Commit graph

27 commits

Author SHA1 Message Date
Dallin Romney
ca0159f1c2
fix(release): remove unused flake classification bypass (#163412)
* fix(release): remove FRV flake receipts

* docs(release): require successful FRV CI gate
2026-10-02 03:02:01 -07:00
Peter Steinberger
9dc08b1fac
fix(release): publish preflight stalls silently, frv continue is silent, and the SDK acknowledgement is reported late (#161633)
* fix(release): bound publish preflight observation, narrate frv continue, and surface SDK acknowledgement early

* fix(release): replay failed preflight reads with their exact filter

* test(release): model the exact-tag release lookup in preflight inventory fixtures
2026-09-29 23:53:05 -07:00
Peter Steinberger
f34c2a21db
feat(release): let a release lead record an exact-job flake instead of blocking publication (#161515)
* feat(release): accept exact-job recorded flakes in release validation

A release lead can classify one failed Normal CI job of a Full Release
Validation run as a flake through the trusted classification workflow. The
receipt binds the exact job id and attempt, CI child run, FRV parent run and
attempt, and Release SHA, and carries a tracking issue or PR plus a reason.
Release Decision, the manifest, the publisher's live re-derivation, the step
summary, and the GitHub release notes tail treat it as a visible advisory.
Required classes and every other child stay blocking.

* docs(release): fold recorded flakes into the shared release boundaries

* fix(release): scope flake receipt discovery to the CI child run

* fix(release): require main lineage for flake receipt producers

* test(release): copy the flake classification module into tooling fixtures

* fix(release): keep advisory-only release notes verifiable
2026-09-30 04:31:07 +00:00
Peter Steinberger
53ccbd1b7b
feat(release): watch FRV children and rerun one child with a bounded budget (#161516)
Adds `pnpm frv watch --run <parent>`: it resolves Full Release Validation children from the parent's dispatch-job logs and reports each attempt transition and failed job once, with runner labels. It tolerates transient GitHub failures and resumes from a small state file.

Adds `pnpm frv rerun --run <parent> --child <key|run-id> [--max-attempts N]`: a bounded, audited single rerun-failed-jobs request. It reruns the green producer when a consumer binds its run attempt (#161317) and checks the new attempt for duplicate or missing jobs.

Retires `pnpm frv prioritize --run`, since the priority variable no longer controls admission. `--restore` stays.
2026-09-30 02:47:22 +00:00
Peter Steinberger
2bdf8709fc
test(core): remove low-value tests (batch d009) (#158725)
* test(codex): deslop s003 tests

* test(gateway): deslop s010 tests

* test(agents): deslop s013 tests

* test(commands): deslop s011 tests

* test(gateway): deslop s014 tests

* test(gateway): deslop s019 tests

* test(infra): deslop s016 tests

* test(agents): deslop s020 tests

* test(scripts): deslop s017 tests

* test(auto-reply): deslop s021 tests

* test: align d009 replay with current fixture contracts

* test(agents): remove orphaned BTW fixture export

* test: preserve independent regression coverage in d009

Restore eight independent authentication, retry, transcript, goal, reply ownership, and Xcode coverage contracts identified during review. Final correction review passed; final Testbox validation remains pending after lease and transport failures.
2026-09-26 11:08:36 +00:00
Dallin Romney
7e8732d9d7
fix: restore blocking release validation and remove publication waivers (#157864)
* fix: restore blocking release validation and remove publication waivers

* fix(release): align recovery proof with strict validation

* docs(release): preserve qualified beta promotion

* fix(release): require strict stable orchestration and retire waived replay

* fix: read waiver-free saved release state after retry removal

* fix: discard retired capability metadata from strict release state
2026-09-25 16:27:23 -07:00
Peter Steinberger
ebdab59f91
feat(release): redesign release validation and publication for faster stable releases (#156812)
* test(release): guard parallel validation dispatch

* feat(release): seal independent child workload evidence

Record immutable, attempt-aware child receipts independently of parent completion. Keep receipt collection advisory and preserve publisher-only retry evidence. Partial child-reuse discovery and consumption remain a follow-up.

* feat(release): reuse sealed child evidence independently

* fix(ci): plan frozen release shards with trusted tooling

* ci(release): generate hosted shard timing budgets

* fix(release): make non-proof validation lanes advisory

* feat(release): seal resolved publication inputs

* fix(release): accept candidate tags at the frozen target

* docs(release): record pending first-hop parallel lanes

Item 8: remote main d51f3607b9 does not contain bf7848ef23. The feat/first-hop-compat-parallel-lanes branch still owns that implementation. Verified remote refs read-only and inspected the main scenario source; do not duplicate it here. No source changes; prior item gates remain valid.

* ci(plugins): run release plugin coverage on relevant pull requests

* ci(release): support reserved validation runner groups

* docs(release): reconcile fast-path validation guidance

* test(release): reconcile final guards and record validation

* fix(release): retry transient GitHub API failures during evidence verification

* test(release): reconcile advisory Linux CI lane cases with the fast-path policy

* test(release): copy the sealed-evidence tooling closure into the frozen fixtures

* fix(release): keep package integrity blocking and require live operator authority for sealed SDK and soak inputs

* chore(release): record the landing follow-ups in the PR body

* test(ci): expect the four-hour Testbox lease default from #156614

* test(release): reconcile untouched release suites with the advisory policy and reserved runner groups

* fix(release): reconcile advisory-by-default with full coverage and strict stable defaults

Keep RomneyDa's coverage (nine cross-OS Gateway pairs, Linux Gateway lanes as
required proof, Windows/macOS recorded as advisory) and his strict stable
publication gates (stable-profile, soak, blocking performance) as the default,
while retaining Peter's operator fast path: stable_soak_waiver / lane_waiver
are the only way to publish a stable without soak/performance evidence or with
failed non-proof lanes, must name the target version, apply only while the
repository variable still holds them, and are recorded end to end. The stable
closeout accepts the same waivers so the 2026.9.6 closeout replay can proceed.
Adopt main's affected-consumer planner (#156729) with item 4's hosted-row
split re-applied.

* fix(release): revalidate sealed soak waivers at the plugin npm publish boundary

The stable bootstrap approval records whether its soak waiver was explicit or
sealed; the plugin npm child rereads the repository variable before its
token-backed publish and rejects a sealed waiver the variable no longer holds.
Read-only preflight reports sealed waivers with the same rule. Docs state the
nine-pair all-group cross-OS rule and the strict performance gate; the tracked
planner backup is removed and the fast-core worker keeps its runner-group
routing.

* fix(release): recheck sealed waivers before npm I/O and repair CI-surfaced drift

Assert a still-held sealed soak waiver immediately before the plugin
token-backed npm publish, carry the live variable into preflight's gate
evaluation, and state the strict performance gate in the fast-path guide.
Fold main-side drift the merge surfaced: the seal job waits for the new
baseline-ratchets worker, the wrapper closure lists the CLI root options chain,
the maturity publisher's runner-group route is evaluated rather than compared
literally, and two main-authored session test-support suppressions join the
allowlist.

* fix(release): fetch waiver authority live before the plugin npm publish

Read OPENCLAW_RELEASE_STABLE_SOAK_WAIVER from the repository immediately
before the token-backed npm publish (404 means revoked, other read errors
refuse to publish), keep a waiver-less recorded closeout manifest byte-identical
on replay, and describe release_profile=stable as the stable default with the
beta profile plus stable_soak_waiver as the explicit operator fast path.

* test(release): anchor the publish-boundary recheck to the npm publish command

* fix(release): fall back to the job-start waiver when the token cannot read Variables

Keep the live read before npm publish (404 means revoked) but warn and use
the job-start snapshot instead of refusing every bootstrap publish when the
job token lacks Variables access.

* fix(release): refuse the plugin npm publish when waiver authority cannot be read

Revoked (404) and unreadable variable states both stop the token-backed
publish; a job token without Variables read access fails loudly instead of
publishing on a job-start snapshot.
2026-09-24 05:15:18 -07:00
Peter Steinberger
c93c3e0b55
fix(ci): preserve first failures through release validation
Live, Docker, channel and release wrappers could repeat failed validation
or downgrade failed jobs automatically. Run each test invocation once,
remove known-flake redispatch, and require an explicit recorded waiver
when the release policy permits one.

Wait for the original plugin publisher to settle before reporting failure.
Keep bounded artifact-download recovery before tests. Read published
v2026.9.6 empty retry metadata without restoring executable allowances or
automatic waivers, preserving the sealed plan digest. Use the existing
fresh-read owner for release-priority cleanup.

Testbox owner/sibling proof and three CI-config replays passed. The two
freshness regressions passed 20 repetitions. Published evidence retained
its original digest; nonempty retry metadata remained rejected. The stale
Testbox assertion now matches its already-landed four-hour lease; this
change raises no runtime, test, hook or watchdog budget.
2026-09-23 18:27:19 -07:00
Peter Steinberger
ecf2fc7c17
feat(ci): add bounded retries for declared flaky release jobs (#156463)
* feat(frv): retry declared flaky jobs once per child

Freeze exact flaky-job declarations into the execution plan and admit one
automatic retry wave from child attempt one to two. Retain intent and
rejection witnesses across parent recovery without replaying requests.

Coordinate manual retries with automatic owners, preserve confirmed
no-effect outcomes through later operator attempts, and finish batch
provenance admission before issuing sibling mutations. Refuse unsupported
frozen tooling before creating refs or dispatching validation.

* fix(frv): bind immutable retry cache and workflow fixtures

Limit retry-intent cache saves to parent attempt one after the intent
witness succeeds. Qualify only that exact proof-cache path, key, workflow,
and job under cache isolation.

Refresh frozen dispatch fixture defaults and bind the expanded collector
dependencies and artifact downloads to their owning jobs.

* docs(frv): clarify when retry rejection evidence exists
2026-09-23 07:29:37 -07:00
Peter Steinberger
5ed1f2d0a1
feat(ci): add targeted FRV job recovery (#156395)
Rerun one executed job as soon as its child finishes, and recover failed children without waiting for siblings. Preserve immutable plan and attempt bindings, carry valid performance guards, and prove the targeted GitHub API with the isolated broker. Related #156253.
2026-09-23 10:56:20 +00:00
Peter Steinberger
a31de9a521
fix(ci): tolerate FRV attempt materialization (#156302)
Reconcile transient duplicate jobs only in the newest retry attempt, pin run provenance, and bound controller and transport reads by the same deadline. Persistent ambiguity and older-attempt conflicts remain errors. Related #156253.
2026-09-23 01:41:53 -07:00
Peter Steinberger
f8b7dbaa46
ci: move release tooling process tours out of PR checks (#156123)
* test: split FRV CLI tours from fast recovery contracts

* ci: defer installer and FRV process tours to release validation
2026-09-22 20:26:06 -07:00
Dallin Romney
14edef7f06
fix(release): retry failed npm qualification without restarting validation (#150991)
* fix(release): reject continuation after artifact producer failure

* fix(release): retry failed npm qualification and collect its receipt

* fix(release): verify npm recovery outside diagnostic attempt map
2026-09-17 11:03:08 -07:00
Vincent Koc
6670690552
fix(ci): check publication registries before FRV fanout (#147184)
* fix(ci): check publication registries before FRV fanout

* test(ci): align FRV registry admission workflow fixtures
2026-09-14 02:07:41 +08:00
Vincent Koc
e6b8b54a0b
fix(ci): show publication observations in FRV status (#143171)
* fix(ci): show publication observations in FRV status

* fix(ci): include FRV fixtures in release routing expectations
2026-09-09 23:59:39 +09:00
Vincent Koc
56b264d5df
fix(ci): bind release baselines to immutable candidates (#136914)
* fix(ci): bind release baselines to package candidates

* fix(ci): preserve release candidate provenance

* test(ci): complete candidate provenance fixtures

* fix(release): preserve corrupt plugin allow membership

* fix(release): keep corrupt plugin fixture off Codex

* test(release): refresh candidate provenance fixtures

* test(release): normalize package candidate rejection
2026-09-03 10:59:43 -06:00
Vincent Koc
8a718610bd
fix(release): preserve legacy gh log reads (#137016) 2026-09-03 19:16:18 +08:00
Peter Steinberger
6beb5db9e0
fix(release): bind controller continuation to the plan coverage policy (#137109)
The FRV controller validated the normal CI child's dispatch scope without the
sealed plan's coverage policy, so every npm-stable-v1 plan (CI_RELEASE_SCOPE:
npm-stable since #136790) was rejected with "release normal CI dispatch scope
differs from its coverage policy" and `pnpm frv continue --failed` could not
recover a flaky child. Pass plan.coveragePolicy like the workflow-side summary
already does.

Owner: scripts/frv.mjs (same-parent recovery preflight).
Proof: new frv.test.ts case fails before the fix and passes after; 45/45
controller tests pass; observed on Full Release Validation 33722524584.
2026-09-03 00:07:42 -07:00
Peter Steinberger
06f897f562
refactor(ci): shorten release qualification and reuse prepared artifacts (#136105)
* perf(ci): shorten release qualification critical path

* fix(ci): bind native release approval to qualified CI

* test(ci): cover release retry ownership and native routing

* fix(ci): use shared waiter for native release qualification

* fix(ci): bound release diagnostics and isolate test scratch

* fix(ci): type optional npm producer verification inputs

* fix(ci): align release gates and avoid stalled iOS runners
2026-09-02 04:52:19 -07:00
Vincent Koc
8b68b7e3d8
fix(release): report missing FRV child dispatches (#136004) 2026-09-02 13:59:01 +08:00
Peter Steinberger
a162944f54
improve(release): prepare publication artifacts during validation (#135639)
* perf(release): prepare publication artifacts during validation

* fix(release): scope npm registry environment restoration

* test(ci): align release artifact verification fixtures

Account for newly tracked artifact tests and internal workflow-only inputs. Keep synthetic runner timing checks independent of unrelated suite budgets. Reuse the catalog-row selector fix already landed in #135597.

* fix(release): preserve correction identity across prepared artifacts
2026-09-01 18:41:09 -07:00
Peter Steinberger
923454e6dd
fix(scripts): preserve protected GitHub CLI routing (#133624)
* fix(scripts): preserve protected GitHub CLI routing

* test(scripts): prove authority before privileged PR effects
2026-08-30 17:59:40 -07:00
Peter Steinberger
3b609ec685
fix(ci): make Telegram release tests best effort (#133357)
* fix(ci): make Telegram release tests best effort

* fix(ci): require terminal Telegram advisory evidence
2026-08-30 09:29:13 -07:00
Vincent Koc
55abb43917
fix(release): reject unrecoverable FRV continuation (#132711) 2026-08-30 00:29:10 +08:00
Vincent Koc
f8c1398467
fix(release): make FRV reruns write-once (#132338)
* fix(release): make FRV reruns write-once

* test(ci): provide rg in main refresh fixture

* fix(release): reconcile FRV reruns by exact attempt

* fix(release): bind FRV verification attempts

* fix(release): make FRV continuation idempotent
2026-08-29 14:41:00 +08:00
Vincent Koc
1186e6a6f3
feat(release): seal full release candidate evidence (#131751)
* feat(release): seal full release candidate evidence

* fix(release): harden candidate evidence validation

* test(release): cover candidate digest tuples

* fix(release): retain candidate tooling closure

* test(ci): refresh release candidate guard inventories

* test(release): decouple candidate workflow fixture
2026-08-28 21:44:21 +08:00
Vincent Koc
c28cb02384
fix(release): resume failed validation without repeating green jobs (#128141)
* fix(release): resume failed FRV child attempts

* fix(release): harden FRV continuation controller

* fix(release): bind FRV continuation source evidence

* fix(release): support historical FRV source evidence

* fix(release): bind historical FRV source inputs

* fix(release): bind historical FRV source evidence

* fix(release): preserve historical FRV source identity

* fix(release): align FRV continuation CI checks

* fix(release): disable fail-fast for FRV continuations

* test(release): align FRV fail-fast expectation

* fix(release): classify missing FRV artifacts centrally

* fix(release): recover FRV state from workflow artifacts

* fix(release): overwrite recovered FRV plan artifact

* docs(release): clarify FRV plan recovery

* fix(release): harden FRV continuation recovery

* fix(release): revalidate FRV tooling ref before dispatch

* fix(release): authenticate historical FRV plans

* fix(release): fail FRV when temporary ref cleanup fails

* test(ci): update FRV workflow routing expectations

* fix(release): declare FRV workflow ref helper

* fix(release): keep FRV recovery on the same parent

* fix(release): verify original dispatch on parent recovery
2026-08-28 19:35:10 +08:00