fix(delivery): publish the delivery record for absent-N (fresh-host setup gate) - #2634
Conversation
…s pass the setup gate Live-QA finding (v5.260723.3, fresh-plugin linux host): the delivery path published a record only for PENDING deliveries (installed N differs from T), so a host whose codex plugin was never installed (N absent) delivered .3 with no record. Group E's Decision-9 setup gate then refused activation (delivery-incomplete) and its recovery pointed back at genie update — whose delivery path would again not publish. Only the already-current repair path minted the record, forcing a second update run before the first genie setup --codex could ever succeed. The record binds DELIVERY facts, not an activation: absent-N now publishes the same pure fact write (no journal/activation/cache mutation, no downgrade receipt), which Decision 10 permits (only update/install publish). current and indeterminate still publish nothing.
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a855f81e6e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| export function buildDeliveryPublication(facts: CodexDeliveryFacts): PublishDeliveryInput | null { | ||
| const state = classifyCodexDelivery(facts.installedVersion, facts.targetVersion); | ||
| if (state.kind !== 'pending') return null; | ||
| if (state.kind !== 'pending' && state.kind !== 'absent') return null; |
There was a problem hiding this comment.
Do not publish absent records when the installed version is unknown
When publishCodexDeliveryFacts cannot read codex plugin list, it currently passes installedVersion: null via the fallback in src/genie-commands/update.ts; with this new absent branch, that unknown state now publishes a delivery record as if the plugin were truly absent and therefore never sets downgradeFrom. In an explicit downgrade where the list query transiently fails after the binary swap, publishDeliveryImpl writes a matching record and removes/omits the downgrade receipt; later already-current repair sees the record as matching, while setup classifies the still-newer installed plugin as installed-newer, so rerunning update/setup cannot activate the selected downgrade. Please only publish this path for an actually observed absent registration, not for an unclassified query failure.
Useful? React with 👍 / 👎.
…s, IN_PROGRESS The H3 SessionStart line surfaced ledger drift: waves 1+2 shipped 2026-07-22 (PRs automagik-dev#2625/automagik-dev#2626/automagik-dev#2628/automagik-dev#2629, per-group SHIP reviews, validations reproduced) but their evidence and criteria were never recorded; status still read APPROVED with execution long underway. - status APPROVED -> IN_PROGRESS - 41 evidence-backed criteria ticked (5 -> 46/67): Groups A-D ACs + global criteria owned by merged groups; deliberately NOT ticked: the two live 'codex mcp get genie --json' operator proofs, Group F/G criteria, and all post-merge QA rows - appended the waves-1+2 evidence block, the seven live-QA fixes (automagik-dev#2631-automagik-dev#2634, automagik-dev#2636), Group E's actual merge commit (4be6917), and the open automagik-dev#2633-deferred follow-up (pre-A route-arm retirement) Adversarially verified pre-commit by the pm-ledger-verify workflow: 0 must-fix; its 4 advisory findings (defect count, untracked follow-up, unrecorded E merge) are incorporated above.
Live-QA finding from the v5.260723.3 dogfood (fresh-plugin linux host)
genie setup --codexon a host whose codex plugin was never installed refused withdelivery-incomplete— and its recovery ("run genie update") looped, because the delivery path only publishes a record for pending deliveries (installed N ≠ T). With N absent, delivery published nothing; only the already-current repair path mints the record, forcing this dance on every fresh codex host:update (delivers, no record) → setup refuses → update again (repair publishes) → setup works
Fix
buildDeliveryPublicationnow publishes forabsenttoo. The record binds delivery facts, not an activation — publication stays a pure fact write (no journal, activation, receipt, or cache mutation), which Decision 10 permits (only update/install publish).current/indeterminatestill publish nothing. Downgrade binding remains pending-only.Result: one
genie update→ onegenie setup --codexon fresh hosts, exactly as the recovery text promises.Validation (self-run): codex-delivery/install/update/install-promote/repair suites 277/0 with the two absent-N contract tests inverted and extended; full suite green except the pre-existing macOS-only
ssui-bridge test and one isolated-pass concurrency flake; typecheck + lint clean.