Skip to content

docs: define v0.3 release assessment and safe cutover order - #3151

Merged
Chris0Jeky merged 19 commits into
mainfrom
docs/v0.3-release-assessment-2026-09-17
Sep 18, 2026
Merged

Chris0Jeky merged 19 commits into
mainfrom
docs/v0.3-release-assessment-2026-09-17

Conversation

@Chris0Jeky

@Chris0Jeky Chris0Jeky commented Sep 17, 2026

Copy link
Copy Markdown
Owner

Summary

Add a dated release-owner assessment for the final v0.3.0 path and reconcile the canonical private-repository cutover checklist with the safe executable order.

The assessment and checklist now:

  • distinguish issue throughput from formal release-gate completion;
  • preserve the ruled [Backend][Frontend][Review] Make proposal provenance metadata lifecycle- and authorization-safe #2315 residual instead of recreating it as a blocker;
  • separate already-settled product and infrastructure rulings from genuinely open maintainer decisions;
  • map the coupled path across Smart CI, storage, exact-tag qualification, least privilege, runner isolation, private cutover, GHCR continuity, and the public mirror;
  • propose explicit release dispositions for every issue open in the measured 2026-09-17 snapshot;
  • record fix(ci): close Smart CI merge-base receipt residuals #3156 and feat(ci): add fail-closed landed-verifier decision core #3167 as active bounded implementation lanes;
  • define runner-aware exact-tag qualification and the private-Release-to-public-mirror handoff;
  • put repository privacy before stable Smart CI gate registration in the executable checklist;
  • require both post-privacy and frozen-final-head rehearsals to use the trusted fail-closed Linux-only mode before exact-tag Windows qualification;
  • keep sections A-J as genuine pre-cutover readiness proof and move all real-tag, post-association, exact-tag qualification, publication, mirror, and announcement actions to section L.

Live delta after the dated snapshot

The assessment deliberately preserves its measured 2026-09-17 boundary. Live GitHub has since moved to:

For release routing:

Review repairs

The current head ee101bb364dd7097457ff124577f8fc0da97e08c incorporates the review rounds to date:

Boundary

This PR updates a dated decision-support artifact under docs/analysis/ and the canonical executable checklist under docs/ci/. It does not mutate issue closure or milestone membership, authorize deletion, alter secrets/settings, change repository visibility, register runners, change package visibility, or infer maintainer approval. Live GitHub and newer recorded rulings remain authoritative.

Verification

Supports #2235, #2324, #2337, #2439, and #3170.

Latest targeted follow-up at c2dc5dc makes the A-J prerequisite set and the pre-runner-association CI-17 Linux-only rehearsal explicit in both readiness and human-action sequencing.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 17, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-18T00:02:23.895658Z 79e09b2 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 33a6218aa3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
@Chris0Jeky

Copy link
Copy Markdown
Owner Author

Addressed the three direct policy blockers identified in the fresh-context review at the prior head. Commit e74f4ab now: (1) keeps strict branch-current and administrator enforcement as evidence-based maintainer decisions rather than settled settings; (2) makes the settled $0 Actions ceiling binding and removes paid overage as a v0.3 release option; and (3) keeps #2838 behind the explicit ADR-0066/J.3 maintainer gate and review before any merge. Local git diff --check and node scripts/check-doc-links.mjs pass; hosted checks and the post-fix review are requalifying at this head.

Copy link
Copy Markdown
Owner Author

@codex review

All five initial review threads are addressed and resolved on 4df31cb227fc1fa0e0a0445cc895a86e8cf9ef3f. Please re-review the corrected release sequencing and settled-decision alignment.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4df31cb227

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated

Copy link
Copy Markdown
Owner Author

@codex review

Both review rounds have been addressed and all threads are resolved on 95601f578d492a961f460d86d0a25eb3193d30f7. Please perform a final consistency pass against the authoritative release and cutover documents.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 95601f578d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated

Copy link
Copy Markdown
Owner Author

@codex review

All three review rounds are addressed on exact head 44522782d5f4139f4be313836a1fe660103a4a36. Please perform a final consistency pass, particularly across GHCR pre-cutover visibility, hosted-only private rehearsal, runner association, and exact-tag Windows qualification under the settled $0 posture.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 44522782d5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md
@Chris0Jeky

Copy link
Copy Markdown
Owner Author

Repair pushed at 3c93884 and rebased by merge onto current main 1983a06. The assessment now (1) excludes the Windows release job from the hosted-only private rehearsal, (2) requires a secret-safe isolated Windows runner and forbids release credentials on ordinary hosted or persistent CI-04 runners, and (3) requires a proven draft-only publication hold before the real tag. Verified locally with git diff --check and node scripts/check-doc-links.mjs: 0 broken relative links; the three masking warnings are pre-existing files outside this change. Hosted checks and fresh post-push review remain pending.

Copy link
Copy Markdown
Owner Author

@codex review

Please review the current head 3c93884b6d0ae0fc2fdc017218a43d5b8394d324 after the post-tag publication hold, isolated Windows release-credential boundary, and hosted-only rehearsal exclusions were added. The PR body now also records the live #3158 / #3162 milestone delta without altering the dated document snapshot.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3c93884b6d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated

Copy link
Copy Markdown
Owner Author

@codex address that feedback

Address the current-head P1 review finding in discussion 4042320998: the post-privacy, pre-runner-association rehearsal must use a proven Linux-only mode across all required CI and reusable workflows, suppressing every private hosted Windows lane, not only the Windows release job. Align CP-7, H9, execution waves, and the definition of done, and keep cutover fail-closed if that mode is absent or bypassable.

@chatgpt-codex-connector

Copy link
Copy Markdown

Summary

Testing

  • git diff --check
  • node scripts/check-doc-links.mjs — passed with 0 broken relative links; it reported three pre-existing malformed-code-delimiter masking warnings outside this change.
  • node scripts/check-docs-governance.mjs
  • git status --short --branch — clean working tree on branch work.

View task →

Copy link
Copy Markdown
Owner Author

@codex review

The current head bcb785ad1e57aa590643020ebcd0b8ae8483f4c9 addresses the remaining P1 by making the post-privacy, pre-association rehearsal fail-closed and Linux-only across required CI plus every called/reusable workflow. Please perform a fresh consistency review of CP-7, H9, the execution waves, and the definition of done.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bcb785ad1e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md
Comment thread docs/analysis/2026-09-17-v0.3-release-assessment.md Outdated

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact head 3fb2cf488ab09d1fba2f98d2089ef6454d9f7cbc. The canonical cutover checklist now places privacy before required-gate registration and carries the same GHCR, Linux-only rehearsal, pre-association runner, exact-tag Windows, private-Release, mirror, and rollback order as the assessment and #2337. The frozen final-head rehearsal now also uses the trusted Linux-only mode with self-hosted runners offline.

@Chris0Jeky Chris0Jeky changed the title docs: add current v0.3 release assessment docs: define v0.3 release assessment and safe cutover order Sep 17, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3fb2cf488a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md Outdated

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact head 79e09b210e1b66234a87d7a022bc45c48bd2ffeb. The latest repair removes the A-I/SC-6 circular dependency: section H now proves only pre-cutover nightly/release mechanisms and public-mode evidence; real-tag creation, post-association exact-tag qualification, publication, mirror, and announcement remain solely in section L.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 79e09b210e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md
Comment thread docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md Outdated
@Chris0Jeky

Copy link
Copy Markdown
Owner Author

Follow-up to the fresh review: cf2d587 removes the remaining stale exact-tag qualification wording from the readiness/assessment documents. Section H now requires only pre-cutover release-contract and public/no-publish rehearsal readiness; real-tag qualification/publication remain in section L after privacy and runner association. Docs governance, doc links (0 broken; 3 pre-existing masking warnings), and git diff --check pass. Current base is main@1983a06d; fresh exact-head review and hosted checks remain pending.

@Chris0Jeky

Copy link
Copy Markdown
Owner Author

Follow-up fix pushed at c2dc5dc. It removes the stale CI-16-as-section-A / A-to-I mapping, and makes the required order explicit: after the private-mode CI-17 Linux-only rehearsal while runners remain unassociated, SC-7 may associate only already-proven runners. The existing checklist already states the same order; the readiness and SC-7 human-action text now match it.

@Chris0Jeky Chris0Jeky left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fresh-context review — SHIP

Head ee101bb364dd7097457ff124577f8fc0da97e08c. Docs/analysis + cutover checklist + OUTSTANDING_TASKS.md SC-6/SC-7 wording only.

Lenses: executable-instruction effect, false safety claims, human-action check-off, control-plane merge authority.

Verdict: SHIP. No merge-blocking correctness, security, or data-loss defect.

  • Human items SC-6/SC-7 stay [ ]. Agents are still forbidden from visibility/billing/runner-association.
  • Formal verdict is no-go for the final tag; it does not authorize a cutover or a control-plane merge. J.3 is named as still unanswered.
  • Dated assessment is labelled snapshot, not a replacement for live GitHub or maintainer rulings.

Non-blocking: the 2026-09-17 SHA/milestone counts will age; that is inherent to a dated assessment, not a defect.

No @codex review summoned. Docs-only; this review covers the current head (Codex comments exist on older commits only).

@chatgpt-codex-connector

Copy link
Copy Markdown

On it

@chatgpt-codex-connector

Copy link
Copy Markdown

Summary

  • Confirmed the fresh-context review verdict is SHIP for exact head ee101bb364dd7097457ff124577f8fc0da97e08c; no follow-up code or documentation changes were requested or warranted.
  • The assessment remains explicitly a dated decision-support snapshot and retains the formal no-go position for the final tag. docs/analysis/2026-09-17-v0.3-release-assessment.mdL3-L4 docs/analysis/2026-09-17-v0.3-release-assessment.mdL68-L69
  • The unresolved ADR-0066/J.3 maintainer decision continues to gate the relevant control-plane merge. docs/analysis/2026-09-17-v0.3-release-assessment.mdL171-L172
  • Human-only actions SC-6 and SC-7 remain unchecked: agents may neither change repository visibility/billing nor associate runners before the private Linux-only rehearsal succeeds. OUTSTANDING_TASKS.mdL167-L168
  • The working tree was clean, so there were no changes to commit and—per the no-empty-PR requirement—no follow-up pull request was created.
  • Other open human-action items in OUTSTANDING_TASKS.md remain unchanged, including SC-4, SC-6, SC-7, J.3, credential rotation, and device-specific verification items.

Testing

  • git rev-parse HEAD — returned ee101bb364dd7097457ff124577f8fc0da97e08c.
  • git status --short --branch — clean working tree on branch work.
  • rg -n "no-go|J\\.3|snapshot|SC-6|SC-7|Agents never|visibility or billing|associate" docs/analysis/2026-09-17-v0.3-release-assessment.md OUTSTANDING_TASKS.md docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md — confirmed the stated safety boundaries and open human gates.
  • rg -n '^\\s*- \\[ \\]' OUTSTANDING_TASKS.md — reviewed and preserved the repository’s open human-action items.

View task →

@Chris0Jeky
Chris0Jeky merged commit 647f3a1 into main Sep 18, 2026
11 checks passed
@Chris0Jeky
Chris0Jeky deleted the docs/v0.3-release-assessment-2026-09-17 branch September 18, 2026 09:59
@github-project-automation github-project-automation Bot moved this from Pending to Done in Taskdeck Execution Sep 18, 2026
@Chris0Jeky

Copy link
Copy Markdown
Owner Author

Post-hoc disclosure (criterion 3 / verification plan step 5): this PR was merged before the full ci-required graph had concluded SUCCESS on the exact head. Pending is not green. Later check conclusions are recorded in the session postmerge-ci.json; they do not retroactively satisfy the pre-merge gate. No revert inferred from this comment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant