Skip to content

fix: harden test-deployment rebuild and verification profiles - #402

Merged
monkey1sai merged 4 commits into
mainfrom
fix/issue-400-test-deploy-a4-closure
Jul 24, 2026
Merged

monkey1sai merged 4 commits into
mainfrom
fix/issue-400-test-deploy-a4-closure

Conversation

@monkey1sai

@monkey1sai monkey1sai commented Jul 24, 2026 •

Copy link
Copy Markdown
Owner

Scope

This PR delivers the canonical rebuild and deployment-profile verification slices of #400. The authority-owned mounted A4 capability and post-merge canonical deployment evidence remain follow-up acceptance gates.

Summary

  • Normalize the Windows PowerShell child PSModulePath used by canonical test-deployment rebuilds.
  • Add explicit Developer and Deployment profiles to aggregate verification, including required artifact checks and omission inventory.
  • Add regression coverage for the deployment profile and child environment contract.

Change Classification

Label Value
Change lane G
Behavior contract changed yes
Requirement source issue

AI Coding Governance

Label Value
Linked issue #400
Requirement source issue
CODEOWNERS / owner review required
GitNexus evidence implementation branch retained; no new impact run in this continuation
Browser E2E evidence not applicable to verifier/rebuild-only changes
Agent workflow changed? no
Required checks expected affected scripts/tests and repository CI

Deploy Path Verification

Label Value
Affects runtime / docker / Kit / viewer / ports / env? yes — canonical test-deployment rebuild and aggregate verifier
Canonical deploy path updated? verified by targeted script tests; fresh merged-main rebuild pending
Deploy dry-run command ./scripts/deploy.ps1 -DryRun
Verify command ./scripts/verify-all.ps1 -Profile Deployment -PlanOnly

Verification

  • PASS: scripts/tests/test-verify-all.ps1
  • PASS: PowerShell parser checks
  • PASS: git diff --check
  • PASS: bash scripts/verify-all.sh --profile Deployment --plan-only
  • Known blocker: full test-rebuild-test-deploy.ps1 remains blocked by an existing injected callback scope error (Assert-True unavailable inside the test callback).
  • Canonical rebuild and mounted A4 201 evidence remain pending fresh origin/main merge and authority-owned secrets/capability inputs.

Frontend Verification

Label Value
Frontend route verifier/rebuild-only; no frontend route changed
Main button(s) tested verifier/rebuild-only
Fixture used pruned deployment fixture in scripts/tests/test-verify-all.ps1
Backend API called no backend API in this change
Runtime action deployment health target inventory only; no runtime ID observed
Visible success state plan inventory emitted; no browser UI state
E2E command not applicable to verifier/rebuild-only changes
Screenshot / trace not applicable to verifier/rebuild-only changes
Design gate status not applicable
Design screen(s) not applicable
Reference-missing route(s) / surface(s) not applicable
Full completion claimed no
Design reference manifest not applicable
Visual fidelity result not applicable
Visual comparison not applicable
Visual artifacts not applicable
Known gaps authority-owned A4 capability and canonical merged-main deployment evidence pending

Part of #400

Copilot AI review requested due to automatic review settings July 24, 2026 05:27
@coderabbitai

coderabbitai Bot commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The PR adds Windows PowerShell child-environment handling to test deployment execution and introduces Developer and Deployment profiles with plan-only support for PowerShell and POSIX aggregate verification scripts.

Changes

Verification and deployment tooling

Layer / File(s) Summary
Child environment and pruning contracts
scripts/lib/rebuild-test-deploy.ps1
Adds pruning-contract access and resolves Windows PowerShell module roots into an isolated child PSModulePath.
Child process environment wiring
scripts/lib/rebuild-test-deploy.ps1
Passes the resolved environment through process-runner and cmd.exe launch paths.
Deployment profile and target execution
scripts/verify-all.ps1
Adds profile, repository-root, and plan-only parameters; validates deployment artifacts, health checks, omissions, required targets, and action closures.
POSIX profile and plan-only interface
scripts/verify-all.sh
Adds profile parsing, deployment dispatch, plan-only output, and profile validation.
Regression and end-to-end validation
scripts/tests/test-rebuild-test-deploy.ps1, scripts/tests/test-verify-all.ps1
Validates child module resolution, environment propagation, profile plans, omissions, missing artifacts, and cleanup behavior.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant verify-all.ps1
  participant rebuild-test-deploy.ps1
  participant RepositoryArtifacts
  participant HTTPHealthChecks
  verify-all.ps1->>rebuild-test-deploy.ps1: Load pruning contract
  verify-all.ps1->>RepositoryArtifacts: Validate preserved production files
  verify-all.ps1->>HTTPHealthChecks: Run required health checks
  HTTPHealthChecks-->>verify-all.ps1: Return status
Loading

Possibly related PRs

Suggested reviewers: copilot

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning The PR addresses PSModulePath normalization and deployment verification profiles, but not the many A4, lease, mounted-flow, and evidence requirements in #400. Implement the remaining issue #400 requirements or narrow the scope to the verification changes actually delivered.
✅ Passed checks (4 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed The changes stay within deployment verification, test coverage, and script plumbing for rebuild and aggregate checks.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changes to test-deployment rebuild and verification profile handling.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/issue-400-test-deploy-a4-closure

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (2)
scripts/verify-all.ps1 (2)

7-7: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

$Profile shadows the PowerShell automatic variable $PROFILE.

$Profile is a built-in automatic variable (path to the current PowerShell profile). Reusing it as a parameter name works here since the script never reads the profile path, but it's an easy-to-miss gotcha for future maintainers. Consider $VerifyProfile to avoid the collision.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/verify-all.ps1` at line 7, Rename the script parameter $Profile to
$VerifyProfile in the parameter declaration and update every reference to it
within the script, preserving the existing ValidateSet values and default.

154-162: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Plan output uses bare Write-Host.

The new [PLAN]/[EXECUTE]/[OMIT] output is emitted with bare Write-Host. Coding guidelines require structured logging output in scripts/**/*.ps1 to go through scripts/lib/StructLog.psm1 rather than bare Write-Host. Since the rest of this file already predates that convention, consider routing at least the new plan output through StructLog for consistency.

As per coding guidelines: "Use scripts/lib/StructLog.psm1 for structured logging output; do not replace with bare Write-Host calls".

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/verify-all.ps1` around lines 154 - 162, Route the new plan-reporting
messages in the $publishInventory block through the structured logging helpers
from scripts/lib/StructLog.psm1 instead of bare Write-Host calls. Update the
[PLAN], [EXECUTE], and [OMIT] output while preserving their current message
content and warning severity for omitted targets.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/tests/test-verify-all.ps1`:
- Around line 76-78: Replace the token-matching assertions in the POSIX verifier
checks with an actual invocation of scripts/verify-all.sh using --profile
Deployment --plan-only against the pruned fixture. Capture and validate its
parsed Deployment inventory against the PowerShell plan output, including
omitted targets, and assert that missing artifacts produce the expected failure.

In `@scripts/verify-all.sh`:
- Around line 45-62: Update the profile dispatch in verify-all.sh so Deployment
never falls through into the Developer target-building and execution block when
PLAN_ONLY is not set. Gate that block on PROFILE=Developer or implement the
corresponding Deployment checks, and reject StreamingOnly, TsOnly, and PyOnly
under Deployment to match the behavior of verify-all.ps1.

---

Nitpick comments:
In `@scripts/verify-all.ps1`:
- Line 7: Rename the script parameter $Profile to $VerifyProfile in the
parameter declaration and update every reference to it within the script,
preserving the existing ValidateSet values and default.
- Around line 154-162: Route the new plan-reporting messages in the
$publishInventory block through the structured logging helpers from
scripts/lib/StructLog.psm1 instead of bare Write-Host calls. Update the [PLAN],
[EXECUTE], and [OMIT] output while preserving their current message content and
warning severity for omitted targets.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: bf33bffa-087d-41cd-9787-f01314ae4a74

📥 Commits

Reviewing files that changed from the base of the PR and between 008acb6 and 527507f.

📒 Files selected for processing (5)
  • scripts/lib/rebuild-test-deploy.ps1
  • scripts/tests/test-rebuild-test-deploy.ps1
  • scripts/tests/test-verify-all.ps1
  • scripts/verify-all.ps1
  • scripts/verify-all.sh

Comment on lines +76 to +78
$verifyShell = Get-Content -LiteralPath (Join-Path $repoRoot 'scripts\verify-all.sh') -Raw
Assert-True ($verifyShell -match '--profile') 'POSIX verifier mirror accepts an explicit deployment profile'
Assert-True ($verifyShell -match '--plan-only') 'POSIX verifier mirror publishes the same profile inventory without executing it'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== locate files =="
git ls-files | rg '(^|/)test-verify-all\.ps1$|verify-all\.sh$|verify-all\.ps1$|AGENTS\.md$' || true

echo "== script sizes =="
for f in scripts/tests/test-verify-all.ps1 scripts/verify-all.sh scripts/verify-all.ps1 scripts/lib/StructLog.psm1; do
  [ -f "$f" ] && wc -l "$f"
done

echo "== inspect test file around assertions =="
if [ -f scripts/tests/test-verify-all.ps1 ]; then
  cat -n scripts/tests/test-verify-all.ps1 | sed -n '1,140p'
fi

echo "== inspect shell verifier outline/content =="
if [ -f scripts/verify-all.sh ]; then
  wc -l scripts/verify-all.sh
  cat -n scripts/verify-all.sh | sed -n '1,260p'
fi

echo "== inspect powershell verifier outline/content around relevant sections =="
if [ -f scripts/verify-all.ps1 ]; then
  wc -l scripts/verify-all.ps1
  cat -n scripts/verify-all.ps1 | sed -n '1,260p'
fi

echo "== search for test-verify-all usages and fixtures =="
rg -n "test-verify-all|verify-all|--profile|--plan-only|deployment profile|profile inventory|Plan output|missing|artifact" scripts AGENTS.md .github 2>/dev/null || true

Repository: monkey1sai/AI-BIM-governance

Length of output: 50385


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== git status/stat =="
git status --short
git diff --stat

echo "== shell syntax parse if available =="
bash -n scripts/verify-all.sh 2>&1 || true
pwsh -Command "& {if (Test-Path scripts/verify-all.ps1) { $f='scripts/verify-all.ps1'; $tokens=$errors=$null; [System.Management.Automation.Parser]::ParseInput((Get-Content -Raw $f), [ref]$tokens, [ref]$errors); $errors?.Write(); $tokens } else { 'verify-all.ps1 missing' } }" 2>&1 || true

echo "== deterministic flag-token semantic probe =="
python3 - <<'PY'
from pathlib import Path
import re
p=Path('scripts/tests/test-verify-all.ps1')
if p.exists():
    text=p.read_text()
    print("has profile token assertion:", bool(re.search(r'--profile', text)))
    print("has plan-only token assertion:", bool(re.search(r'--plan-only', text)))
    print("calls verify shell exec:", bool(re.search(r'Invoke-Expression|Start-Process|powershell|pwsh|verify-all', text)))
    print("contains parity output assertions:", bool(re.search(r'parity|output|assert.*profile|profile inventory', text, re.I)))
PY

Repository: monkey1sai/AI-BIM-governance

Length of output: 261


Exercise the Bash profile contract instead of scanning tokens.

These assertions pass if the flags only occur as strings; they do not verify Bash parsing, the Deployment inventory generated from the pruned fixture, omitted targets, or missing-artifact failure. Run scripts/verify-all.sh with --profile Deployment --plan-only and assert parity with the PowerShell plan output.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/tests/test-verify-all.ps1` around lines 76 - 78, Replace the
token-matching assertions in the POSIX verifier checks with an actual invocation
of scripts/verify-all.sh using --profile Deployment --plan-only against the
pruned fixture. Capture and validate its parsed Deployment inventory against the
PowerShell plan output, including omitted targets, and assert that missing
artifacts produce the expected failure.

Source: Coding guidelines

Comment thread scripts/verify-all.sh

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the workspace's test-deployment verification path per issue #400. It normalizes the Windows PowerShell child PSModulePath used by the canonical rebuild (so Get-FileHash resolves under a PowerShell 7-first parent), and splits the aggregate verifier into explicit Developer and Deployment profiles so a pruned deployment checkout is checked against the artifacts/runtime it actually preserves rather than authoring-only inputs. Regression tests cover both the new profiles and the child-environment contract.

Changes:

  • Add a normalized Windows PowerShell child environment (Get-TestDeployWindowsPowerShellChildEnvironment) and a pruning-contract accessor (Get-TestDeployPruningContract) in scripts/lib/rebuild-test-deploy.ps1, threaded into both the injected and real deploy launch paths.
  • Add Developer/Deployment profiles, -PlanOnly, required-artifact + health-endpoint checks, and an omission inventory to scripts/verify-all.ps1, with a partial mirror in scripts/verify-all.sh.
  • Add regression coverage in scripts/tests/test-verify-all.ps1 and extend scripts/tests/test-rebuild-test-deploy.ps1 for the child-environment contract and closure scope capture.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
scripts/verify-all.ps1 Adds Developer/Deployment profiles, plan-only inventory, required-artifact and health-endpoint targets, and Required/Action target semantics.
scripts/verify-all.sh POSIX mirror of --profile/--plan-only; only emits a Deployment plan and diverges from the .ps1 for non-plan-only and Developer plan-only runs.
scripts/lib/rebuild-test-deploy.ps1 Adds pruning-contract accessor and Windows PowerShell child PSModulePath normalization; passes normalized env to injected and cmd.exe launch paths.
scripts/tests/test-verify-all.ps1 New fixture asserting Developer full contract, Deployment omission inventory, and missing-artifact failure (not yet wired into CI).
scripts/tests/test-rebuild-test-deploy.ps1 Captures helper functions for closure scope, adds -Environment to injected runners, and validates the normalized child module path.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread scripts/verify-all.sh
Comment on lines +45 to +62
case "$PROFILE" in
Developer) ;;
Deployment)
echo "[PLAN] profile=deployment"
echo "[EXECUTE] deployment required artifacts"
echo "[EXECUTE] coordinator health"
echo "[EXECUTE] governance health"
echo "[EXECUTE] conversion health"
echo "[EXECUTE] kit manager health"
echo "[EXECUTE] viewer endpoint"
echo "[OMIT] tests (contracts+fakes)"
echo "[OMIT] bim-review-coordinator (full verify)"
echo "[OMIT] web-viewer-sample (full verify)"
echo "[OMIT] bim-streaming-server stage-loading contract"
if [ "$PLAN_ONLY" -eq 1 ]; then exit 0; fi
;;
*) echo "unknown profile: $PROFILE" >&2; exit 2 ;;
esac
Comment on lines +1 to +2
# scripts/tests/test-verify-all.ps1
# Verifies the canonical aggregate verifier's developer and pruned-deployment profiles.
Comment thread scripts/verify-all.ps1 Outdated
[switch] $PyOnly,
[switch] $ContinueOnError
[switch] $ContinueOnError,
[ValidateSet('Developer', 'Deployment')][string] $Profile = 'Developer',

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 527507f3e9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/verify-all.sh
Comment on lines +47 to +60
Deployment)
echo "[PLAN] profile=deployment"
echo "[EXECUTE] deployment required artifacts"
echo "[EXECUTE] coordinator health"
echo "[EXECUTE] governance health"
echo "[EXECUTE] conversion health"
echo "[EXECUTE] kit manager health"
echo "[EXECUTE] viewer endpoint"
echo "[OMIT] tests (contracts+fakes)"
echo "[OMIT] bim-review-coordinator (full verify)"
echo "[OMIT] web-viewer-sample (full verify)"
echo "[OMIT] bim-streaming-server stage-loading contract"
if [ "$PLAN_ONLY" -eq 1 ]; then exit 0; fi
;;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Implement Deployment checks in the POSIX mirror

When scripts/verify-all.sh --profile Deployment is run without --plan-only, this branch only prints the deployment inventory and then falls through to the normal Developer target construction below, so pruned deployment checkouts run/skip authoring suites instead of checking required artifacts and live health endpoints; it also accepts filters that the PowerShell verifier rejects. Please make the .sh Deployment profile execute the same deployment targets or delegate to the PowerShell verifier so the mirror does not report the wrong result.

AGENTS.md reference: scripts/AGENTS.md:L34-L34

Useful? React with 👍 / 👎.

Comment thread scripts/verify-all.ps1
Comment on lines +63 to +66
$response = Invoke-WebRequest @requestParameters
if ($response.StatusCode -ne 200) {
throw "unexpected HTTP status $($response.StatusCode)"
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Fail deployment health on degraded payloads

For Deployment profile health checks, this helper treats any HTTP 200 as success, but the conversion authority intentionally returns HTTP 200 even when converter preflight is unavailable with status="degraded" and ifc_to_usdc_conversion=false (see bim-streaming-server/tests/test_host_native_conversion_service.py:2518-2544). In that scenario conversion health is marked [OK] although IFC→USDC conversion is unusable, so parse the JSON status/claims for endpoints that expose them before passing the deployment verifier.

Useful? React with 👍 / 👎.

Comment thread scripts/verify-all.sh
fi

case "$PROFILE" in
Developer) ;;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Honor PlanOnly for the shell Developer profile

When scripts/verify-all.sh --plan-only is used with the default Developer profile, this branch does nothing and the script proceeds to construct and execute the real pytest/npm targets instead of printing the inventory and exiting like verify-all.ps1 -PlanOnly. That turns a dry plan request into a full verification run in dependency-missing or pruned environments; please emit the Developer plan and exit before target execution.

AGENTS.md reference: scripts/AGENTS.md:L34-L34

Useful? React with 👍 / 👎.

Comment thread scripts/verify-all.ps1
Comment on lines +115 to +119
$Targets += New-DeploymentHealthTarget -Name 'coordinator health' -Uri 'http://127.0.0.1:8004/health'
$Targets += New-DeploymentHealthTarget -Name 'governance health' -Uri 'http://127.0.0.1:49102/health'
$Targets += New-DeploymentHealthTarget -Name 'conversion health' -Uri 'http://127.0.0.1:49101/health'
$Targets += New-DeploymentHealthTarget -Name 'kit manager health' -Uri 'http://127.0.0.1:8010/health'
$Targets += New-DeploymentHealthTarget -Name 'viewer endpoint' -Uri 'http://127.0.0.1:5173/'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Probe the configured deployment ports

When deploy.ps1 is run with supported non-default topology such as COORDINATOR_PORT, VIEWER_PORT, or -GovernancePort, the Deployment verifier still probes the hard-coded defaults here. In that environment it can either fail a healthy deployment or pass against stale services left on the default ports, so these URIs need to be derived from the same deploy/env settings used to launch the stack.

Useful? React with 👍 / 👎.

Comment thread scripts/verify-all.ps1
Comment on lines +102 to +104
$pruningContract = Get-TestDeployPruningContract
$requiredArtifacts = @('scripts\deploy.ps1') + @($pruningContract.PreservedProductionFiles)
Test-DeploymentRequiredArtifacts -Root $RepoRoot -RequiredRelativePaths $requiredArtifacts

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Enforce the pruning side of deployment verification

This loads the pruning contract but only uses PreservedProductionFiles, so RootToolingDirNames is never checked. If the cleanup regresses and leaves .codex, .claude, openspec, patches, or other authoring/tooling roots in the deployment checkout, -Profile Deployment can still pass as long as the required files and health endpoints exist; add an absence/allowlist check for the pruned roots so a clean deployment result actually proves the contract.

AGENTS.md reference: AGENTS.md:L48-L48

Useful? React with 👍 / 👎.

@monkey1sai monkey1sai changed the title fix: close test-deployment verification gaps fix: harden test-deployment rebuild and verification profiles Jul 24, 2026
@monkey1sai
monkey1sai merged commit 48e0a2e into main Jul 24, 2026
17 checks passed
@monkey1sai
monkey1sai deleted the fix/issue-400-test-deploy-a4-closure branch July 24, 2026 05:47

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 64881de068

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/ci.yml
run: powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -File scripts/tests/test-rebuild-test-deploy.ps1

- name: Run aggregate verifier profile tests
if: needs.changes.outputs.rebuild_test_deploy == 'true'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Run verifier tests when verifier scripts change

With this condition, the new aggregate verifier tests only run when rebuild_test_deploy is true, but the classifier pattern above does not include scripts/verify-all.ps1 or scripts/verify-all.sh—only deploy/rebuild helpers and test files. A PR that changes the verifier itself will therefore get only static analysis and skip the regression tests added here; gate this step on a classifier that also matches the verifier scripts.

Useful? React with 👍 / 👎.

Comment thread scripts/verify-all.ps1
. (Join-Path $PSScriptRoot 'lib\rebuild-test-deploy.ps1')
$pruningContract = Get-TestDeployPruningContract
$requiredArtifacts = @('scripts\deploy.ps1') + @($pruningContract.PreservedProductionFiles)
Test-DeploymentRequiredArtifacts -Root $RepoRoot -RequiredRelativePaths $requiredArtifacts

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Don’t preflight artifacts before plan/continue handling

When the Deployment profile is pointed at an incomplete checkout, this eager artifact check throws while the target list is still being constructed, so -ContinueOnError cannot collect the remaining health failures and -PlanOnly cannot print the intended inventory. The same artifact validation is already registered as the first target action below, where failures are summarized and honor the normal control flow, so remove this pre-loop execution.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants