fix: harden transactional test-deployment rebuild - #333
Conversation
📝 WalkthroughWalkthroughThe PR adds a transactional rebuild/deploy plan and design specification, strengthens PowerShell path, lock, checkout, environment, and cutover handling, and adds extensive tests for staged preparation, fail-closed behavior, reparse-point safety, lock contention, and cleanup. ChangesTransactional rebuild and deploy
Estimated code review effort: 4 (Complex) | ~60 minutes Sequence Diagram(s)sequenceDiagram
participant InvokeTestDeployRebuild
participant Git
participant EnvSnapshot
participant ServiceStopper
participant Filesystem
InvokeTestDeployRebuild->>Git: clone and validate staged checkout
InvokeTestDeployRebuild->>EnvSnapshot: restore preserved environment files
InvokeTestDeployRebuild->>ServiceStopper: stop deployment-zone services
InvokeTestDeployRebuild->>Filesystem: perform directory cutover
Filesystem-->>InvokeTestDeployRebuild: return cutover or rollback result
Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Warning Tools execution failed with the following error: Failed to run tools: 13 INTERNAL: Received RST_STREAM with code 2 (Internal server error) Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
This PR hardens the test-deployment rebuild helper to reduce the chance of unsafe filesystem mutation by adding fail-closed path safety checks, a same-parent exclusive rebuild lock, and staged replacement behavior for non-git / broken-gitfile deployments, alongside expanded PowerShell integration fixtures and accompanying design/plan documentation.
Changes:
- Add
Assert-TestDeployPathSafety,Enter-TestDeployRebuildLock, and broken-gitfile detection; wire them intoInvoke-TestDeployRebuildwith staged replacement + service-stop aggregation. - Strengthen env snapshot restore by verifying written bytes match the preserved snapshot (and removing the
.exampledependency). - Add extensive RED fixtures in
scripts/tests/test-rebuild-test-deploy.ps1plus new transactional design and implementation plan docs.
Reviewed changes
Copilot reviewed 3 out of 4 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| scripts/tests/test-rebuild-test-deploy.ps1 | Adds transactional + path/reparse/lock RED fixtures and safety teardown assertions. |
| scripts/lib/rebuild-test-deploy.ps1 | Implements path safety validation, exclusive rebuild lock, broken gitfile detection, staged replacement orchestration, and stricter env restore verification. |
| docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md | Documents the transactional rebuild/worktree E2E design, constraints, and verification contract. |
| docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md | Adds a task-based implementation plan with constraints, evidence expectations, and verification layers. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| $deployLeaf = Split-Path -Leaf $deployRoot | ||
| $lockPath = Normalize-TestDeployPath -Path (Join-Path $deployParent ".$deployLeaf.rebuild.lock") | ||
| $handle = $null | ||
| try { | ||
| $handle = [System.IO.File]::Open( | ||
| $lockPath, | ||
| [System.IO.FileMode]::OpenOrCreate, | ||
| [System.IO.FileAccess]::ReadWrite, | ||
| [System.IO.FileShare]::None | ||
| ) | ||
| } catch [System.IO.IOException] { | ||
| $lowCode = [int]$_.Exception.HResult -band 0xFFFF | ||
| if ($lowCode -in @(32, 33)) { | ||
| throw "test deploy rebuild already in progress for '$deployRoot'" | ||
| } | ||
| throw "failed to acquire test deploy rebuild lock '$lockPath': $($_.Exception.Message)" | ||
| } |
| } catch { | ||
| $stageError = $_ | ||
| if (Test-Path -LiteralPath $stageRoot) { | ||
| Remove-Item -LiteralPath $stageRoot -Recurse -Force -ErrorAction SilentlyContinue | ||
| } | ||
| throw $stageError | ||
| } |
There was a problem hiding this comment.
Actionable comments posted: 4
🧹 Nitpick comments (2)
docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md (1)
64-69: 🗄️ Data Integrity & Integration | 🔵 Trivial | ⚡ Quick winDefine one canonical CurrentWorktree diff command.
The design’s
git diffcommand differs from the plan’s command at Line 143: it omits--no-ext-diffand--ita-visible-in-index. Align both documents and the implementation to one exact command, or explicitly document why the flags differ; otherwise source bytes and provenance can vary for the same worktree.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md` around lines 64 - 69, The worktree materialization flow and the plan must use one canonical CurrentWorktree git diff command. Update the documented command near the source-change steps and the corresponding implementation to match the plan’s exact flags, including --no-ext-diff and --ita-visible-in-index, or explicitly document a justified difference; preserve matching source bytes and manifest provenance for the same worktree.scripts/lib/rebuild-test-deploy.ps1 (1)
543-544: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winPrefer structured logging over bare
Write-Hostin the new staged path.The new staged-rebuild block introduces several
Write-Hostcalls (also at Lines 560, 595, 624, 634). Per repo convention these should route throughscripts/lib/StructLog.psm1rather than bareWrite-Host. The rest of this file predates the rule, so aligning at least the new lines keeps the staged transaction observable in the structured stream.As per coding guidelines: "Use
scripts/lib/StructLog.psm1for structured logging output; do not replace with bareWrite-Hostcalls".🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/lib/rebuild-test-deploy.ps1` around lines 543 - 544, Replace the new staged-rebuild Write-Host calls, including those near the staged checkout discard and the referenced later lines, with the structured logging functions provided by StructLog.psm1. Preserve each message and relevant values while routing output through the established structured logging interface; leave pre-existing Write-Host calls outside the staged path unchanged.Source: Coding guidelines
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md`:
- Around line 291-309: Do not present the frontend E2E runner as implemented. In
docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md:291-309,
rewrite Step 5 and the result-layer requirements in future tense while retaining
the unchecked status; in
docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md:143-175,
label the contract as proposed rather than current capability. Preserve the
stated wrapper, dependency bootstrap, and current-run evidence gate
requirements.
- Around line 111-170: Update the Task 2 checklist to reflect the existing
implementation in scripts/lib/rebuild-test-deploy.ps1: mark the staged
preparation, standalone checkout validation, environment restoration,
service-stop handling, and rename cutover slices complete where implemented, and
split any incomplete requirements into explicit unchecked gaps. Preserve the
remaining validation and test-gate items as unchecked unless the implementation
already satisfies them.
- Around line 1-3: Classify the plan document as a “working note” and reference
docs/AGENTS.md for agent-documentation rules. Also update
docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md
at lines 1-3 to classify it as “spec design,” reference docs/AGENTS.md, and
state that the implementation remains the runtime source of truth.
In
`@docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md`:
- Line 7: 將第 7 行的目前行為描述標示為 implementation gap 或 historical
evidence,而非執行時真相;同時引用實際實作 helper 的相關
script,明確說明該段內容是待程式碼驗證的證據。保留原有問題清單,但避免將設計文件本身視為權威行為來源。
---
Nitpick comments:
In
`@docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md`:
- Around line 64-69: The worktree materialization flow and the plan must use one
canonical CurrentWorktree git diff command. Update the documented command near
the source-change steps and the corresponding implementation to match the plan’s
exact flags, including --no-ext-diff and --ita-visible-in-index, or explicitly
document a justified difference; preserve matching source bytes and manifest
provenance for the same worktree.
In `@scripts/lib/rebuild-test-deploy.ps1`:
- Around line 543-544: Replace the new staged-rebuild Write-Host calls,
including those near the staged checkout discard and the referenced later lines,
with the structured logging functions provided by StructLog.psm1. Preserve each
message and relevant values while routing output through the established
structured logging interface; leave pre-existing Write-Host calls outside the
staged path unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: dd3eb22e-6027-41d3-9033-e7e4d3f7769b
📒 Files selected for processing (4)
docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.mddocs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.mdscripts/lib/rebuild-test-deploy.ps1scripts/tests/test-rebuild-test-deploy.ps1
| # 交易式測試部署重建與 Worktree 前端 E2E Implementation Plan | ||
|
|
||
| > **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development or superpowers:executing-plans task-by-task. Every worker/reviewer must return Scope, Evidence, Finding, Uncertainty, Risk, Next step. |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟠 Major | ⚡ Quick win
Declare the document nature and source-of-truth boundary.
Both documents need explicit classification and must separate agent instructions from runtime/product claims.
docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md#L1-L3: mark this as aworking noteand referencedocs/AGENTS.mdfor agent-documentation rules.docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md#L1-L3: mark this asspec design, referencedocs/AGENTS.md, and state that implementation remains the runtime truth.
📍 Affects 2 files
docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md#L1-L3(this comment)docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md#L1-L3
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md`
around lines 1 - 3, Classify the plan document as a “working note” and reference
docs/AGENTS.md for agent-documentation rules. Also update
docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md
at lines 1-3 to classify it as “spec design,” reference docs/AGENTS.md, and
state that the implementation remains the runtime source of truth.
Source: Coding guidelines
| ### Task 2: GREEN transaction orchestrator | ||
|
|
||
| **Files:** | ||
| - Modify: `scripts/lib/rebuild-test-deploy.ps1` | ||
| - Modify: `scripts/dev/rebuild-test-deploy.ps1` | ||
| - Optionally create: `scripts/lib/test-deploy-transaction.ps1` only if keeping the existing library reviewable requires a narrow separation | ||
|
|
||
| - [ ] **Step 1: Implement path safety and run layout** | ||
|
|
||
| Add narrow helpers equivalent to: | ||
|
|
||
| - `Assert-TestDeployPathSafety` | ||
| - `New-TestDeployRunLayout` | ||
| - `Enter-TestDeployRebuildLock` | ||
| - `Get-TestDeployCheckoutState` | ||
|
|
||
| Walk all existing path components; any reparse point fails. Lock uses `FileShare.None` and remains as a stable lock file. Return stage/previous/run/env/provenance paths on the same volume. | ||
|
|
||
| - [ ] **Step 2: Implement external env backup** | ||
|
|
||
| Backup allowlisted files before live mutation; record length/SHA256/ACL hash without value. Restore into stage regardless of `.example` existence and verify bytes/hash. Redact origin URLs in command display/errors. | ||
|
|
||
| - [ ] **Step 3: Implement OriginMain stage** | ||
|
|
||
| Use explicit refspec, detached exact commit, standalone `.git` directory, expected origin hash and required-script validation. Do not mutate live checkout. | ||
|
|
||
| - [ ] **Step 4: Implement CurrentWorktree stage** | ||
|
|
||
| Capture: | ||
|
|
||
| ```text | ||
| HEAD | ||
| + git diff HEAD --binary --full-index --no-ext-diff --ita-visible-in-index | ||
| + git ls-files --others --exclude-standard -z | ||
| ``` | ||
|
|
||
| Reject sensitive/tooling/cache/reparse/path-escape entries. Copy leaf files and verify hashes. Re-fingerprint source before cutover. | ||
|
|
||
| - [ ] **Step 5: Implement two-rename cutover** | ||
|
|
||
| Order: prepare/validate stage -> verified service stop -> repeat path safety -> `live -> previous` -> `stage -> live` -> deploy. Only pre-deploy rename failure auto-restores old live. Post-deploy failure returns recovery metadata without claiming external side-effect rollback. | ||
|
|
||
| - [ ] **Step 6: Preserve compatible result fields and expose logs** | ||
|
|
||
| Keep `DeploymentPath`, `OriginMainCommit`, `DeployExitCode`; add source mode/commit/patch/untracked hashes, checkout kind, provenance/previous/env backup paths, stdout/stderr paths, recovery status. | ||
|
|
||
| - [ ] **Step 7: Wire wrapper flags** | ||
|
|
||
| ```powershell | ||
| .\scripts\dev\rebuild-test-deploy.ps1 -Build | ||
| .\scripts\dev\rebuild-test-deploy.ps1 -Build -SourceMode CurrentWorktree | ||
| ``` | ||
|
|
||
| No `-DryRun` or implicit dirty mode. Print no secret values. | ||
|
|
||
| - [ ] **Step 8: Run GREEN transaction gate** | ||
|
|
||
| ```powershell | ||
| pwsh -NoProfile -File scripts/tests/test-rebuild-test-deploy.ps1 | ||
| ``` |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Synchronize the task checklist with the implemented transaction path.
Task 2 is entirely unchecked, although the supplied scripts/lib/rebuild-test-deploy.ps1 implementation already contains staged preparation, standalone-checkout validation, environment restoration, service-stop handling, and rename cutover. Mark completed slices accurately or split remaining work into explicit gaps; otherwise this plan misstates the implementation status.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md`
around lines 111 - 170, Update the Task 2 checklist to reflect the existing
implementation in scripts/lib/rebuild-test-deploy.ps1: mark the staged
preparation, standalone checkout validation, environment restoration,
service-stop handling, and rename cutover slices complete where implemented, and
split any incomplete requirements into explicit unchecked gaps. Preserve the
remaining validation and test-gate items as unchecked unless the implementation
already satisfies them.
| - [ ] **Step 5: Implement one-click wrapper** | ||
|
|
||
| ```powershell | ||
| .\scripts\dev\rebuild-worktree-e2e.ps1 -Build | ||
| ``` | ||
|
|
||
| It calls `CurrentWorktree` rebuild in a child process/library-safe path, verifies source provenance, seeds fixture, bootstraps dependencies, runs live shell smoke + strict real IFC functional slice, and optionally strict conversion/Kit visual layers. It writes a run-specific manifest and returns nonzero on any required layer. | ||
|
|
||
| - [ ] **Step 6: Define honest result layers** | ||
|
|
||
| Record separately: | ||
|
|
||
| - `shell_smoke_passed` | ||
| - `real_ifc_intake_ready` | ||
| - `conversion_ready_observed` | ||
| - `governance_semantic_observed` | ||
| - `kit_webrtc_visual_observed` | ||
|
|
||
| Only the first two are the minimum worktree frontend E2E gate. Full-system claim requires governance semantic + Kit visual; skipped/not-observed never counts as passed. |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Do not present the frontend E2E runner as implemented yet.
The PR objectives state that browser E2E remains an unchecked future item, but these sections describe a working one-click runner and successful evidence contract. Mark this as planned/unimplemented until the wrapper, dependency bootstrap, and current-run evidence gate exist.
docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md#L291-L309: use future-tense requirements and retain the unchecked status.docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md#L143-L175: label the section as a proposed contract, not current capability.
📍 Affects 2 files
docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md#L291-L309(this comment)docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md#L143-L175
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md`
around lines 291 - 309, Do not present the frontend E2E runner as implemented.
In
docs/superpowers/plans/2026-07-10-transactional-test-deploy-worktree-e2e.md:291-309,
rewrite Step 5 and the result-layer requirements in future tense while retaining
the unchecked status; in
docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md:143-175,
label the contract as proposed rather than current capability. Preserve the
stated wrapper, dependency bootstrap, and current-run evidence gate
requirements.
|
|
||
| 讓 agent 能從 dedicated worktree 安全地重建固定測試部署區 `D:\Users\deploy\AI-bim-geo`,並完成可追溯的前端 E2E;同時保留既有正式驗收口令 `rebuild-test-deploy.ps1 -Build` 的 `origin/main` 語意。 | ||
|
|
||
| 本設計修正的核心問題是:目前 helper 會在目的地原地 reset/clean、只以 `.git` 是否存在判斷 checkout、只信任數字 PID、健康檢查只看 HTTP 2xx,且 Playwright fixture/依賴/證據不足時可能以 `blocked` 結束。這些行為可造成機密環境檔遺失、錯停 PID、舊 runtime 假通過、或 fresh checkout 舊圖假裝成新證據。 |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Label the current-behavior claim as evidence, not runtime truth.
Line 7 asserts what the helper “currently” does without identifying the implementation source or marking the statement as an implementation gap/historical evidence. Add that boundary and point to the relevant script; the docs rules prohibit treating this document as authoritative program behavior.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In
`@docs/superpowers/specs/2026-07-10-transactional-test-deploy-worktree-e2e-design.md`
at line 7, 將第 7 行的目前行為描述標示為 implementation gap 或 historical
evidence,而非執行時真相;同時引用實際實作 helper 的相關
script,明確說明該段內容是待程式碼驗證的證據。保留原有問題清單,但避免將設計文件本身視為權威行為來源。
Source: Coding guidelines
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c1c8dd5f9e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if ($restoredEnvFiles.Count -gt 0) { | ||
| Write-Host "[rebuild-test-deploy] restored deployment env files count=$($restoredEnvFiles.Count): $($restoredEnvFiles -join ', ')" | ||
| } | ||
| } else { |
There was a problem hiding this comment.
Route valid checkouts through the staged swap
When $deployRoot already has a valid .git directory—the normal state after a successful rebuild—this else keeps the old in-place path. It runs git fetch/reset/clean directly in the live checkout, so a clean or env-restore failure leaves the active deployment partially reset with no $previousRoot to recover from; the staged clone/validate/rename path should cover valid checkouts too after the origin check.
Useful? React with 👍 / 👎.
| } | ||
| $deployZoneRunDir = Join-Path $deployRoot 'scripts\.run' | ||
| $serviceStopFailures = New-Object 'System.Collections.Generic.List[string]' | ||
| foreach ($serviceName in @('bim-streaming-server', 'bim-streaming-conversion-service', 'governance-service')) { |
There was a problem hiding this comment.
Stop kit-manager-api before moving the live tree
For staged replacement runs, this stop list omits kit-manager-api, but deploy.ps1 starts it from the deployment tree and records its pidfile under the same run dir (scripts/deploy.ps1 lines 1302-1316; host-native-launcher.ps1 lines 330-335). If a previous deploy left kit-manager-api running, the swap moves its pidfile away with $previousRoot, then the new deploy sees port 8010 occupied without a pidfile and can fail or prompt as a stranger process; include this service in the verified pre-cutover stop set.
Useful? React with 👍 / 👎.
| if (Test-Path -LiteralPath $stageRoot) { | ||
| Remove-Item -LiteralPath $stageRoot -Recurse -Force -ErrorAction SilentlyContinue | ||
| } |
There was a problem hiding this comment.
Surface failed staged cleanup instead of hiding it
After the stage has restored preserved .env files, later validation or service-stop failures enter this cleanup path. If Remove-Item fails on Windows because of a transient lock/ACL/reparse issue, -ErrorAction SilentlyContinue leaves a sibling .rebuild-stage-* directory containing copied secrets without telling the operator; report or append cleanup failures so the failed rebuild does not silently leak an env-bearing stage tree.
Useful? React with 👍 / 👎.
| } | ||
|
|
||
| $restoredEnvFiles = @(Restore-TestDeployEnvSnapshot -DeploymentPath $stageRoot -Snapshot $envSnapshot) | ||
| $removed = @(Remove-TestDeployAgentTooling -DeploymentPath $stageRoot -AllowNonFixedPathForTests:$AllowNonFixedPathForTests) |
There was a problem hiding this comment.
Validate the staged checkout for reparse points
This staged path only scans the existing live deployment before cloning, then restores env files and recursively removes tooling from $stageRoot without ever applying the same reparse-point guard to the cloned tree. If origin/main materializes a tracked symlink/junction or a reparse point under a tooling directory, the rebuild can either recurse through it during cleanup or activate a live deployment containing a reparse point; run the stage through the path-safety check before tooling removal/cutover.
Useful? React with 👍 / 👎.
|
|
||
| $liveMovedToPrevious = $false | ||
| if (Test-Path -LiteralPath $deployRoot -PathType Container) { | ||
| [System.IO.Directory]::Move($deployRoot, $previousRoot) |
There was a problem hiding this comment.
Report the previous checkout after staged cutover
Once this rename succeeds, any later failure in runtime env setup or deploy.ps1 -Build leaves the old deployment only at the generated $previousRoot, but the result/wrapper prints no previous path or recovery command. In that post-cutover failure scenario operators get only the deploy exit code and have to guess which .rebuild-previous-* directory is the rollback source; include the previous path in the returned/logged metadata whenever the live tree is moved aside.
Useful? React with 👍 / 👎.
Summary
AI Coding Governance
Frontend Verification
Deploy Path Verification
Validation
Known Risks
Summary by CodeRabbit
New Features
Bug Fixes
Documentation