Skip to content

chore(release): group 6 — toolchain, version --check, and the codex dogfood matrix deletion - #2883

Merged
namastex888 merged 3 commits into
wish/skills-everywhere-bfrom
wish/skills-everywhere-b-g6
Sep 1, 2026
Merged

namastex888 merged 3 commits into
wish/skills-everywhere-bfrom
wish/skills-everywhere-b-g6

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

Group 6 of wish skills-everywhere-b: the build/release toolchain and the release workflow (criterion C11). This is the one group whose failures never surface in bun run check, so every C11 command was run and its output is pasted below.

This commit closes the G3 release freeze. codex-native-dogfood and its codex-dogfood-completeness roll-up were guaranteed red on every head carrying G3 (they require exit 2 / activation-pending from update --publish-local-delivery and a setup --codex run matching /Activated Codex plugin/, all deleted in G3). Both jobs and their publish.needs edge are gone, so wish/skills-everywhere-b is releasable again.

3 commits, 19 files, +256 / −4,482.


Deliverable status

# Deliverable State
1 build-binary.sh stages only the Orca tree + skills/; marketplace staging, the required-file loop beyond the two Orca entries, the per-skill mirror assertions, --plugin-root and verify-codex-activation-payload.ts all gone Already landed in G3/G4 — verified below (build-binary.sh green, tarball top level = exactly INSTALL_PAYLOAD_MEMBERS, plugins/genie = Orca only). No edit needed.
2 release-payload-version.ts reduced to the three files; verifyCodexMarketplaceEntry + both call sites gone; .claude-plugin / .agents stamping gone; --verify-source still works Already landed in G3/G4 — file is 136 lines, TOP_LEVEL_VERSION_FILES = plugins/genie/{package.json,orca-plugin.json}, COMMITTED_VERSION_FILES = package.json + plugins/genie/package.json. Verified below.
3 Same reduction in version.ts, version.yml, release-guard.sh; the version-file-count error message and release-docs.test.ts follow; CLAUDE.md sentence Code already landed in G4/G5 (version.yml says expected exactly three version files; release-guard.sh lists two required + one conditional). CLAUDE.md's stale "still five version files" fixed here, plus version.yml's stale "all six changed fields" header.
4 scripts/version.ts --check read-only mode Done here.
5 Delete scripts/build.js + scripts/sync.js with build:plugin / build-and-sync / sync Done here (+ the scripts/build.js build-tarballs.yml path filter and its release-docs.test.ts literal).
6 fresh-install-smoke.ts loses the whole plugin-layout half, derives its inventory from skills/*/SKILL.md, keeps the negative source-path assertion extended to $GENIE_HOME/plugins/genie/skills Already landed in G4 — verified below. The file is 320 lines, has no --plugin-root, listSkillNames() reads skills/*/SKILL.md, and :118 forbids the prefix $GENIE_HOME/plugins/genie, which subsumes .../skills. No edit needed.
7 Delete codex-native-dogfood + codex-dogfood-completeness and exactly one publish.needs edge; delete the harness, entry-runner and both validators; decide on candidate-dogfood-matrix.ts Done here.
8 Verify (not assume) that build-delivery-evidence.ts and release-update-path-smoke are tree-level Verified, no edit — evidence below.
9 run-musl-dogfood.sh + musl-adapter-smoke.yml byte-unchanged Verified empty diff below.
10 Re-point every broken test Done here — version-format.test.ts, release-docs.test.ts, workflow-yaml-parse.test.ts.
11 Record that version.yml is workflow_run Recorded below.

C11 — every command, with output

bun scripts/release-payload-version.ts --verify-source .

release-payload-version: OK (verify-source 5.260831.7)
exit=0

bash scripts/build-binary.sh --platform linux-x64-glibc

fresh-install-smoke: OK (25 valid skills, 22 bundled references, Claude variables unset)
orca-bundle-parity: OK
release-payload-version: OK (verify-source 5.260831.7)
==> [linux-x64-glibc] bun build --compile --target=bun-linux-x64  (v5.260831.7)
  [77ms]  bundle  283 modules
 [399ms] compile  .../dist/linux-x64-glibc/genie
release-payload-version: OK (stamp 5.260831.7)
fresh-install-smoke: OK (25 valid skills, 22 bundled references, Claude variables unset)
release-payload-version: OK (verify 5.260831.7)
fresh-install-smoke: OK (25 valid skills, 22 bundled references, Claude variables unset)
release-payload-version: OK (verify 5.260831.7)
==> .../dist/genie-5.260831.7-linux-x64-glibc.tar.gz  (34 MB)
exit=0

The four-platform CI matrix (build-tarballs.yml) is the rest of C11's "green on all four platforms"; only linux-x64-glibc is runnable on this host.

Payload layout re-proof (the G3 INSTALL_PAYLOAD_MEMBERS lesson). tar -tzf top level over the freshly built tarball, and the plugins/genie contents:

$ tar -tzf dist/genie-5.260831.7-linux-x64-glibc.tar.gz | sed 's|^\./||' | cut -d/ -f1 | sort -u
LICENSE
VERSION
genie
plugins
skills
templates

$ tar -tzf ... | grep '^\./plugins/' | sed 's|^\./plugins/genie/||' | cut -d/ -f1 | sort -u
README.md
orca-entrypoint.min.js
orca-entrypoint.ts
orca-plugin.json
orca-runtime.ts
package.json
plugin.json
references

$ grep -n INSTALL_PAYLOAD_MEMBERS src/lib/install-promotion.ts
32:export const INSTALL_PAYLOAD_MEMBERS = ['LICENSE', 'VERSION', 'genie', 'plugins', 'skills', 'templates'] as const;

Exact match, and plugins/genie is the Orca tree only — deliverable 1 confirmed complete on entry. bun test scripts/install-swap.test.ts green (in batch 2 below).

bash scripts/release-guard.sh — substituted, recorded

The literal command in the wish's validation block is not runnable and never was:

$ bash scripts/release-guard.sh
release-guard: unknown subcommand '<none>'
exit=64

$ bash scripts/release-guard.sh guard-trusted-release
release-guard: privileged release workflow must run from trusted refs/heads/main (got '<empty>')
exit=3

The script has no default subcommand (:504 *) misuse "unknown subcommand"), and its only workflow invocation (release.yml:116 guard-trusted-release) fail-closes outside Actions by design. The proof is therefore its test suite — the same substitution G5's review recorded:

$ bun test scripts/release-guard.test.ts
 39 pass
 0 fail
 81 expect() calls

release-guard.sh's version list is already the reduced set (:161-172): package.json + plugins/genie/package.json required, plugins/genie/orca-plugin.json accepted when it moved.

bun scripts/fresh-install-smoke.ts

fresh-install-smoke: OK (25 valid skills, 22 bundled references, Claude variables unset)
exit=0

25 = the post-#2870 inventory, derived from skills/*/SKILL.md. Also run three more times inside build-binary.sh (source, staged payload, extracted payload).

bun scripts/version.ts --check — the new mode

version --check: 3 version file(s), no writes performed
  • package.json
  • plugins/genie/orca-plugin.json
  • plugins/genie/package.json

✅ Every version file is present and bump-ready
exit=0

Exits 0 and names only the three files C11 requires. The mode is read-only by construction: it calls assertVersionFileShape (which parses and dry-runs the token replacement, writing nothing) and never calls generateVersion(). Argument handling now runs before any mutation and rejects anything that is not exactly --check, so a typo can never degrade into the irreversible bare bump. Two new unit tests cover the happy path (byte-identical files before/after) and the failure path (a malformed and a missing target reported, not rewritten).

bun test scripts/version-format.test.ts scripts/version-ci-staging.test.ts scripts/release-docs.test.ts

Run as part of the full scripts/ batch:

$ bun test scripts/version-format.test.ts scripts/version-ci-staging.test.ts scripts/release-docs.test.ts \
           scripts/release-payload-version.test.ts scripts/release-guard.test.ts scripts/workflow-yaml-parse.test.ts
 116 pass / 0 fail / 1068 expect() calls

$ bun test scripts/build-delivery-evidence.test.ts scripts/materialize-release-subjects.test.ts \
           scripts/verify-delivery-evidence-pack.test.ts scripts/candidate-dogfood-matrix.test.ts \
           scripts/fresh-install-smoke.test.ts scripts/install-swap.test.ts
 34 pass / 0 fail / 152 expect() calls

$ bun test scripts/skills-lint.test.ts scripts/skills-inventory-parity.test.ts scripts/orca-manifest-parity.test.ts \
           scripts/orca-bundle-parity.test.ts scripts/complexity-budget.test.ts scripts/wishes-lint.test.ts \
           scripts/design-review-evidence.test.ts scripts/gh-retry.test.ts
 106 pass / 0 fail / 226 expect() calls

$ bun test scripts/reconcile-channel-manifests.test.ts scripts/reconcile-release-note.test.ts \
           scripts/release-generic-provenance.test.ts scripts/release-native-predicate.test.ts \
           scripts/release-immutability.test.ts scripts/release-replay-guard.test.ts \
           scripts/verify-release.test.ts scripts/run-musl-dogfood.test.ts
 53 pass / 0 fail / 203 expect() calls

309 pass / 0 fail across every scripts/*.test.ts except scripts/reconcile-release-assets.test.ts, which times out locally (pre-existing, recorded in the wave handoff). CI runs it.

bun test src/lib/delivery-evidence-verify.test.ts — 9 pass (the one src/ file touched, a comment only).

bun run check — substituted by check:fast

Per the host OOM rule the full bun test step is left to CI. check:fast ran green as the pre-push hook on every push:

$ bun run typecheck && bun run lint && bun run dead-code && bun run skills:lint && bun run wishes:lint \
  && bun run lint:complexity-budget && bun run lint:orca-bundle
tsc --noEmit                → clean
biome check .               → 2 warnings (pre-existing complexity: doctor.ts:765 = 26, orca-orchestration-adapter.ts:789 = 29)
bunx knip                   → clean
skills-lint: OK (43 files scanned, 0 missing, 0 resource violations)
wishes-lint: OK (84 files scanned, 0 broken brainstorm links, template validator green)
complexity-budget           → Warnings 2/7, max 29/42, suppressions 0/8 — OK: budget intact.
orca-bundle-parity: OK

C7 — the release-workflow proof

Neither job exists, and nothing needs them

$ git grep -nE "^  (codex-native-dogfood|codex-dogfood-completeness):" -- .github/workflows/
(no output; grep exit 1)

Parsed as YAML rather than grepped, the full job DAG is now:

admit                            | needs: null
prepare-delivery-evidence        | needs: "admit"
attest-delivery-evidence         | needs: "prepare-delivery-evidence"
delivery-evidence-compatibility  | needs: ["admit","attest-delivery-evidence"]
skills-install-smoke             | needs: "prepare-delivery-evidence"
release-update-path-smoke        | needs: ["prepare-delivery-evidence","attest-delivery-evidence","delivery-evidence-compatibility"]
stable-release-security-gate     | needs: ["prepare-delivery-evidence","attest-delivery-evidence","delivery-evidence-compatibility"]
publish                          | needs: ["admit","attest-delivery-evidence","delivery-evidence-compatibility","skills-install-smoke","release-update-path-smoke","stable-release-security-gate"]
manifests                        | needs: "finalize"
finalize                         | needs: "publish"

publish.needs — six edges, each with its if: guard

Exactly one edge left (codex-dogfood-completeness) with exactly its own guard line; the other six edges and their six guard lines are byte-intact:

  publish:
    name: Publish to GitHub Releases
    needs:
      - admit
      - attest-delivery-evidence
      - delivery-evidence-compatibility
      - skills-install-smoke
      - release-update-path-smoke
      - stable-release-security-gate
    if: >-
      ${{
        always() &&
        needs.admit.result == 'success' &&
        needs.attest-delivery-evidence.result == 'success' &&
        needs.delivery-evidence-compatibility.result == 'success' &&
        needs.skills-install-smoke.result == 'success' &&
        needs.release-update-path-smoke.result == 'success' &&
        needs.stable-release-security-gate.result == 'success'
      }}

release-update-path-smoke still depends on genie update --publish-local-delivery (asserted by workflow-yaml-parse.test.ts: expect(smoke).toContain('update --publish-local-delivery'), plus .code == "delivery-verified" and .deliveryComplete == true). stable-release-security-gate still consumes scripts/candidate-dogfood-matrix.ts.

Both facts are now pinned by new tests rather than left to review:

  • workflow-yaml-parse.test.ts → "publish requires exactly the six surviving gates, each with its if-guard" (asserts the edge list with toEqual, then loops the guard for each).
  • workflow-yaml-parse.test.ts → "the Codex dogfood matrix is gone and nothing needs it" (loops every job's needs).
  • release-docs.test.ts → the six-gate loop plus expect(publish.split('\n').filter(isEdgeLine)).toHaveLength(6).

git diff --exit-code origin/dev -- .github/workflows/musl-adapter-smoke.yml scripts/run-musl-dogfood.sh

(empty; exit 0)

MUSL DIFF EMPTY (exit 0). scripts/run-musl-dogfood.test.ts green.


The candidate-dogfood-matrix.ts decision — KEEP, both consumers named

scripts/candidate-dogfood-matrix.ts is kept, and only its dogfood-matrix consumers were deleted. The wish's alternative — reworking the two surviving consumer jobs — was rejected.

The two consuming jobs, by name:

  1. prepare-delivery-evidence (release-publish.yml, the Generate retry-stable candidate manifests and descriptors step). It derives the entire platform inventory from it:
    • bun scripts/candidate-dogfood-matrix.ts --manifest "$SELECTED_MANIFEST" --artifact-dir dist --output candidate-dogfood-matrix.json
    • mapfile -t MANIFEST_PLATFORMS < <(jq -er '.include[].platform' candidate-dogfood-matrix.json) — the loop that builds every delivery descriptor and every previous-stable download
    • UPDATE_PATH_MATRIX is a jq projection of the same file, and release-update-path-smoke's whole strategy matrix is that projection
    • a second invocation re-derives the matrix for the previous stable release and cross-checks the platform sets
  2. stable-release-security-gate — itself a publish.needs edge. It re-derives the matrix from the downloaded manifest with independent release controls and cmps it against the artifact prepare-delivery-evidence uploaded:
    • bun scripts/candidate-dogfood-matrix.ts --manifest "$MANIFEST" --artifact-dir security-gate/dist --output security-gate/rederived-matrix.json
    • cmp -- security-gate/candidate-dogfood-matrix.json security-gate/rederived-matrix.json
    • every per-artifact digest it verifies comes out of rederived-matrix.json, and scripts/candidate-dogfood-matrix.test.ts is one of the eight suites it runs in-job

Why keep. The script's name is historical; its job is "derive the admitted platform inventory from the selected manifest", which is now load-bearing for a publish.needs gate and for the update-path smoke's platform coverage. Deleting it would force rewriting the security gate's independent re-derivation — the single strongest anti-tamper control in the release — as part of a deletion PR. release-docs.test.ts:288 and workflow-yaml-parse.test.ts:162 therefore keep asserting it, and a new workflow-yaml-parse.test.ts test ("candidate-dogfood-matrix.ts survives with both of its consuming jobs") pins both consumers so a later "it was only for the dogfood" cleanup fails loudly.

The one thing that did leave with the matrix: prepare-delivery-evidence's dogfood_matrix job output (and the DOGFOOD_MATRIX shell variable feeding it). Its only consumers were codex-native-dogfood's strategy.matrix and codex-dogfood-completeness's EXPECTED_MATRIX; with both jobs gone it was dead workflow config. The candidate-dogfood-matrix.json file it projected is still built, still uploaded as codex-dogfood-candidate-matrix, and still downloaded by stable-release-security-gate. Recorded as a deviation below since the wish did not name it.


No workflow references a deleted script

Every scripts/… and tests/support/… path appearing anywhere under .github/workflows/, checked for existence on this head:

$ grep -rhoE "(scripts|tests/support)/[A-Za-z0-9._/-]+\.(ts|sh|js|mjs|cjs)" .github/workflows/ | sort -u | while read -r p; do
    [ -f "$p" ] && echo "OK      $p" || echo "MISSING $p"; done

OK      scripts/audit-next-tag-pinning.sh      OK      scripts/release-generic-provenance.sh
OK      scripts/build-binary.sh                OK      scripts/release-generic-provenance.test.ts
OK      scripts/build-delivery-evidence.test.ts OK     scripts/release-guard.sh
OK      scripts/build-delivery-evidence.ts     OK      scripts/release-guard.test.ts
OK      scripts/candidate-dogfood-matrix.test.ts OK    scripts/release-immutability.sh
OK      scripts/candidate-dogfood-matrix.ts    OK      scripts/release-native-predicate.sh
OK      scripts/check-action-pins.sh           OK      scripts/release-native-predicate.test.ts
OK      scripts/check-fingerprint-pinning.sh   OK      scripts/release-payload-version.ts
OK      scripts/fresh-install-smoke.ts         OK      scripts/run-musl-dogfood.sh
OK      scripts/gh-retry.sh                    OK      scripts/skills-inventory-parity.test.ts
OK      scripts/install-swap.test.ts           OK      scripts/skills-inventory-parity.ts
OK      scripts/json-top-level-string.js       OK      scripts/skills-lint.ts
OK      scripts/materialize-release-subjects.sh OK     scripts/verify-delivery-evidence-pack.test.ts
OK      scripts/orca-bundle-parity.ts          OK      scripts/verify-delivery-evidence-pack.ts
OK      scripts/reconcile-channel-manifests.sh OK      scripts/verify-release.sh
OK      scripts/reconcile-release-assets.sh    OK      scripts/verify-release.test.ts
OK      scripts/reconcile-release-note.sh      OK      scripts/version.ts

34 referenced, 34 present, 0 missing. Every bun run <script> / npm run <script> name appearing in .github/workflows/** and .husky/** (build, check, check:fast, lint, lint:complexity-budget, lint:docs-links, lint:docs-markdown, lint:orca-bundle, skills:lint, typecheck, wishes:lint) still exists in package.json after the build:plugin / sync / build-and-sync removal.

This is now a permanent guard, not a one-off grep: workflow-yaml-parse.test.ts → "no workflow invokes a script deleted with the dogfood matrix" iterates every .yml under .github/workflows/ against the six deleted paths.

Importer sweep over the deleted basenames

build.js, sync.js, codex-dogfood-harness, codex-dogfood-entry-runner, validate-live-dogfood-evidence, validate-dogfood-matrix-evidence across src scripts tests .github package.json knip.json biome.json tsconfig.json .coderabbit.yaml install.sh:

Hit Class
codex-dogfood-harness, codex-dogfood-entry-runner zero hits
scripts/validate-live-dogfood-evidence.ts in src/lib/delivery-evidence-verify.ts:459 (a comment cross-reference) deleted-here — the dangling sentence removed in this PR
scripts/validate-dogfood-matrix-evidence.ts ×2 in release-docs.test.ts deleted-here — both assertions removed
scripts/build.js ×1 in version-format.test.ts deleted-here — the surviving mention is prose explaining the deletion
all sync.js hits (.genie-sync.json, roadmap-sync.js) survives — unrelated substring

Residual codex-dogfood-* strings in the workflow are the two artifact names codex-dogfood-candidate-matrix and codex-dogfood-previous-release, both still produced by prepare-delivery-evidence and both still downloaded by surviving jobs (stable-release-security-gate and release-update-path-smoke respectively). Not jobs, not deleted scripts.


Deliverable 8 — verified, not assumed

scripts/build-delivery-evidence.ts needs no edit. It is tree-level in both places the wish names:

117: function physicalTreeDigest(root: string): string {
118:   const stat = lstatSync(root);
119:   if (!stat.isDirectory() || stat.isSymbolicLink()) fail('plugins/genie must be a physical directory');
...
227:   canonicalPayloadSha256: physicalTreeDigest(join(extractionRoot, 'plugins', 'genie')),

It digests whatever plugins/genie contains and only requires the directory to be physical — both still true for the Orca-only tree. bun test scripts/build-delivery-evidence.test.ts green.

release-update-path-smoke is likewise tree-level — its payload steps are [[ -d "${stage}/plugins/genie" && ! -L ... ]], rm -rf -- "${GENIE_HOME}/plugins/genie", cp -R -- "${stage}/plugins/genie" "${GENIE_HOME}/plugins/genie". No manifest enumeration. Unchanged.

For the record, per the wish's grep note: release-publish.yml's real genie update --publish-local-delivery invocation is a single run; the neighbouring printf only echoes its exit status.


Deliverable 11 — version.yml is workflow_run, so its edit is inert on dev

.github/workflows/version.yml is triggered by workflow_run, and workflow_run workflows execute the DEFAULT-BRANCH copy. The edits to it in this PR (and the three-file JSON_FILES list G4/G5 landed) are therefore inert on dev until the rolling promotion PR merges to main — this is the 2026-07-11 downgrade lineage, wish Risk row "version.yml is workflow_run".

Its pre-merge evidence is consequently the two version test suites, both green here:

  • bun test scripts/version-format.test.ts — including the new --check coverage
  • bun test scripts/version-ci-staging.test.ts — synchronizeVersionFiles stages exactly package.json, plugins/genie/orca-plugin.json, plugins/genie/package.json under GITHUB_ACTIONS=true, nothing when unset, and fails the sync when git add fails

plus release-docs.test.ts's expect(workflow).toContain('expected exactly three version files').

Post-merge acceptance (cannot be proven pre-merge): the first [auto-version] bump after this branch's promotion to main must commit exactly those three files, and release-guard.sh check-version-child must accept that child. Recorded as post-promotion acceptance, not ticked on inference.


Group 6 acceptance criteria

  • C11 in full, every command run and its output pasted — above. Two substitutions recorded: release-guard.sh (unrunnable bare / fail-closed outside Actions → release-guard.test.ts, 39 pass) and bun run check → check:fast + targeted suites (host OOM rule; CI runs the full gate).
  • git grep -n "plugins/genie" -- src scripts .github package.json returns only Orca-owned lines. Non-empty by necessity, in the same three classes G3/G4/G5 recorded: (a) the Orca payload itself — orca-plugin.json, orca-entrypoint{,.min}, orca-runtime, plugin.json, references/orca-orchestration.md, the orca-plugin-ref.yml subtree republish, and the tarball/$GENIE_HOME staging of that tree; (b) the three version-file paths in version.ts / version.yml / release-guard.sh / release-payload-version.ts and their tests; (c) negative guards and retirement surfaces for host assets a previous Genie wrote (fresh-install-smoke.ts:118's forbidden-prefix list, legacy-integration-retirement.ts, skills-installer.ts's mirror commentary). No importer of a deleted payload.
  • git diff --exit-code origin/dev -- .github/workflows/musl-adapter-smoke.yml scripts/run-musl-dogfood.sh empty.
  • scripts/workflow-yaml-parse.test.ts passes and no job references a deleted script — 34/34 referenced paths present; the check is now a permanent test.
  • The candidate-dogfood-matrix.ts decision is recorded with the two consuming jobs named — KEEP; prepare-delivery-evidence and stable-release-security-gate.

Deviations

  1. Deliverables 1, 2, 3 (code) and 6 were already landed by G3/G4/G5 and are verified and recorded here rather than re-done, exactly as the dispatch brief anticipated. What G6 actually added on top: the two stale doc counts (CLAUDE.md "five version files" → three with the names; version.yml's header "all six changed fields"), which no earlier group's tests caught because both are prose.
  2. bun run check → check:fast + targeted suites. Host OOM rule (full bun test exits 137 on pre-existing Worker tests). CI runs the full gate on this push. scripts/reconcile-release-assets.test.ts skipped locally (pre-existing timeout); every other scripts/*.test.ts ran — 309 pass / 0 fail.
  3. bash scripts/release-guard.sh → bun test scripts/release-guard.test.ts. The literal command is a usage error (exit 64) and guard-trusted-release fail-closes outside Actions (exit 3); both outputs pasted above. Same substitution G5's review recorded.
  4. prepare-delivery-evidence's dogfood_matrix output was removed although the wish only named the two jobs and the one publish.needs edge. Its sole consumers were the deleted jobs, so it was dead workflow config; the JSON file it projected is untouched and still consumed. If a reviewer prefers strict minimality, restoring three lines (DOGFOOD_MATRIX=, the outputs: entry, the echo) is the alternative — no other job reads it either way.
  5. scripts/build.js's pluginPackageManifest generator was not rehomed. version-format.test.ts's "plugin package generator preserves reviewed MIT metadata" test asserted the committed plugins/genie/package.json equalled a generated manifest. With the generator deleted the test now asserts the committed file's shape directly (name, private, description, MIT license, type, empty dependencies, engines) and that it is exactly JSON.stringify(…, null, 2) + '\n'. Same protection — a hand edit that drops the license or adds a runtime dependency still fails — without resurrecting a build step.
  6. Four prose comments inside release-publish.yml that cross-referenced codex-native-dogfood (the Codex pin rationale, the AppArmor lift, the step-sequence provenance note, the slsa-verifier install note) were reworded rather than left dangling. workflow-yaml-parse.test.ts's pin test was rewritten: it asserted codexPins.length > 1 and workflowImages.toHaveLength(2) because the deleted matrix carried the second copy of each pin; it now asserts exactly one Codex pin and exactly one Alpine digest, still cross-checked against scripts/run-musl-dogfood.sh. A second, divergent pin reintroduced anywhere still fails.
  7. One src/ file touched — src/lib/delivery-evidence-verify.ts:459, deleting a comment's cross-reference to validate-live-dogfood-evidence.ts. Comment only; no behavior change, 9/9 tests green.

`scripts/build.js` compiled hook executables and regenerated
`plugins/genie/package.json`; both compile targets left with the hook runtime
and the plugin manifest is now a reviewed, committed Orca-payload file.
`scripts/sync.js` copied the plugin into `~/.claude/plugins/genie`, which no
longer exists. Their `build:plugin`, `sync` and `build-and-sync` npm scripts and
the `scripts/build.js` build-tarballs path filter go with them.

`scripts/version.ts` gains a read-only `--check` mode. The bare command read no
argv at all and always performed a real bump, so the three-file version set had
no runnable verification; `--check` reports the targets and their bump-readiness
and exits 0 without writing, and any other argv is rejected before any mutation.

CLAUDE.md's version-file sentence follows the set down to three.
Closes the G3 release freeze. `codex-native-dogfood` and its
`codex-dogfood-completeness` roll-up exercised `genie setup --codex`, the
activation-pending update terminal and the doctor integrationSummary — all
deleted in G3 — so both jobs were guaranteed red on every head carrying G3.
They leave together with `tests/support/codex-dogfood-{harness,harness.test,entry-runner}.ts`,
`scripts/validate-live-dogfood-evidence.ts` and
`scripts/validate-dogfood-matrix-evidence.ts` (with their tests): 3,889 lines.

`publish.needs` drops exactly one edge, `codex-dogfood-completeness`, with its
matching if-guard; `admit`, `attest-delivery-evidence`,
`delivery-evidence-compatibility`, `skills-install-smoke`,
`release-update-path-smoke` and `stable-release-security-gate` all remain with
their guards byte-intact, and `release-update-path-smoke` keeps depending on
`genie update --publish-local-delivery`.

`scripts/candidate-dogfood-matrix.ts` is KEPT: `prepare-delivery-evidence`
derives the platform inventory and the update-path projection from it, and
`stable-release-security-gate` — itself a `publish.needs` edge — re-derives and
`cmp`s it. Only the `dogfood_matrix` job output, whose sole consumer was the
deleted matrix, goes with them; the JSON artifact it projected is still built,
uploaded and consumed.

`scripts/run-musl-dogfood.sh` and `.github/workflows/musl-adapter-smoke.yml` are
byte-unchanged against origin/dev.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-01T00:34:08.282270Z 9897597 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9897597f99

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/version.ts
Comment on lines +193 to +198
if (argv.length > 0) {
if (argv.length === 1 && argv[0] === '--check') {
await runCheck(rootDir);
return;
}
throw new Error(`usage: bun scripts/version.ts [--check] (got: ${argv.join(' ')})`);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Exercise the --check CLI boundary in tests

The added tests invoke versionCheckReport() directly, so they cannot catch regressions in this argument dispatch or the main().catch path: for example, an unknown flag or malformed target could accidentally exit successfully, omit the required stderr diagnostic, or fall through to the mutating bare command while these tests remain green. Add subprocess-level coverage for successful --check, error exit code and stderr, and repeated read-only execution, as required for every new CLI surface.

AGENTS.md reference: AGENTS.md:L32-L32

Useful? React with 👍 / 👎.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: ce6bd276-b11f-45db-acf8-36701cc4f4be

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@namastex888
namastex888 merged commit 9772243 into wish/skills-everywhere-b Sep 1, 2026
11 checks passed
@automagik-genie
automagik-genie deleted the wish/skills-everywhere-b-g6 branch September 25, 2026 04:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant