and NPM packages on self-hosted runners (#4562)
PastaPastaPasta Sep 27, 2026
74d3352
chore(swift-sdk): freeze App Store schema 3.0.0
github-actions[bot] Sep 27, 2026
5febda1
feat(platform)!: a contender's fund doubles for every 50 contenders a…
QuantumExplorer Sep 27, 2026
8936d44
feat(platform)!: anyOf, allOf and not in propertyConstraints rules (P…
QuantumExplorer Sep 27, 2026
e8c4d1b
feat(platform)!: present and absent tests in propertyConstraints rule…
QuantumExplorer Sep 27, 2026
b48edfe
feat(platform)!: in, value membership in propertyConstraints rules (P…
QuantumExplorer Sep 27, 2026
e1325f8
feat(platform)!: boolean operands in propertyConstraints rules (PV14)…
QuantumExplorer Sep 27, 2026
eeed935
fix(platform)!: contenders state the most they pay and are charged th…
QuantumExplorer Sep 27, 2026
7a57518
feat(platform)!: pay document ttl storage fees to the epochs the docu…
QuantumExplorer Sep 27, 2026
50b9fb1
feat(platform)!: string equality for enums in propertyConstraints rul…
QuantumExplorer Sep 27, 2026
5c79d12
chore(release): update changelog and bump version to 4.2.0-beta.5 (#5…
QuantumExplorer Sep 27, 2026
d5a5875
feat(platform)!: compare two string properties in propertyConstraints…
QuantumExplorer Sep 27, 2026
3840c2f
feat(platform)!: string ifAbsent defaults in propertyConstraints rule…
QuantumExplorer Sep 27, 2026
3b190e9
feat(platform)!: identifier comparisons in propertyConstraints rules …
QuantumExplorer Sep 27, 2026
4d4f38d
feat(platform)!: $ownerId comparisons in propertyConstraints rules (P…
QuantumExplorer Sep 27, 2026
b33aba1
refactor(dpp): restore shipped registration_cost v1 index parsing (#5…
QuantumExplorer Sep 27, 2026
f0b7108
refactor(drive): create once-per-identity claim trees in insert_contr…
QuantumExplorer Sep 27, 2026
3e6e258
fix(dpp): parse nested required and transient entries by prefix (#5050)
QuantumExplorer Sep 27, 2026
1b30651
feat(sdk): propertyConstraints discovery and pre-check in the JS SDK …
QuantumExplorer Sep 27, 2026
a5a1af5
feat(sdk): propertyConstraints rules and pre-check in the Swift SDK a…
QuantumExplorer Sep 27, 2026
f487972
docs: add a contract keywords reference page to the book (#5067)
QuantumExplorer Sep 27, 2026
8783489
feat(sdk): propertyConstraints rules and pre-check in the Kotlin SDK …
QuantumExplorer Sep 27, 2026
3f15eea
docs(platform): document the genesis protocol version exception and S…
QuantumExplorer Sep 27, 2026
86c948d
test(drive): pin that a cached contract read after an in-block update…
QuantumExplorer Sep 27, 2026
8340446
fix(dpp): restore the shipped order of basic consensus errors (#5053)
QuantumExplorer Sep 27, 2026
a9e3a2f
ci: bootstrap PR-first runner images on v4.2-dev
infraclaw-dash Sep 27, 2026
db75bab
ci: reconcile rootless runner workflows with v4.2-dev
infraclaw-dash Sep 27, 2026
9c39e66
docs(platform): say why in-place edits to shipped generations are ine…
QuantumExplorer Sep 27, 2026
5c8c4dd
refactor(platform): fold DRIVE_ABCI_QUERY_VERSIONS_V3 into V2 (#5057)
QuantumExplorer Sep 27, 2026
013dce6
test: follow the test conventions in tests added in 4.1 and 4.2 (#5062)
QuantumExplorer Sep 27, 2026
29b6a16
ci: bootstrap PR-first runner image publishing (#4912)
ktechmidas Sep 27, 2026
d3b96b3
refactor(platform): import instead of inline crate paths in 4.1 and 4…
QuantumExplorer Sep 27, 2026
cd604da
Merge branch 'v4.2-dev' into codex/rootless-ci-hardening
ktechmidas Sep 27, 2026
c1dcfc9
ci: remove host privilege requirements from persistent Linux runners …
ktechmidas Sep 27, 2026
b60bcdb
docs(platform): add Parameters and Returns sections to 4.1 and 4.2 di…
QuantumExplorer Sep 27, 2026
07ab909
fix(ci): build release clients natively on unprivileged runners
PastaPastaPasta Sep 27, 2026
3cb2a8d
fix(release): require all generated clients in packed archives
PastaPastaPasta Sep 27, 2026
a7a4c57
fix(ci): isolate release runners from PR build state
PastaPastaPasta Sep 27, 2026
eaa9d1e
fix(release): build clients natively on unprivileged runners (#5068)
ktechmidas Sep 27, 2026
ab2aaa4
fix(swift-sdk): take migration copies out of WAL mode
jeanpierreroma Sep 27, 2026
3120a22
chore(swift-sdk): freeze App Store schema 3.0.0
github-actions[bot] Sep 27, 2026
e090ae2
fix(dpp)!: refuse token cost and unruled keyword changes on update wi…
QuantumExplorer Sep 27, 2026
d7d5c84
fix(dpp)!: accept a reordered entryPayload and refuse unruled keyword…
QuantumExplorer Sep 27, 2026
55f0587
docs(swift-sdk): say the migration copy is switched out of WAL mode
jeanpierreroma Sep 27, 2026
2302a80
docs: give every contract keyword its own chapter in the book (#5075)
QuantumExplorer Sep 27, 2026
24b228a
fix(dpp)!: propertyConstraints compare identifier properties that dec…
QuantumExplorer Sep 27, 2026
5e1e7e0
fix(ci): isolate NPM and Kotlin releases in disposable runners
infraclaw-dash Sep 27, 2026
9cd341c
docs(release): fix NPM dry-run tag example
infraclaw-dash Sep 27, 2026
10b1c2c
feat(platform)!: string length, byte length and array count operands …
QuantumExplorer Sep 27, 2026
81ee8df
feat(platform)!: creation, update and transfer times and heights in p…
QuantumExplorer Sep 27, 2026
37a7785
fix(wasm-sdk): leave price tier validation to rs-dpp (#5058)
QuantumExplorer Sep 27, 2026
406ca9a
docs: list the complete contract language in the keywords overview (#…
QuantumExplorer Sep 27, 2026
91a88b0
fix(dpp)!: report contracts refused by parser generation 3 as consens…
QuantumExplorer Sep 27, 2026
c5e80c9
fix(drive-abci): sign a locked block when a later proposal left no ex…
QuantumExplorer Sep 27, 2026
e7aed01
feat(platform)!: contains in propertyConstraints rules (PV14) (#5083)
QuantumExplorer Sep 27, 2026
da7cc2d
fix(drive-abci): sign vote extensions only for blocks this node accep…
QuantumExplorer Sep 27, 2026
6d58d7e
feat(platform)!: startsWith and endsWith in propertyConstraints rules…
QuantumExplorer Sep 27, 2026
5870cdd
fix(wasm-sdk): keep StateTransitionResult.ownerBalance exact in JSON …
QuantumExplorer Sep 27, 2026
b23a06b
fix(dpp)!: size estimates of strings of 16384 or more characters no l…
QuantumExplorer Sep 27, 2026
55a05ae
fix(drive-abci): finalize a block accepted in an earlier round after …
QuantumExplorer Sep 27, 2026
d38592f
docs: remove committed working specs and plans (#5060)
QuantumExplorer Sep 27, 2026
c4125c9
docs: encrypt the 69-byte compact xpub in the contact-request guide (…
QuantumExplorer Sep 27, 2026
e0937ce
feat(kotlin-sdk)!: new propertyConstraints read kinds and system read…
QuantumExplorer Sep 27, 2026
7894963
feat(swift-sdk)!: new propertyConstraints read kinds and system reads…
QuantumExplorer Sep 28, 2026
a1d4d85
feat(platform)!: ifThen, ifThenElse, notIn, min, max and abs in prope…
QuantumExplorer Sep 28, 2026
f40ee0a
test(sdk): ifThen and ifThenElse rules through rs-sdk-ffi and the Swi…
QuantumExplorer Sep 28, 2026
fc6e394
feat(platform)!: elected moderation windows may be 0 off mainnet, mai…
QuantumExplorer Sep 28, 2026
2ee0b56
chore(swift-sdk): freeze App Store schema 3.0.0
github-actions[bot] Sep 28, 2026
8d587f2
fix(dpp)!: propertyConstraints read empty objects as absent and follo…
QuantumExplorer Sep 28, 2026
eae2859
feat(platform)!: countOf and sumOf totals from count and sum trees in…
QuantumExplorer Sep 28, 2026
bed9b16
fix(dpp): pass the contract's $defs to the countOf and sumOf key enum…
QuantumExplorer Sep 28, 2026
dd01f49
fix(sdk): consensus errors reach JS with their code (#5112)
QuantumExplorer Sep 28, 2026
8c29a53
feat(platform)!: generatedFrom, string properties the platform genera…
QuantumExplorer Sep 28, 2026
06d9675
fix(drive)!: subscription filters match generated properties a transi…
QuantumExplorer Sep 28, 2026
052071c
chore(swift-sdk): freeze App Store schema 3.0.0 (#5035)
llbartekll Sep 28, 2026
e826b8f
fix(swift-sdk): take migration copies out of WAL mode (#5070)
llbartekll Sep 28, 2026
c5dee05
fix(swift-sdk): free FFI errors in state-transition wrappers (#5117)
QuantumExplorer Sep 28, 2026
c83c2c0
fix(sdk): consensus errors reach Swift and Kotlin apps with their cod…
QuantumExplorer Sep 28, 2026
b3d59b8
fix(swift-sdk): documentTransfer handles a missing document and signs…
QuantumExplorer Sep 28, 2026
aba908b
fix(platform)!: refuse own-type totals on contested types and fail lo…
QuantumExplorer Sep 28, 2026
7799497
feat(sdk)!: countOf and sumOf totals in the rule descriptors of the J…
QuantumExplorer Sep 28, 2026
812d630
fix(platform)!: a preallocated agreement source must fit a tree key (…
QuantumExplorer Sep 28, 2026
4a8998f
ci: use pinned ARM64 Rust images on Mac-backed Linux runners
infraclaw-dash Sep 28, 2026
b281e39
ci: isolate ARM64 image updates from the ordinary runner pool
infraclaw-dash Sep 28, 2026
16afde9
fix(ci): keep wallet FFI test pointer cast portable on ARM64
infraclaw-dash Sep 28, 2026
e776f95
fix(sdk): bound each DAPI request attempt, including the response bod…
llbartekll Sep 28, 2026
5298d20
chore(release): update changelog and bump version to 4.2.0-beta.6 (#5…
QuantumExplorer Sep 28, 2026
013ff40
ci: use pinned ARM64 Rust images on Mac-backed Linux runners (#5124)
ktechmidas Sep 28, 2026
1ef7a02
fix(release)!: run NPM and Kotlin releases on disposable runners (#5077)
ktechmidas Sep 28, 2026
52e03df
fix(ci): repair headless Swift keychains and PIC RocksDB
infraclaw-dash Sep 28, 2026
6d42b15
fix(kotlin-sdk): prepare secure emulator state in nightly tests
infraclaw-dash Sep 28, 2026
bf19672
fix: bound doctest linker concurrency on CI runners
infraclaw-dash Sep 28, 2026
f33d18b
fix: update trusted runner image controller pin
infraclaw-dash Sep 28, 2026
8157568
fix(drive)!: refuse a duplicate value in a unique index on a nested p…
QuantumExplorer Sep 28, 2026
c0589ec
fix: repair headless Swift, RocksDB and doctest CI (#5129)
ktechmidas Sep 28, 2026
6cff96f
fix(kotlin-sdk): prepare secure emulator state in nightly tests (#5131)
ktechmidas Sep 28, 2026
4d1f0cc
fix: update trusted runner image controller pin (#5134)
ktechmidas Sep 28, 2026
99207ac
fix(drive-abci): check_tx refuses a masternode vote a block would ref…
QuantumExplorer Sep 28, 2026
91db70a
fix(sdk): masternodeVote takes the ProTxHash as an Identifier and ret…
QuantumExplorer Sep 28, 2026
b936d4c
fix(sdk): index-only document creates and deletes resolve once they l…
QuantumExplorer Sep 28, 2026
af86fc7
fix(sdk): accept vote poll end-date timestamps (#5139)
QuantumExplorer Sep 28, 2026
ad99cc1
fix(ci): resolve Kotlin release NDK from runner environment
infraclaw-dash Sep 28, 2026
1096df9
ci(kotlin-sdk): resolve release NDK from runner environment (#5141)
ktechmidas Sep 28, 2026
4d13315
feat(sdk)!: DataContract.validateUpdate in @dashevo/wasm-dpp2 (#5140)
QuantumExplorer Sep 28, 2026
08012d9
ci: deploy isolated PR Hygiene engine on v4.2
infraclaw-dash Sep 28, 2026
dbcc118
ci: deploy isolated PR Hygiene engine on v4.2 (#5142)
ktechmidas Sep 28, 2026
d22f8ab
fix(drive): refuse indexOnly prefix pivots whose pages could be incom…
QuantumExplorer Sep 28, 2026
c135e7c
ci(wasm-sdk): bound optimizer threads independently of compilation
infraclaw-dash Sep 28, 2026
1368fbb
fix(platform-wallet): a ProUpServTx always carries an output (#5105)
QuantumExplorer Sep 28, 2026
b40e4db
feat: add Value::same_scalar_data for comparing single values across …
QuantumExplorer Sep 28, 2026
1464314
fix(dpp)!: refuse a dotted property path in sum and average keywords …
QuantumExplorer Sep 28, 2026
6e12d48
chore: merge v4.2-dev into v4.3-dev
PastaPastaPasta Sep 28, 2026
201c2f9
ci: restore legacy runner image template compatibility
infraclaw-dash Sep 28, 2026
9f78909
ci: restore legacy runner image template compatibility (#5155)
ktechmidas Sep 28, 2026
a02b146
chore: merge v4.2-dev into v4.3-dev
PastaPastaPasta Sep 28, 2026
9433a95
ci(wasm-sdk): inline Binaryen thread cap as a bash step
PastaPastaPasta Sep 28, 2026
b66233d
ci(wasm-sdk): default Binaryen to four threads
PastaPastaPasta Sep 28, 2026
2806459
perf(wasm-sdk): optimize release WASM with a single -Oz pass
PastaPastaPasta Sep 28, 2026
a0a7b3f
perf(wasm-sdk): speed up release WASM optimization (#5147)
ktechmidas Sep 28, 2026
c795f81
feat(drive): compute a document type's GroveDB layout for the SDKs (#…
QuantumExplorer Sep 28, 2026
217167d
fix(ci): validate runner candidates using full commit statuses
infraclaw-dash Sep 28, 2026
b81ed54
fix: validate runner candidates using full commit statuses (#5156)
ktechmidas Sep 28, 2026
5a3fa4a
chore: merge v4.2-dev into v4.3-dev
PastaPastaPasta Sep 28, 2026
c4493d5
ci: pin integrated runner controller revision
infraclaw-dash Sep 28, 2026
99bc968
ci: pin integrated runner controller revision (#5157)
ktechmidas Sep 28, 2026
6f552ea
chore: merge v4.2-dev into v4.3-dev
PastaPastaPasta Sep 28, 2026
fcacc64
feat(drive): compute what creating a document costs for the SDKs (#5159)
QuantumExplorer Sep 28, 2026
955eeaa
chore: merge v4.2-dev into v4.3-dev
PastaPastaPasta Sep 28, 2026
eefca92
feat(sdk): let apps that build document creates by hand state the con…
QuantumExplorer Sep 29, 2026
e674233
chore: merge v4.2-dev into v4.3-dev
PastaPastaPasta Sep 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
22 changes: 18 additions & 4 deletions .claude/skills/pr-description/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,8 @@ Generate a pull request title and description for the current branch using the p
1. Determine the base branch:
- Use the argument if provided
- Otherwise, auto-detect: `git remote set-head origin --auto >/dev/null 2>&1 && git symbolic-ref refs/remotes/origin/HEAD 2>/dev/null | sed 's|refs/remotes/||'`
- Fall back to `v4.0-dev` if the command above fails
- If that fails, use the repository's default branch on GitHub: `gh repo view --json defaultBranchRef -q .defaultBranchRef.name`
- If both fail, ask the user rather than guessing a version branch

2. Gather context by running these git commands:
- `git log --oneline $(git merge-base HEAD <base>)..HEAD` β€” all commits on this branch
Expand All @@ -25,19 +26,30 @@ Generate a pull request title and description for the current branch using the p
- What specific code changes were made
- Whether there are breaking changes
- What tests were added or modified
- What value the change adds, and for whom
- What could go wrong: consensus impact, behaviour users could notice, slow or flaky tests

4. Output a suggested PR title using conventional commits format:
- Scopes: `sdk`, `drive`, `dpp`, `dapi`, `dashmate`, `wasm-dpp`, `wasm-sdk`, `platform`
- Types: `feat`, `fix`, `refactor`, `chore`, `docs`, `test`, `build`
- Types and scopes: use only the `types:` and `scopes:` lists in `.github/workflows/pr.yml`. The PR title check rejects anything else, so read them from that file rather than from memory
- The scope is optional: leave it out (e.g. `chore: ...`) when the change spans several packages or no listed scope fits. Never invent a scope
- The subject must not start with an uppercase letter
- Add `!` after the type for breaking changes (e.g. `feat!:`)
- Format: **Suggested title:** `type(scope): description`

5. Fill in this PR template (preserve all HTML comments exactly as shown):
5. Fill in this PR template (preserve all HTML comments exactly as shown). The `## Basic explanation` section always comes first; the sections after it follow `.github/PULL_REQUEST_TEMPLATE.md`. If that file differs from the copy below, follow the file:

```markdown
<!--- Provide a general summary of your changes in the Title above -->
<!--- Pull request titles must use the [conventional commits](https://www.conventionalcommits.org/en/v1.0.0/#summary) format -->

## Basic explanation

**What this does:** <The change in the most basic terms, for a reader who does not know this code. Explain any jargon in passing, or avoid it.>

**Value:** <What gets better and for whom (users, wallets, node operators, the network). Give a number when there is one.>

**Risks:** <What could go wrong, sized honestly: say "Low" and why when it is low. Mention consensus impact, behaviour users could notice, and slow or flaky tests.>

## Issue being fixed or feature implemented
<!--- Why is this change required? What problem does it solve? -->
<!--- If it fixes an open issue, please link to the issue here. -->
Expand Down Expand Up @@ -69,6 +81,7 @@ Generate a pull request title and description for the current branch using the p
- [ ] I have added or updated relevant unit/integration/functional/e2e tests
- [ ] I have added "!" to the title and described breaking changes in the corresponding section if my code contains any
- [ ] I have made corresponding changes to the documentation if needed
- [ ] If I added or changed GroveDB structure, I described it in the area's `structure.rs`, regenerated `grovedb-structure.json`, and checked the structure viewer link posted on this pull request

**For repository code-owners and collaborators only**
- [ ] I have assigned this pull request to a milestone
Expand All @@ -80,6 +93,7 @@ Output the entire PR description (title + body) as a single raw Markdown code bl

## Guidelines

- Always open with `## Basic explanation`: three short paragraphs (what it does, value, risks) that someone outside this code can follow. For a security fix, keep it neutral: describe what the fix does, not how the bug could be exploited
- Keep the description **concise** β€” avoid walls of text. Prefer short bullet points over paragraphs
- Be specific β€” reference file paths, struct/function names, and types
- For "How Has This Been Tested?", check `git diff` for new `*test*`, `*spec*` files. Briefly describe what tests cover (1 line per test file), not every individual test case
Expand Down
4 changes: 4 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,10 @@ end_of_line = lf
[*.rs]
indent_size = 4

# Swift and Kotlin follow their languages' 4-space convention.
[*.{swift,kt,kts}]
indent_size = 4

# Preserve the existing indentation of the Swift SDK Python scripts.
[packages/swift-sdk/scripts/*.py]
indent_size = 4
Expand Down
103 changes: 103 additions & 0 deletions .github/NPM_RUNNER.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,103 @@
# NPM release runners

NPM release compilation uses a fresh single-job runner with a unique
`platform-release-<run-id>-<attempt>-npm` label in the `platform-release-builds`
runner group. Kotlin releases use the same lifecycle with a `-kotlin` label. Publishing
continues on GitHub-hosted Ubuntu with OIDC; the builder receives no publishing
credentials. The `npm-release-build` action is shared by releases and image
validation so both compile and pack with the same setup.

## Image contract

`.github/runner-requirements.json` pins the complete Linux image requirements and
recipe commit. The job runs `ci-image-contract verify` before compiling. The
runner must have `/opt/client-codegen` matching `packages/dapi-grpc/codegen.json`.
Its protobuf 3.18.1 compiler is intentionally separate from Rust's protoc 32.0.
TypeScript generation comes from the workspace's pinned `ts-protoc-gen` dependency.

Image-owned native dependencies are verified, never installed using sudo. Rust,
Node and the pinned WASM tools use writable runner/user locations. Cargo targets
remain in job-local HOME; each release starts with fresh runner, HOME and workspace state. The
runner needs no Docker CLI/socket or KVM device.

## Provisioning and promotion

Use the reviewed `dashpay/dash-selfhosted-image` recipe and a tested immutable
image digest, not a moving tag. Deploy the host-side disposable release controller
only after the NPM validation workflow succeeds on that image. Do not add generic
release labels to persistent CI registrations. See the
[controller installation and cleanup runbook](https://github.com/dashpay/dash-selfhosted-image/blob/main/docs/disposable-releases.md).
Old release tags
still contain their original workflows and do not automatically gain this fix.

Requirements-changing PRs select a candidate label bound to the complete PR head
and image digest. The image controller must support the `npm` job kind and
`.github/workflows/npm-runner-validation.yml`. Manifests requesting native client
generation require successful Rust, Kotlin and NPM candidate jobs for promotion;
skipped fork jobs do not qualify. Existing same-repository/trusted-fork guards
remain in effect.

The trusted `runner-image-candidate.yml` bootstrap, controller and Rust/Kotlin
candidate routing must be installed on each consuming branch before candidate
promotion can work. Platform PRs #4702 and #4912 establish those pieces; reconcile
their requirements/selector files with this NPM extension when landing them. In
particular, update both the bootstrap's reusable-workflow SHA and its
`control_revision` to a reviewed image-repository revision supporting
`client_codegen` and `npm`. Merely changing `recipe_revision` is insufficient.
The default `v4.2-dev` and `v4.3-dev` branches must each use an explicit compatible
manifest; this change does not alter an existing release tag or deploy a runner.

## Verification

`npm-runner-validation.yml` runs the real release build and packing action, DAPI
unit tests, and a byte-for-byte check that packed Node/web clients match the
freshly generated files. It uploads tarballs but never publishes them.
`test-client-codegen.yml` also builds the native compilers on hosted Linux/macOS,
checks committed generated output, tests failure recovery and validates packing.

Local setup and generator test commands are in `packages/dapi-grpc/README.md`.

After installing the controller, use the `release.yml` dispatch with
`tag=npm-test:v<package.json version>` on a protected development branch for a non-publishing
NPM build. For Kotlin, dispatch `release-kotlin-sdk.yml` from the protected branch
with an existing published `tag` and `dry_run=true`: compilation/artifact upload
run, but release attachment and Maven publication are both skipped. Check that
the image contract matches the selected source. Neither controller unit tests
nor an image smoke test establishes that these end-to-end jobs pass.

## Separate PR and release state

The `platform-release-builds` organization runner group selects only
`dashpay/platform` and contains only controller-created one-job registrations.
Each build requests:

```yaml
runs-on:
group: platform-release-builds
labels: [self-hosted, Linux, X64, 'platform-release-${{ github.run_id }}-${{ github.run_attempt }}-npm']
```

There is no fallback to `npm-build`, `rust-ci` or `kotlin-ci`. Without the
controller, builds stay queued. Runtime markers reject accidental routing to an
ordinary runner; they are not cryptographic attestation. The host controller
independently checks repository, event, workflow, run, attempt and commit before
creating fresh JIT capacity. Only one job can consume each registration; the host
destroys its container/processes, HOME, registration and workspace afterward.

**Ordinary PR caching is unchanged.** PR validation keeps its own persistent
Cargo/Gradle/Yarn caches. Releases reuse the prebaked image/toolchains but never
mount PR state or restore shared executable dependency caches. Yarn caching is
opted out only for the release runtime; Kotlin release build/publication disable
Gradle cache restores. A cold release compile is the intentional tradeoff; do not
reintroduce shared caches to speed it up without reviewing their writer trust.

`release.yml` calls its local reusable workflow, so the workflow travels with the
release source. Port it and the matching image requirements to 4.3; the host
controller needs no branch-specific allowlist. Branch protection, trusted tags,
fork approvals and hosted publishing authorization remain necessary. Optional
selected-workflow group restrictions are defense in depth, not the mechanism
that erases prior-job state. Labels alone are not authorization.

This assumes a trusted host and pinned image. A fresh container does not repair
host compromise or retroactively secure old release tags/artifacts. Merge/deploy
the controller before relying on this workflow change for a release.
Loading
Loading