Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -532,7 +532,7 @@ jobs:
runs-on: windows-latest
environment: production
if: >
github.ref_type == 'tag' ||
(github.event_name == 'push' && github.ref_type == 'tag') ||
(github.event_name == 'workflow_dispatch' &&
inputs.dry_run == false &&
inputs.publish == true &&
Expand Down
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
# Changelog

## Unreleased

## Fixes

- Issue #19: tag-selected manual workflow dry runs no longer enter the NuGet publish job. Automatic tag publishing requires a push event; manual branch publishing retains its explicit publish and dry-run gates. [#19](https://github.com/PrimordialCode/Mammoth.LiteMapper/issues/19)

## 3.0.0

### Breaking Changes
Expand Down
7 changes: 7 additions & 0 deletions DECISIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,13 @@

`SPECIFICATION.md` is authoritative. Accepted entries here are non-semantic implementation decisions unless explicitly stated otherwise.

## Issue #19: distinguish automatic tag pushes from manual dispatches (2026-10-03)

- Context: the bare tag test in the publish condition bypassed workflow_dispatch inputs. With successful prerequisites, a tag-selected dry run could enter the production approval gate even with publish=false.
- Decision: automatic tag publishing requires github.event_name=push. The existing manual branch publishing gate remains publish=true, dry_run=false on main/release/*/hotfix/*. Tag dispatches remain available for nonpublishing rehearsals; no new manual tag publishing path is introduced.
- Evidence: MSTest evaluates the actual workflow conditions and needs graph over 96 event/ref/input cases and 48 unsuccessful-prerequisite cases. Two tag-rehearsal cases verify zero mocked push calls; five authorized-path cases execute the extracted publish script with dotnet mocked locally; unsupported-event and absent-input controls also run.
- Consequences: one production YAML line changes; production environment protection, exact package/symbol validation, checksums/provenance, and NuGet push behavior remain intact. The restricted expression evaluator and local job scheduler validate current source semantics, not live GitHub runner/environment behavior. This is an operational release-safety fix, not a product-specification change.

## Accepted non-semantic implementation decisions

### DEC-0001
Expand Down
7 changes: 7 additions & 0 deletions IMPLEMENTATION_PLAN.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,12 @@
# Mammoth.LiteMapper Implementation Plan

## Issue #19: tag-selected rehearsal publishing gate (2026-10-03)

- Scope: prevent tag-selected workflow dispatches from bypassing manual publish/dry_run authorization. No generator, public API, package validation, or release-protection change.
- Test-first evidence: source-extracted condition/dependency tests and mocked execution of the actual push step initially produced 20 failures and 134 passes, with zero skips. Both dry-run tag dispatches reached three mocked pushes; non-dry-run tag dispatches already skipped pack.
- Implementation: require a push event for the automatic tag branch of the publish condition. Preserve manual production publishing on main, release/*, and hotfix/* with publish=true and dry_run=false, and preserve production approval and the successful artifact dependency chain.
- Validation: the 154 new cases and 19 existing release-quality cases pass; Release solution build has zero warnings/errors. Full local suite results are recorded in STATUS.md; exact-head ordinary PR CI results are recorded in the PR and issue #19. No release-capable workflow is dispatched and no NuGet publication is attempted.

## Issue #17: release quality and test discovery

- Scope: harden the canonical release workflow and helper for bare stable/prerelease SemVer tags, exact six-artifact handoff, checksums/provenance, package/API/consumer/AOT validation, explicit test discovery, analyzer-only generator packaging, and synchronized release documentation.
Expand Down
11 changes: 11 additions & 0 deletions STATUS.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,16 @@
# Mammoth.LiteMapper Status

## GitHub issue #19 publishing gate checkpoint (2026-10-03)

- Scope: prevent tag-selected manual rehearsals from entering the NuGet publish job. The production change requires a push event for automatic tag publishing; manual main/release/*/hotfix/* publishing still requires publish=true and dry_run=false. Production approval, dependencies, and all package/artifact validations are preserved.
- Red-first evidence: 154 new source-based condition/dependency/mock cases ran before the YAML change: 20 failed, 134 passed, zero skipped. Both tag-selected dry runs recorded three mocked push calls, including publish=false. Non-dry-run tag dispatches already skipped pack, despite their unsafe raw publish condition.
- Focused evidence: 154 new cases plus 19 existing release-quality cases pass (173 total, zero skipped). Release solution build passes with zero warnings/errors. YAML parsing and whitespace validation allowing the repository's existing CRLF endings pass. Independent read-only review found no acceptance gap.
- Full local evidence: the solution run recorded 806 passes, two sample/usage failures caused by stale NuGet assets pointing to the sandbox user's cache (NETSDK1064 for System.IO.Hashing 10.0.12), and one Native AOT prerequisite skip. Regenerating assets in the working environment and rebuilding recovered both failures; the affected tests plus all focused release tests then passed 175/175 with zero skips. Across the full run and targeted recovery, all 808 executed test cases have passing evidence; this does not claim a single all-green full-suite invocation.
- Local limitation: MSVC C++ tooling is unavailable, so NativeAotConsumerPublishesAndRunsWithoutLiteMapperWarnings is inconclusive. Trimming and the other package/consumer/API/benchmark validations passed in the full run. The initial sandbox restore failed with NU1301 SSL authentication errors; the approved unrestricted restore succeeded.
- Review handoff: draft PR targets develop. Exact-head ordinary PR CI results are recorded in the PR and issue #19. Local evidence is under artifacts/validation/issue-19/{red,focused,full,recovery}. The condition evaluator covers the workflow's current expression subset and needs graph, not live GitHub production-environment approval behavior.
- Operational note: installed AgentStack expects .agent-stack/active-tracker.json while this repository uses .agent-stack/modules/protocol/active-tracker.json; repository-authorized GitHub CLI fallback recorded the plan and significant checkpoints. GITHUB_PrimordialCode authentication remained process-local.
- Boundaries: no workflow dispatch, real NuGet push, release, tag push, merge, or security-setting change. Issue #19 remains open for human review; no unrelated issue or product contract changed.

## GitHub issue #17 release quality checkpoint (2026-09-17)

- Scope: canonical CI/release hardening for bare stable/prerelease SemVer tags, exact six-artifact handoff, package/API/consumer/AOT validation, explicit MSTest discovery, analyzer-only generator packaging, and release documentation.
Expand Down
4 changes: 2 additions & 2 deletions docs/RELEASE_CHECKLIST.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ The canonical release workflow is .github/workflows/ci.yml. Releases use bare Se

- Confirm the tag exactly matches the GitVersion SemVer value.
- Confirm the tag is protected and the production environment requires the configured human approval.
- Run the workflow manually with dry_run=true to rehearse the complete validation path.
- Run the workflow manually with dry_run=true on a branch or tag to rehearse the complete validation path. The publish job must remain skipped, regardless of the publish input.

## Validation and artifacts

Expand All @@ -21,6 +21,6 @@ The canonical release workflow is .github/workflows/ci.yml. Releases use bare Se

## Publish

- Publish only from a valid SemVer tag or an explicitly approved production workflow dispatch on main, release/**, or hotfix/**.
- Publish automatically only on a push of a valid SemVer tag. Manual production publishing requires publish=true and dry_run=false on main, release/**, or hotfix/**; selecting a tag for a manual dispatch does not authorize publishing.
- The publish job downloads and verifies the uploaded artifacts, then pushes those exact six files without duplicate suppression.
- A dry run must report the artifacts that would be published and must never call dotnet nuget push or mutate NuGet.
Loading
Loading