chore(release): group 6 — toolchain, version --check, and the codex dogfood matrix deletion - #2883
Conversation
`scripts/build.js` compiled hook executables and regenerated `plugins/genie/package.json`; both compile targets left with the hook runtime and the plugin manifest is now a reviewed, committed Orca-payload file. `scripts/sync.js` copied the plugin into `~/.claude/plugins/genie`, which no longer exists. Their `build:plugin`, `sync` and `build-and-sync` npm scripts and the `scripts/build.js` build-tarballs path filter go with them. `scripts/version.ts` gains a read-only `--check` mode. The bare command read no argv at all and always performed a real bump, so the three-file version set had no runnable verification; `--check` reports the targets and their bump-readiness and exits 0 without writing, and any other argv is rejected before any mutation. CLAUDE.md's version-file sentence follows the set down to three.
Closes the G3 release freeze. `codex-native-dogfood` and its
`codex-dogfood-completeness` roll-up exercised `genie setup --codex`, the
activation-pending update terminal and the doctor integrationSummary — all
deleted in G3 — so both jobs were guaranteed red on every head carrying G3.
They leave together with `tests/support/codex-dogfood-{harness,harness.test,entry-runner}.ts`,
`scripts/validate-live-dogfood-evidence.ts` and
`scripts/validate-dogfood-matrix-evidence.ts` (with their tests): 3,889 lines.
`publish.needs` drops exactly one edge, `codex-dogfood-completeness`, with its
matching if-guard; `admit`, `attest-delivery-evidence`,
`delivery-evidence-compatibility`, `skills-install-smoke`,
`release-update-path-smoke` and `stable-release-security-gate` all remain with
their guards byte-intact, and `release-update-path-smoke` keeps depending on
`genie update --publish-local-delivery`.
`scripts/candidate-dogfood-matrix.ts` is KEPT: `prepare-delivery-evidence`
derives the platform inventory and the update-path projection from it, and
`stable-release-security-gate` — itself a `publish.needs` edge — re-derives and
`cmp`s it. Only the `dogfood_matrix` job output, whose sole consumer was the
deleted matrix, goes with them; the JSON artifact it projected is still built,
uploaded and consumed.
`scripts/run-musl-dogfood.sh` and `.github/workflows/musl-adapter-smoke.yml` are
byte-unchanged against origin/dev.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9897597f99
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if (argv.length > 0) { | ||
| if (argv.length === 1 && argv[0] === '--check') { | ||
| await runCheck(rootDir); | ||
| return; | ||
| } | ||
| throw new Error(`usage: bun scripts/version.ts [--check] (got: ${argv.join(' ')})`); |
There was a problem hiding this comment.
Exercise the --check CLI boundary in tests
The added tests invoke versionCheckReport() directly, so they cannot catch regressions in this argument dispatch or the main().catch path: for example, an unknown flag or malformed target could accidentally exit successfully, omit the required stderr diagnostic, or fall through to the mutating bare command while these tests remain green. Add subprocess-level coverage for successful --check, error exit code and stderr, and repeated read-only execution, as required for every new CLI surface.
AGENTS.md reference: AGENTS.md:L32-L32
Useful? React with 👍 / 👎.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Group 6 of wish
skills-everywhere-b: the build/release toolchain and the release workflow (criterion C11). This is the one group whose failures never surface inbun run check, so every C11 command was run and its output is pasted below.This commit closes the G3 release freeze.
codex-native-dogfoodand itscodex-dogfood-completenessroll-up were guaranteed red on every head carrying G3 (they require exit 2 /activation-pendingfromupdate --publish-local-deliveryand asetup --codexrun matching/Activated Codex plugin/, all deleted in G3). Both jobs and theirpublish.needsedge are gone, sowish/skills-everywhere-bis releasable again.3 commits, 19 files, +256 / −4,482.
Deliverable status
build-binary.shstages only the Orca tree +skills/; marketplace staging, the required-file loop beyond the two Orca entries, the per-skill mirror assertions,--plugin-rootandverify-codex-activation-payload.tsall gonebuild-binary.shgreen, tarball top level = exactlyINSTALL_PAYLOAD_MEMBERS,plugins/genie= Orca only). No edit needed.release-payload-version.tsreduced to the three files;verifyCodexMarketplaceEntry+ both call sites gone;.claude-plugin/.agentsstamping gone;--verify-sourcestill worksTOP_LEVEL_VERSION_FILES=plugins/genie/{package.json,orca-plugin.json},COMMITTED_VERSION_FILES=package.json+plugins/genie/package.json. Verified below.version.ts,version.yml,release-guard.sh; the version-file-count error message andrelease-docs.test.tsfollow;CLAUDE.mdsentenceversion.ymlsaysexpected exactly three version files;release-guard.shlists two required + one conditional). CLAUDE.md's stale "still five version files" fixed here, plusversion.yml's stale "all six changed fields" header.scripts/version.ts --checkread-only modescripts/build.js+scripts/sync.jswithbuild:plugin/build-and-sync/syncscripts/build.jsbuild-tarballs.ymlpath filter and itsrelease-docs.test.tsliteral).fresh-install-smoke.tsloses the whole plugin-layout half, derives its inventory fromskills/*/SKILL.md, keeps the negative source-path assertion extended to$GENIE_HOME/plugins/genie/skills--plugin-root,listSkillNames()readsskills/*/SKILL.md, and:118forbids the prefix$GENIE_HOME/plugins/genie, which subsumes.../skills. No edit needed.codex-native-dogfood+codex-dogfood-completenessand exactly onepublish.needsedge; delete the harness, entry-runner and both validators; decide oncandidate-dogfood-matrix.tsbuild-delivery-evidence.tsandrelease-update-path-smokeare tree-levelrun-musl-dogfood.sh+musl-adapter-smoke.ymlbyte-unchangedversion-format.test.ts,release-docs.test.ts,workflow-yaml-parse.test.ts.version.ymlisworkflow_runC11 — every command, with output
bun scripts/release-payload-version.ts --verify-source .bash scripts/build-binary.sh --platform linux-x64-glibcThe four-platform CI matrix (
build-tarballs.yml) is the rest of C11's "green on all four platforms"; onlylinux-x64-glibcis runnable on this host.Payload layout re-proof (the G3
INSTALL_PAYLOAD_MEMBERSlesson).tar -tzftop level over the freshly built tarball, and theplugins/geniecontents:Exact match, and
plugins/genieis the Orca tree only — deliverable 1 confirmed complete on entry.bun test scripts/install-swap.test.tsgreen (in batch 2 below).bash scripts/release-guard.sh— substituted, recordedThe literal command in the wish's validation block is not runnable and never was:
The script has no default subcommand (
:504*) misuse "unknown subcommand"), and its only workflow invocation (release.yml:116 guard-trusted-release) fail-closes outside Actions by design. The proof is therefore its test suite — the same substitution G5's review recorded:release-guard.sh's version list is already the reduced set (:161-172):package.json+plugins/genie/package.jsonrequired,plugins/genie/orca-plugin.jsonaccepted when it moved.bun scripts/fresh-install-smoke.ts25 = the post-#2870 inventory, derived from
skills/*/SKILL.md. Also run three more times insidebuild-binary.sh(source, staged payload, extracted payload).bun scripts/version.ts --check— the new modeExits 0 and names only the three files C11 requires. The mode is read-only by construction: it calls
assertVersionFileShape(which parses and dry-runs the token replacement, writing nothing) and never callsgenerateVersion(). Argument handling now runs before any mutation and rejects anything that is not exactly--check, so a typo can never degrade into the irreversible bare bump. Two new unit tests cover the happy path (byte-identical files before/after) and the failure path (a malformed and a missing target reported, not rewritten).bun test scripts/version-format.test.ts scripts/version-ci-staging.test.ts scripts/release-docs.test.tsRun as part of the full
scripts/batch:309 pass / 0 fail across every
scripts/*.test.tsexceptscripts/reconcile-release-assets.test.ts, which times out locally (pre-existing, recorded in the wave handoff). CI runs it.bun test src/lib/delivery-evidence-verify.test.ts— 9 pass (the onesrc/file touched, a comment only).bun run check— substituted bycheck:fastPer the host OOM rule the full
bun teststep is left to CI.check:fastran green as the pre-push hook on every push:C7 — the release-workflow proof
Neither job exists, and nothing needs them
Parsed as YAML rather than grepped, the full job DAG is now:
publish.needs— six edges, each with itsif:guardExactly one edge left (
codex-dogfood-completeness) with exactly its own guard line; the other six edges and their six guard lines are byte-intact:release-update-path-smokestill depends ongenie update --publish-local-delivery(asserted byworkflow-yaml-parse.test.ts:expect(smoke).toContain('update --publish-local-delivery'), plus.code == "delivery-verified"and.deliveryComplete == true).stable-release-security-gatestill consumesscripts/candidate-dogfood-matrix.ts.Both facts are now pinned by new tests rather than left to review:
workflow-yaml-parse.test.ts→ "publish requires exactly the six surviving gates, each with its if-guard" (asserts the edge list withtoEqual, then loops the guard for each).workflow-yaml-parse.test.ts→ "the Codex dogfood matrix is gone and nothing needs it" (loops every job'sneeds).release-docs.test.ts→ the six-gate loop plusexpect(publish.split('\n').filter(isEdgeLine)).toHaveLength(6).git diff --exit-code origin/dev -- .github/workflows/musl-adapter-smoke.yml scripts/run-musl-dogfood.shMUSL DIFF EMPTY (exit 0).scripts/run-musl-dogfood.test.tsgreen.The
candidate-dogfood-matrix.tsdecision — KEEP, both consumers namedscripts/candidate-dogfood-matrix.tsis kept, and only its dogfood-matrix consumers were deleted. The wish's alternative — reworking the two surviving consumer jobs — was rejected.The two consuming jobs, by name:
prepare-delivery-evidence(release-publish.yml, theGenerate retry-stable candidate manifests and descriptorsstep). It derives the entire platform inventory from it:bun scripts/candidate-dogfood-matrix.ts --manifest "$SELECTED_MANIFEST" --artifact-dir dist --output candidate-dogfood-matrix.jsonmapfile -t MANIFEST_PLATFORMS < <(jq -er '.include[].platform' candidate-dogfood-matrix.json)— the loop that builds every delivery descriptor and every previous-stable downloadUPDATE_PATH_MATRIXis ajqprojection of the same file, andrelease-update-path-smoke's whole strategy matrix is that projectionstable-release-security-gate— itself apublish.needsedge. It re-derives the matrix from the downloaded manifest with independent release controls andcmps it against the artifactprepare-delivery-evidenceuploaded:bun scripts/candidate-dogfood-matrix.ts --manifest "$MANIFEST" --artifact-dir security-gate/dist --output security-gate/rederived-matrix.jsoncmp -- security-gate/candidate-dogfood-matrix.json security-gate/rederived-matrix.jsonrederived-matrix.json, andscripts/candidate-dogfood-matrix.test.tsis one of the eight suites it runs in-jobWhy keep. The script's name is historical; its job is "derive the admitted platform inventory from the selected manifest", which is now load-bearing for a
publish.needsgate and for the update-path smoke's platform coverage. Deleting it would force rewriting the security gate's independent re-derivation — the single strongest anti-tamper control in the release — as part of a deletion PR.release-docs.test.ts:288andworkflow-yaml-parse.test.ts:162therefore keep asserting it, and a newworkflow-yaml-parse.test.tstest ("candidate-dogfood-matrix.ts survives with both of its consuming jobs") pins both consumers so a later "it was only for the dogfood" cleanup fails loudly.The one thing that did leave with the matrix:
prepare-delivery-evidence'sdogfood_matrixjob output (and theDOGFOOD_MATRIXshell variable feeding it). Its only consumers werecodex-native-dogfood'sstrategy.matrixandcodex-dogfood-completeness'sEXPECTED_MATRIX; with both jobs gone it was dead workflow config. Thecandidate-dogfood-matrix.jsonfile it projected is still built, still uploaded ascodex-dogfood-candidate-matrix, and still downloaded bystable-release-security-gate. Recorded as a deviation below since the wish did not name it.No workflow references a deleted script
Every
scripts/…andtests/support/…path appearing anywhere under.github/workflows/, checked for existence on this head:34 referenced, 34 present, 0 missing. Every
bun run <script>/npm run <script>name appearing in.github/workflows/**and.husky/**(build,check,check:fast,lint,lint:complexity-budget,lint:docs-links,lint:docs-markdown,lint:orca-bundle,skills:lint,typecheck,wishes:lint) still exists inpackage.jsonafter thebuild:plugin/sync/build-and-syncremoval.This is now a permanent guard, not a one-off grep:
workflow-yaml-parse.test.ts→ "no workflow invokes a script deleted with the dogfood matrix" iterates every.ymlunder.github/workflows/against the six deleted paths.Importer sweep over the deleted basenames
build.js,sync.js,codex-dogfood-harness,codex-dogfood-entry-runner,validate-live-dogfood-evidence,validate-dogfood-matrix-evidenceacrosssrc scripts tests .github package.json knip.json biome.json tsconfig.json .coderabbit.yaml install.sh:codex-dogfood-harness,codex-dogfood-entry-runnerscripts/validate-live-dogfood-evidence.tsinsrc/lib/delivery-evidence-verify.ts:459(a comment cross-reference)scripts/validate-dogfood-matrix-evidence.ts×2 inrelease-docs.test.tsscripts/build.js×1 inversion-format.test.tssync.jshits (.genie-sync.json,roadmap-sync.js)Residual
codex-dogfood-*strings in the workflow are the two artifact namescodex-dogfood-candidate-matrixandcodex-dogfood-previous-release, both still produced byprepare-delivery-evidenceand both still downloaded by surviving jobs (stable-release-security-gateandrelease-update-path-smokerespectively). Not jobs, not deleted scripts.Deliverable 8 — verified, not assumed
scripts/build-delivery-evidence.tsneeds no edit. It is tree-level in both places the wish names:It digests whatever
plugins/geniecontains and only requires the directory to be physical — both still true for the Orca-only tree.bun test scripts/build-delivery-evidence.test.tsgreen.release-update-path-smokeis likewise tree-level — its payload steps are[[ -d "${stage}/plugins/genie" && ! -L ... ]],rm -rf -- "${GENIE_HOME}/plugins/genie",cp -R -- "${stage}/plugins/genie" "${GENIE_HOME}/plugins/genie". No manifest enumeration. Unchanged.For the record, per the wish's grep note:
release-publish.yml's realgenie update --publish-local-deliveryinvocation is a single run; the neighbouringprintfonly echoes its exit status.Deliverable 11 —
version.ymlisworkflow_run, so its edit is inert ondev.github/workflows/version.ymlis triggered byworkflow_run, andworkflow_runworkflows execute the DEFAULT-BRANCH copy. The edits to it in this PR (and the three-fileJSON_FILESlist G4/G5 landed) are therefore inert ondevuntil the rolling promotion PR merges tomain— this is the 2026-07-11 downgrade lineage, wish Risk row "version.yml isworkflow_run".Its pre-merge evidence is consequently the two version test suites, both green here:
bun test scripts/version-format.test.ts— including the new--checkcoveragebun test scripts/version-ci-staging.test.ts—synchronizeVersionFilesstages exactlypackage.json,plugins/genie/orca-plugin.json,plugins/genie/package.jsonunderGITHUB_ACTIONS=true, nothing when unset, and fails the sync whengit addfailsplus
release-docs.test.ts'sexpect(workflow).toContain('expected exactly three version files').Post-merge acceptance (cannot be proven pre-merge): the first
[auto-version]bump after this branch's promotion tomainmust commit exactly those three files, andrelease-guard.sh check-version-childmust accept that child. Recorded as post-promotion acceptance, not ticked on inference.Group 6 acceptance criteria
release-guard.sh(unrunnable bare / fail-closed outside Actions →release-guard.test.ts, 39 pass) andbun run check→check:fast+ targeted suites (host OOM rule; CI runs the full gate).git grep -n "plugins/genie" -- src scripts .github package.jsonreturns only Orca-owned lines. Non-empty by necessity, in the same three classes G3/G4/G5 recorded: (a) the Orca payload itself —orca-plugin.json,orca-entrypoint{,.min},orca-runtime,plugin.json,references/orca-orchestration.md, theorca-plugin-ref.ymlsubtree republish, and the tarball/$GENIE_HOMEstaging of that tree; (b) the three version-file paths inversion.ts/version.yml/release-guard.sh/release-payload-version.tsand their tests; (c) negative guards and retirement surfaces for host assets a previous Genie wrote (fresh-install-smoke.ts:118's forbidden-prefix list,legacy-integration-retirement.ts,skills-installer.ts's mirror commentary). No importer of a deleted payload.git diff --exit-code origin/dev -- .github/workflows/musl-adapter-smoke.yml scripts/run-musl-dogfood.shempty.scripts/workflow-yaml-parse.test.tspasses and no job references a deleted script — 34/34 referenced paths present; the check is now a permanent test.candidate-dogfood-matrix.tsdecision is recorded with the two consuming jobs named — KEEP;prepare-delivery-evidenceandstable-release-security-gate.Deviations
CLAUDE.md"five version files" → three with the names;version.yml's header "all six changed fields"), which no earlier group's tests caught because both are prose.bun run check→check:fast+ targeted suites. Host OOM rule (fullbun testexits 137 on pre-existingWorkertests). CI runs the full gate on this push.scripts/reconcile-release-assets.test.tsskipped locally (pre-existing timeout); every otherscripts/*.test.tsran — 309 pass / 0 fail.bash scripts/release-guard.sh→bun test scripts/release-guard.test.ts. The literal command is a usage error (exit 64) andguard-trusted-releasefail-closes outside Actions (exit 3); both outputs pasted above. Same substitution G5's review recorded.prepare-delivery-evidence'sdogfood_matrixoutput was removed although the wish only named the two jobs and the onepublish.needsedge. Its sole consumers were the deleted jobs, so it was dead workflow config; the JSON file it projected is untouched and still consumed. If a reviewer prefers strict minimality, restoring three lines (DOGFOOD_MATRIX=, theoutputs:entry, theecho) is the alternative — no other job reads it either way.scripts/build.js'spluginPackageManifestgenerator was not rehomed.version-format.test.ts's "plugin package generator preserves reviewed MIT metadata" test asserted the committedplugins/genie/package.jsonequalled a generated manifest. With the generator deleted the test now asserts the committed file's shape directly (name,private, description, MIT license,type, emptydependencies, engines) and that it is exactlyJSON.stringify(…, null, 2) + '\n'. Same protection — a hand edit that drops the license or adds a runtime dependency still fails — without resurrecting a build step.release-publish.ymlthat cross-referencedcodex-native-dogfood(the Codex pin rationale, the AppArmor lift, the step-sequence provenance note, the slsa-verifier install note) were reworded rather than left dangling.workflow-yaml-parse.test.ts's pin test was rewritten: it assertedcodexPins.length > 1andworkflowImages.toHaveLength(2)because the deleted matrix carried the second copy of each pin; it now asserts exactly one Codex pin and exactly one Alpine digest, still cross-checked againstscripts/run-musl-dogfood.sh. A second, divergent pin reintroduced anywhere still fails.src/file touched —src/lib/delivery-evidence-verify.ts:459, deleting a comment's cross-reference tovalidate-live-dogfood-evidence.ts. Comment only; no behavior change, 9/9 tests green.