-
Notifications
You must be signed in to change notification settings - Fork 1.2k
docs(devlog): record the v2.34.0 release train outcome #2762
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,40 +1,104 @@ | ||
| # 020 — publish the preview prerelease | ||
| # 020 — publish the preview prerelease (revised) | ||
|
|
||
| Supersedes the first draft of this page. The original said "invoke the script in a way that | ||
| does not execute the suite here," which an independent audit of `scripts/release.ts` showed | ||
| does not exist: the local suite at `scripts/release.ts:521-555` has no flag and no env | ||
| escape, and the documented `--publish` re-entry re-runs it. | ||
|
|
||
| ## Target | ||
|
|
||
| `2.34.0-preview.20260827`, dist-tag `preview`. | ||
| `2.34.0-preview.20260827`, dist-tag `preview`, from branch `preview` at the release commit. | ||
|
|
||
| ## Division of labour, measured rather than assumed | ||
|
|
||
| `release.yml` never runs the test suite. What the script does that the workflow does not: | ||
|
|
||
| | Step | Script | Workflow | | ||
| | --- | --- | --- | | ||
| | branch/clean-tree/version-shape preflight | yes | yes, later, against `GITHUB_REF` | | ||
| | `assertUnusedReleaseVersion` + channel-moves-forward | both | unused-only | | ||
| | `audit:high`, `tsc`, **full suite**, `privacy:scan` | yes | `audit:high` yes; suite **no**; `tsc`+GUI inside `prepublishOnly` | | ||
| | bump, commit `release: v…`, deploy-key push | **yes** | **no** | | ||
| | wait for push-event `ci.yml` + `service-lifecycle` at the sha | yes | requires the runs exist; does not wait | | ||
| | create git tag + GitHub release | **no** | **yes**, and only when `dry-run != true` | | ||
|
|
||
| ## How | ||
| So the git steps are the script's alone, and the publish gates are the workflow's alone. | ||
|
|
||
| From a checkout on `preview`, with the deploy key exported: | ||
| ## Chosen route | ||
|
|
||
| Run the git steps by hand, let the branch's own push-event CI run, then dispatch: | ||
|
|
||
| ``` | ||
| OCX_RELEASE_SSH_KEY=~/.ssh/opencodex_release_ed25519 \ | ||
| bun scripts/release.ts 2.34.0-preview.20260827 --tag preview | ||
| # on preview, at the promoted head | ||
| npm version 2.34.0-preview.20260827 --no-git-tag-version | ||
| git commit -am 'release: v2.34.0-preview.20260827' | ||
| GIT_SSH_COMMAND='ssh -i ~/.ssh/opencodex_release_ed25519 -o IdentitiesOnly=yes' \ | ||
| git push git@github.com:lidge-jun/opencodex.git HEAD:preview | ||
| # wait for push-event ci.yml AND service-lifecycle at that exact sha | ||
| gh workflow run release.yml --ref preview \ | ||
| -f version=2.34.0-preview.20260827 -f tag=preview \ | ||
| -f expected-sha=<40-char sha> -f dry-run=true | ||
| # inspect, then re-dispatch with dry-run=false | ||
| ``` | ||
|
|
||
| That is the dry run — `release.yml` defaults `dry-run=true`, and the script bumps, commits, | ||
| and pushes the real release commit either way. Inspect the dispatched run, then re-run the | ||
| same command with `--publish`. | ||
| The suite runs on `ssh lidge` via `ocx-run` at that exact sha, as every phase of the | ||
| hardening unit did. This is not skipping a gate: the suite is not one of `release.yml`'s | ||
| gates, and the ones that are get enforced server-side regardless of what ran locally. | ||
|
|
||
| Rejected alternative: running `bun scripts/release.ts` on lidge. It would work and it is | ||
| the more faithful path, but it puts an interactive multi-stage release — including a | ||
| 20-minute CI wait and a deploy-key push — behind an ssh session, where a dropped | ||
| connection strands a half-pushed release. The hand route makes each step separately | ||
| observable and separately retryable. | ||
|
|
||
| ## Two traps, both verified in source | ||
|
|
||
| ## The preflight problem, and how this phase satisfies it honestly | ||
| **A dry run still pushes the bump.** `dry-run` only controls the workflow's publish/tag/ | ||
| release steps (`release.yml:319-348`). The release commit is real either way, which is the | ||
| point: the dry run exercises the actual commit. | ||
|
|
||
| The preflight runs the suite locally, which is forbidden here. Do not edit the script to | ||
| skip it. Instead: | ||
| **`release.ts` skips the bump when the version already matches** (`release.ts:568`, | ||
| `if (currentVersion === version)`). Harmless here, since `preview` carries `2.34.0` after | ||
| the promotion and the target is the prerelease string. It matters for the stable release, | ||
| where the target `2.34.0` equals what `dev` already carries — recorded in `040`. | ||
|
|
||
| 1. Run the full suite on `ssh lidge` via `ocx-run` at the exact release sha first. | ||
| 2. Let `release.ts` reach its test step. If it runs the suite locally, that violates the | ||
| constraint — so the suite step must be satisfied by the remote run and the script | ||
| invoked in a way that does not execute it here, or the release must be dispatched | ||
| directly via `gh workflow run release.yml` with the same `expected-sha` the script | ||
| would have used. | ||
| 3. Whichever route is taken, record which gates actually ran and where. The binding | ||
| checks are the workflow's own: `release.yml` verifies the version matches | ||
| `package.json` and refuses if the branch moved off `expected-sha`. | ||
| **Do not create the tag locally.** The `Protect release tags` ruleset (`20769150`) covers | ||
| `refs/tags/v*` with `deletion`, `non_fast_forward`, and `update` and has no bypass actor, and | ||
| `release.yml:268-274` refuses to publish a version whose tag already exists. The workflow | ||
| creates the tag after a successful publish. | ||
|
|
||
| ## Acceptance | ||
|
|
||
| - `npm view @bitkyc08/opencodex dist-tags` shows `preview = 2.34.0-preview.20260827` | ||
| - `npm view @bitkyc08/opencodex@2.34.0-preview.20260827 gitHead` equals the release commit | ||
| - the Release workflow run concluded `success` and was NOT a dry run | ||
| - Cross-platform CI and Service lifecycle were green at the release sha before dispatch | ||
| - the Release run concluded `success` with `dry-run=false` | ||
| - push-event Cross-platform CI and Service lifecycle were green at the release sha first | ||
|
|
||
| ## Outcome — shipped | ||
|
|
||
| Release commit `809a06ba00340c905dfac4ab588616e638c2fbfd`, one file changed | ||
| (`package.json`, 1 insertion 1 deletion), which is the same shape as both precedent | ||
| release commits `ec51e42d7` (v2.33.0) and `678517f56` (v2.33.0-preview.20260825). Built in | ||
| a detached worktree at `.tmp/rel-preview` so the `dev` checkout and the running local proxy | ||
| were never touched, then pushed to `preview` with the deploy key. | ||
|
|
||
| Gates, in the order the workflow demanded them: | ||
|
|
||
| | Gate | Evidence | | ||
| | --- | --- | | ||
| | full suite at the promoted tree | `pvsuite` on `ssh lidge`, 15334 pass / 0 fail, rc=0, at `62dfc6c54` | | ||
| | push-event Cross-platform CI | run `33072435012`, success at `809a06ba0` | | ||
| | Service lifecycle | run `33072435013`, success at `809a06ba0` | | ||
| | Release dry run | run `33073378226`, success; packed 838 files / 9.3 MB incl. a freshly built `gui/dist` | | ||
| | Release publish | run `33073503058`, success | | ||
|
|
||
| Registry and git metadata after the publish: | ||
|
|
||
| - `dist-tags` = `{ preview: 2.34.0-preview.20260827, latest: 2.33.0 }` | ||
| - `gitHead` of the published version = `809a06ba00340c905dfac4ab588616e638c2fbfd` | ||
| - tag `v2.34.0-preview.20260827` resolves to the same commit; GitHub Release exists with | ||
| `prerelease=true` | ||
|
|
||
| The `gui/dist` question the audit raised answered itself in the dry run: the directory is | ||
| gitignored but listed in `files`, and `prepublishOnly` builds it inside the workflow before | ||
| `npm pack`, so the tarball carried `gui/dist/assets/index-BPGhccMP.js` and the rest. | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -28,3 +28,65 @@ unit is closable to `_fin`. | |
| - the docs deploy run for the `main` release concluded `success` | ||
| - a real install of `2.34.0` reports `2.34.0` from its own runtime | ||
| - the record names every sha and run id rather than describing them | ||
|
|
||
| ## Outcome — the release record | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This adds the terminal release record and documents every later phase as shipped, yet the entire unit remains under AGENTS.md reference: AGENTS.md:L83-L86 Useful? React with 👍 / 👎. |
||
|
|
||
| ### Both channels, both commits | ||
|
|
||
| | Channel | Version | Release commit | Branch head | | ||
| | --- | --- | --- | --- | | ||
| | `preview` | `2.34.0-preview.20260827` | `809a06ba00340c905dfac4ab588616e638c2fbfd` | `origin/preview` | | ||
| | `latest` | `2.34.0` | `80fff9a7f47332a4445df2b26ea175053fa55b0b` | `origin/main` | | ||
|
|
||
| `dev` stayed at `7ca954ffd997197d1cff6fc6d69842be51177a8f` throughout; both release trees are | ||
| byte-identical to it apart from the preview's version string. `main` needed no separate | ||
| release commit — the promotion merge is the release commit, for the reason in `030`. | ||
|
|
||
| ### Run ids | ||
|
|
||
| | What | Run | | ||
| | --- | --- | | ||
| | preview push CI | `33072435012` | | ||
| | preview service lifecycle | `33072435013` | | ||
| | preview release dry run | `33073378226` | | ||
| | preview release publish | `33073503058` | | ||
| | promotion branch CI (the one that caught the version-line regression) | `33074009466` | | ||
| | promotion branch hygiene (after relabel) | `33074473195` | | ||
| | main push CI | `33075147758` | | ||
| | main service lifecycle | `33075147219` | | ||
| | main release dry run | `33076185925` | | ||
| | main release publish | `33076348477` | | ||
| | docs deploy | `33075147234` | | ||
|
|
||
| Remote full suite: `pvsuite` on `ssh lidge` at `62dfc6c54` (the tree both releases ship), | ||
| 15334 pass / 0 fail, rc=0. | ||
|
|
||
| ### Docs deploy | ||
|
|
||
| `deploy-docs.yml` fired on the promotion push without a manual dispatch, as expected from | ||
| the `docs-site/**` path filter. Run `33075147234` at `80fff9a7f`, both `build` and `deploy` | ||
| jobs success, and the `github-pages` deployment `6123269073` is bound to that same sha. | ||
| `https://opencodex.me/` answers `200` and serves the expected title. The legacy | ||
| `/pages/builds/latest` API returns 404 here because Pages is workflow-built, not | ||
| legacy-built — that is not a failure signal. | ||
|
|
||
| ### Installed-runtime proof | ||
|
|
||
| In a `mktemp -d`: `npm pack @bitkyc08/opencodex@2.34.0` then unpacked gives | ||
| `package/package.json` at `2.34.0` with `package/gui/dist/index.html` present and both | ||
| `bin` entries intact; installing it and running the installed binary prints | ||
| `opencodex 2.34.0`. Packed size matched the preview exactly — 838 files, 9.3 MB packed, | ||
| 19.9 MB unpacked — which is what publishing identical trees to two channels should look | ||
| like. | ||
|
|
||
| ### What is deliberately NOT in this release | ||
|
|
||
| PR #2745 (OAuth 429 credential-identity rebind) is unmerged, awaiting the security review | ||
| `MAINTAINERS.md` requires for credential-handling changes. The drift it fixes ships to both | ||
| channels unfixed. This was disclosed in the readiness statement before the train started and | ||
|
Comment on lines
+84
to
+86
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This publishes the identity-drift failure mode and its unmerged corrective PR while explicitly stating that the defect remains in both release channels; the nearby open-CodeQL assessment likewise belongs to ongoing security triage. Repository policy requires unreleased findings and severity assessments to stay in scratch space rather than tracked AGENTS.md reference: AGENTS.md:L103-L112 Useful? React with 👍 / 👎. |
||
| is not a decision made here. | ||
|
|
||
| Separately, and worth stating plainly rather than burying: `dev` carries 84 open CodeQL | ||
| alerts (78 high) against `main`'s previous 73, so this train raises the open-alert count by | ||
| 11. None were introduced by the promotion itself — the branch diff against `dev` was empty — | ||
| but they now ship on `latest`. Triaging them is separate work against `dev`. | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The outcome identifies the preview release commit as
809a06ba0but records the remote full suite at62dfc6c54, so the suite did not run at the "exact sha" asserted here; the version bump means these are not even identical Git trees. Describe this as validation of the promoted pre-bump tree and rely explicitly on the push CI at809a06ba0, or provide full-suite evidence from the actual release commit.Useful? React with 👍 / 👎.