Skip to content

ci: make release workflow Reborn compile-only - #6188

Merged
think-in-universe merged 1 commit into
mainfrom
codex/issue-6160-skip-release-docker
Jul 20, 2026
Merged

think-in-universe merged 1 commit into
mainfrom
codex/issue-6160-skip-release-docker

Conversation

@hanakannzashi

@hanakannzashi hanakannzashi commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Make the tag-driven release workflow Reborn-compile-only for Build IronClaw Reborn binaries for multiple CPU architectures in the release pipeline #6160.
  • Keep the legacy cargo-dist/WASM/GitHub Release DAG visible for rollback, but hard-disable its plan root so all dependent legacy build, host, checksum, and announcement jobs skip.
  • Retain a separate impossible guard on the release Docker caller; manual and hourly runs in docker.yml remain available.
  • Preserve ci: build and validate Reborn release binaries across seven targets #6176's canonical seven-target reborn-binary-compile path as the only active release-tag job.
  • Add a caller-level smoke contract and CI path/roll-up wiring so workflow-only changes cannot silently disable Reborn compilation or re-enable publishing.
  • Document the temporary policy, blast radius, and rollback.

Dependency state

#6185 and #6176 are merged. This branch was rebuilt as one commit directly on #6176's merge result (5d3dfcc1c) and preserves the reusable seven-target Reborn compile workflow plus the host dependency/success gate.

This work does not depend on #6122.

The PR remains Draft only while the final fork tag run and refreshed CI/review complete.

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

Refs #6160

Validation

  • cargo +1.96.0 fmt --all -- --check
  • Both focused release-workflow smoke contracts (2 passed)
  • Full cargo +1.96.0 test -p ironclaw_reborn_cli (368 passed: 257 unit + 5 extension + 106 smoke)
  • cargo +1.96.0 clippy --workspace --all-targets --all-features -- -D warnings
  • cargo +1.96.0 test -p ironclaw_architecture (66 passed)
  • YAML parse and actionlint for release.yml, docker.yml, code_style.yml, and reborn-release-compile.yml
  • scripts/pre-commit-safety.sh
  • git diff --check
  • Combined canonical fork tag run 29668508858: all seven canonical targets succeeded and every legacy/publish job skipped. This was pre-rebase evidence using the two exact guards.
  • Final exact-head fork tag run 29690675159: tag ironclaw-v0.30.1-rc.4 resolved to PR head 6be18b3a1; all seven compile/native-smoke jobs succeeded, both musl portability checks passed, exactly seven non-empty reborn-compile-* artifacts were uploaded, all eight legacy/publish jobs skipped, and no rc.4 GitHub Release or checksum PR was created.

The earlier fork release run 29610386170 validated only the superseded Docker-only policy.

Security Impact

The disabled legacy root prevents the tag path from reaching legacy artifact publication, GitHub Release creation, registry checksum updates, announcements, or their associated publishing credentials. The explicit Docker guard prevents release-path image publication. Independent manual/scheduled Docker workflow permissions are unchanged.

Reborn Trust-Boundary Checklist

N/A — this changes release CI policy only and does not alter runtime, persistence, ingress, capability, or product security boundaries.

Database Impact

None.

Blast Radius

Release tags run only the seven-platform Reborn compile matrix. They produce short-lived Actions evidence artifacts, but no legacy binaries, WASM bundles, Docker images, GitHub Release, permanent downloadable release assets, registry checksum update, or announcement. Manual/hourly docker.yml entry points are unaffected.

Rollback Plan

Remove plan's impossible github.repository == '' guard to re-enable the non-Docker legacy release DAG; the workflow trigger is already tag-only. Restore docker-image.if to ${{ always() && needs.host.result == 'success' }} separately only when release image publication is intentionally re-enabled. No schema or persisted-state migration is involved.


Review track: C (CI/release)

@ironloopai

ironloopai Bot commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: 6be18b3a15fe7284b9c61896f07ed9b15588024a
Result: 1/1 reviewers completed without blocking findings.
Next: Ready for normal human review and CI checks.
Updated: 2026-07-19T15:00:10.552Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Completed Approved 0 blocking findings / 0 notes 2026-07-19T15:00:10.543Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Approved; 0 blocking findings; Approved. The focused six-file CI change correctly makes the legacy release DAG unreachable from its disabled plan root, preserves the active Reborn compile caller, keeps Docker r…
Recent activity
Time Reviewer State Detail
2026-07-19T14:54:56.829Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head 6be18b3.
2026-07-19T14:54:56.829Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-19T14:56:48.510Z ironloop/common-reviewer (reviewer) Result captured Needs validation; 0 blocking findings.
2026-07-19T14:56:48.510Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
2026-07-19T14:56:51.946Z ironloop/common-reviewer (reviewer) Started Reviewer worker started.
2026-07-19T14:56:54.515Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 051c661.
2026-07-19T15:00:10.543Z ironloop/common-reviewer (reviewer) Result captured Approved; 0 blocking findings.
2026-07-19T15:00:10.543Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6188 July 17, 2026 11:04 Destroyed
@github-actions github-actions Bot added size: XS < 10 changed lines (excluding docs) risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs scope: ci CI/CD workflows scope: docs Documentation and removed contributor: core 20+ merged PRs labels Jul 17, 2026
@coderabbitai

coderabbitai Bot commented Jul 17, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • Release Process

    • Temporarily disabled legacy release publishing, including GitHub Releases, registry checks, WASM artifacts, and Docker image publication.
    • Reborn release validation now uses a compile-only workflow with short-lived CI evidence artifacts.
  • Documentation

    • Documented the temporary release policy and re-enablement requirements.
    • Preserved independent manual and scheduled Docker workflow runs.
  • Quality

    • Added automated checks to verify release workflow safeguards and ensure related workflow changes trigger validation.

Walkthrough

Release CI disables the legacy release and Docker publication paths with impossible repository guards. Smoke tests validate workflow wiring, and Code Style now selects and propagates Reborn CLI workflow checks. Documentation records the policy and rollback conditions.

Changes

Reborn release validation

Layer / File(s) Summary
Gate legacy release paths
.github/workflows/release.yml
The legacy plan chain and docker-image caller remain defined but skip under normal repository contexts.
Validate workflow contracts
crates/ironclaw_reborn_cli/tests/smoke.rs
Smoke coverage verifies release dependencies, Docker wiring and triggers, and Code Style failure propagation.
Wire workflow selection and document policy
.github/workflows/code_style.yml, .github/workflows/README.md
Release and Docker workflow edits select Reborn CLI smoke checks, failed smoke results fail the roll-up, and the release policy is documented.

Estimated code review effort: 2 (Simple) | ~15 minutes

Possibly related PRs

Suggested reviewers: think-in-universe

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and accurately summarizes the main change to the release workflow.
Description check ✅ Passed The description matches the template with summary, change type, linked issue, validation, security, impact, rollback, and review sections filled.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds a changelog entry and a smoke test to verify that the release CI workflow temporarily skips Docker image builds and publication while keeping independent Docker workflow runs active. The reviewer suggested a more robust approach for extracting the Docker job block in the test to prevent fragility when the workflow file is modified.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread crates/ironclaw_reborn_cli/tests/smoke.rs Outdated

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
❌ Changes requested 1 0 1 82ee5c5879de

Head: 82ee5c5879de564c31ccafaf068be9fa4078fd97
Next: Fix the blocking findings, push the PR branch, then re-run this reviewer.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

The release caller is correctly disabled, but the new regression test is not wired to run for future workflow-only changes, so the policy can regress before merge without failing required checks.

Findings

Blocking: 1 / Notes: 0

Blocking findings

1. ❌ [MEDIUM] Run this contract test for workflow-only changes

Location: crates/ironclaw_reborn_cli/tests/smoke.rs:158-180
This test lives in the Reborn CLI smoke suite, but the has_reborn_cli path gate in .github/workflows/code_style.yml excludes both .github/workflows/release.yml and .github/workflows/docker.yml. The Reborn test classifier likewise returns has_reborn_tests=false for either workflow path. Consequently, a later PR or merge-group diff that only re-enables this caller or disables the independent entry points will not run this contract; it runs only after landing, when push runs force all tests. Add these workflow paths to the smoke-test CI scope (with classifier coverage), or move the assertion into an always-run workflow validation job.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

Comment thread crates/ironclaw_reborn_cli/tests/smoke.rs Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/release.yml:
- Around line 476-477: Update the job guard for update-registry-checksums by
removing the constant if: ${{ false }} expression, or replace it with a valid
non-constant condition; preserve needs: host and ensure the job is not
incorrectly gated on docker-image.

In `@crates/ironclaw_reborn_cli/tests/smoke.rs`:
- Around line 170-177: Update the release CI assertion in the smoke test to
match the lint-compliant false condition used by release.yml, replacing the
current `if: ${{ false }}` string while preserving the existing checks for the
Docker caller, release flag, dependency, and inherited secrets.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 2e21fb15-9e0e-4a41-b424-0a4225fa397e

📥 Commits

Reviewing files that changed from the base of the PR and between 81dbdc6 and 82ee5c5.

⛔ Files ignored due to path filters (1)
  • CHANGELOG.md is excluded by !CHANGELOG.md
📒 Files selected for processing (3)
  • .github/workflows/README.md
  • .github/workflows/release.yml
  • crates/ironclaw_reborn_cli/tests/smoke.rs

Comment thread .github/workflows/release.yml Outdated
Comment thread crates/ironclaw_reborn_cli/tests/smoke.rs
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6188 July 17, 2026 11:11 Destroyed
@github-actions github-actions Bot added the contributor: core 20+ merged PRs label Jul 17, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_reborn_cli/tests/smoke.rs`:
- Around line 4298-4323: Update the smoke-test scope classifier used for the
ironclaw_reborn_cli test suite to include .github/workflows/release.yml and
.github/workflows/docker.yml in its curated allowlist, ensuring workflow-only
changes run
release_ci_skips_docker_publish_without_disabling_independent_docker_runs.
Alternatively, move this validation into a CI check that is guaranteed to run
for workflow changes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d6c7285f-079b-46b7-afbb-80c07b81670e

📥 Commits

Reviewing files that changed from the base of the PR and between 82ee5c5 and 60fc641.

⛔ Files ignored due to path filters (1)
  • CHANGELOG.md is excluded by !CHANGELOG.md
📒 Files selected for processing (2)
  • .github/workflows/README.md
  • crates/ironclaw_reborn_cli/tests/smoke.rs

Comment thread crates/ironclaw_reborn_cli/tests/smoke.rs
@railway-app

railway-app Bot commented Jul 17, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-6188 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 19, 2026 at 2:35 pm

@github-actions

github-actions Bot commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.59% (313152 / 365860 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 365860 lines now vs 320188 at floor capture (+45672 lines, +14.26%) — material change (>5%)

⚠️ 2 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.59% — 313152 / 365860 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 345
ironclaw_runtime_policy 31.75% 80 / 252
ironclaw_event_projections 43.31% 673 / 1554
ironclaw_observability 61.54% 16 / 26
ironclaw_authorization 62.46% 604 / 967
ironclaw_dispatcher 62.88% 83 / 132
ironclaw_mcp 64.89% 595 / 917
ironclaw_triggers 65.44% 2142 / 3273
ironclaw_filesystem 67.78% 3957 / 5838
ironclaw_channel_host 68.65% 219 / 319
ironclaw_memory 69.2% 773 / 1117
ironclaw_reborn_migration 71.64% 1551 / 2165
ironclaw_trust 72.88% 661 / 907
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_reborn_event_store 74.67% 958 / 1283
ironclaw_extractors 74.72% 538 / 720
ironclaw_capabilities 75.58% 2092 / 2768
ironclaw_projects 76.48% 400 / 523
ironclaw_reborn_cli 77.07% 10249 / 13298
ironclaw_llm 78.36% 20306 / 25915
ironclaw_product_context 78.57% 11 / 14
ironclaw_run_state 79.25% 424 / 535
ironclaw_telegram_extension 80.18% 4842 / 6039
ironclaw_wasm_product_adapters 80.36% 1448 / 1802
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_first_party_extensions 81.06% 5965 / 7359
ironclaw_memory_native 81.17% 3195 / 3936
ironclaw_events 81.95% 1594 / 1945
ironclaw_network 82.98% 673 / 811
ironclaw_reborn_identity 83.59% 433 / 518
ironclaw_processes 83.76% 939 / 1121
ironclaw_secrets 83.79% 2548 / 3041
ironclaw_wasm 84.44% 1069 / 1266
ironclaw_auth 84.81% 3233 / 3812
ironclaw_product_workflow 84.91% 11031 / 12992
ironclaw_reborn_config 85.2% 2055 / 2412
ironclaw_turns 85.64% 14399 / 16813
ironclaw_channel_delivery 85.79% 1383 / 1612
ironclaw_common 86.13% 1714 / 1990
ironclaw_threads 86.93% 4708 / 5416
ironclaw_slack_v2_adapter 87.3% 1491 / 1708
ironclaw_skills 87.6% 4471 / 5104
ironclaw_hooks 87.78% 9921 / 11302
ironclaw_reborn_composition 87.97% 70290 / 79904
ironclaw_product_adapter_registry 88.06% 531 / 603
ironclaw_host_api 88.1% 3894 / 4420
ironclaw_product_adapters 88.1% 3384 / 3841
ironclaw_reborn_traces 88.2% 11946 / 13544
ironclaw_host_runtime 88.69% 18060 / 20363
ironclaw_webui 88.9% 7652 / 8607
ironclaw_extensions 89.38% 2971 / 3324
ironclaw_reborn_openai_compat 89.5% 3778 / 4221
ironclaw_runner 89.65% 17365 / 19370
ironclaw_telegram_v2_adapter 89.7% 2717 / 3029
ironclaw_approvals 90.18% 1598 / 1772
ironclaw_conversations 90.39% 3123 / 3455
ironclaw_event_streams 90.82% 1009 / 1111
ironclaw_resources 91.65% 4476 / 4884
ironclaw_loop_host 92.28% 15577 / 16880
ironclaw_attachments 93.06% 630 / 677
ironclaw_agent_loop 94.88% 9184 / 9680
ironclaw_safety 95.09% 3682 / 3872
ironclaw_outbound 95.52% 3451 / 3613
ironclaw_first_party_extension_ports 95.62% 3672 / 3840

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (3 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6188 July 17, 2026 16:22 Destroyed
@github-actions github-actions Bot added size: S 10-49 changed lines and removed size: XS < 10 changed lines (excluding docs) labels Jul 17, 2026
@hanakannzashi

Copy link
Copy Markdown
Contributor Author

Review follow-up for head eb4f4efc9:

  • Replaced the constant-false guard with the actionlint-compliant impossible repository predicate and synchronized the contract assertion.
  • Made Docker job extraction independent of the following job name/order by stopping at the next two-space YAML job boundary.
  • Added release.yml and docker.yml to the Reborn CLI smoke selector.
  • Made the required Code Style roll-up propagate workflow-only Reborn CLI smoke failures instead of exiting green.
  • Added contract coverage for both selector and roll-up enforcement, plus CRLF normalization.

Validation: focused contract test, rustfmt, YAML parse, actionlint 1.7.12 on all three relevant workflows, and git diff --check all pass.

@ironloopai review

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
✅ Approved 0 0 0 eb4f4efc993d

Head: eb4f4efc993dbf152817652f8369a9f5094df507
Next: No reviewer action needed.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

Approved. This is a focused five-file CI-policy change that disables only the tag-driven release Docker caller. The independent manual and hourly Docker entry points remain unchanged, no downstream release job depends on the skipped caller, and the new smoke contract plus Code Style routing cover the changed policy. No concrete correctness, security, or test-coverage issue was found.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

@think-in-universe

Copy link
Copy Markdown
Collaborator

Besides docker image, do we need to skip other jobs like build-wasm-extensions in the release workflow?

@hanakannzashi

Copy link
Copy Markdown
Contributor Author

@think-in-universe I tested this with a real tag push in a personal fork.

Evidence:

Observed tag behavior:

  • plan, build-wasm-extensions, all 7 build-local-artifacts jobs, build-global-artifacts, host, update-registry-checksums, and announce all ran and succeeded.
  • host succeeded first, then docker-image was skipped with zero steps and no runner.
  • No reusable Docker Build & Push child job was created, and the run logs contain no Docker login, buildx, build, or push activity.

So the current #6188 guard is working as intended for Docker. build-wasm-extensions is not a Docker dependency; it feeds WASM bundles/checksums into the existing GitHub Release path.

If the intended tag behavior is to keep the existing non-Docker release artifacts, I would leave WASM and the rest of the cargo-dist DAG unchanged. If the intended behavior is Reborn compile-only validation, then yes, we should skip the entire legacy plan -> WASM/local/global -> host -> checksum/announce chain, not only build-wasm-extensions. Skipping WASM alone still allows build-local and host to publish the legacy release. #6188 itself does not contain the Reborn compile job, so I have not expanded its scope without confirmation.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6188 July 18, 2026 03:55 Destroyed
@hanakannzashi hanakannzashi changed the title ci: skip Docker publish in release workflow ci: make release workflow Reborn compile-only Jul 18, 2026
@hanakannzashi
hanakannzashi marked this pull request as draft July 18, 2026 03:56
@hanakannzashi

Copy link
Copy Markdown
Contributor Author

Follow-up after the release-scope clarification: the intended tag path is Reborn-only, so I updated head 8a796809e beyond the earlier Docker-only policy.

  • The legacy plan root now has the actionlint-safe impossible predicate. That makes build-local-artifacts, build-global-artifacts, build-wasm-extensions, host, update-registry-checksums, and announce skip through their existing needs: plan dependency.
  • docker-image retains its own impossible predicate as defense in depth.
  • Manual/hourly docker.yml entry points remain unchanged.
  • The smoke contract now checks the whole disabled legacy DAG, plus the independent Docker triggers and required CI selector/roll-up.

I converted this PR to Draft because it must merge last: #6185 first, then update/merge #6176 with the canonical ironclaw Reborn binary, then rebase this PR and preserve #6176's seven-platform reborn-binary-compile job. It does not depend on #6122.

Local validation passed: full Reborn CLI smoke suite (103 tests), focused workflow contract, rustfmt, all-target/all-feature Clippy with warnings denied, YAML parse, actionlint, pre-commit safety, and diff check.

The previous fork tag run validated only Docker skipping. I will run a new fork tag test on the final combined head before marking this ready, verifying that only the Reborn matrix runs and that no GitHub Release is created.

@ironloopai review

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⏭️ IronLoop Review Declined: reviewer

Review at a glance

Disposition Head
⏭️ Review declined 8a796809e24b

Head: 8a796809e24b11e99c23fd6a5ed6e929bf5085e1
Reason: The required stacked-PR context is unavailable; reviewing this layer alone cannot verify that a release tag retains the intended seven-platform Reborn compile path.
Next: Rebase this PR onto the merged #6185 and #6176 changes so release.yml contains the Reborn compile matrix, then run the required fork tag test against that combined head and request review again.

Run details

Status: Current
Trustworthy review produced: no

Summary

Skipped: this draft layer disables every currently present release job, while its required Reborn compile matrix (#6176) is not included in the supplied base-to-head comparison.

@hanakannzashi

Copy link
Copy Markdown
Contributor Author

The required combined release-path proof is now complete: fork Release run 29668508858 used current #6176 (rebased after #6185, canonical ironclaw) plus this PR's exact two release guards.

Results:

  • all seven canonical ironclaw / ironclaw.exe compile + native smoke jobs succeeded
  • both musl ELF portability checks succeeded
  • exactly seven reborn-compile-* evidence artifacts were created
  • plan, WASM, local/global artifacts, host, Docker, checksum update, and announce all skipped
  • no GitHub Release and no checksum PR were created

This PR correctly remains Draft until #6176 merges. Then it still needs a rebase onto that result and final local contract/static validation before review; the whole old #6188 branch should not be merged/cherry-picked into #6176 because it predates #6185 and would regress canonical paths.

@hanakannzashi
hanakannzashi force-pushed the codex/issue-6160-skip-release-docker branch from 8a79680 to 6be18b3 Compare July 19, 2026 14:19
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6188 July 19, 2026 14:20 Destroyed
@hanakannzashi
hanakannzashi marked this pull request as ready for review July 19, 2026 14:54
@hanakannzashi

Copy link
Copy Markdown
Contributor Author

Final post-#6176 update is complete on head 6be18b3a15fe7284b9c61896f07ed9b15588024a.

  • Rebuilt this branch as one commit directly on merged ci: build and validate Reborn release binaries across seven targets #6176, preserving the canonical seven-target Reborn compile job and its host success gate.
  • Kept only the legacy plan root and release Docker caller disabled; manual/hourly docker.yml entry points are unchanged.
  • Expanded the workflow-only smoke selector to include the reusable Reborn compile workflow and added a contract that the Reborn job remains unguarded/active.
  • Updated the release policy, rollback instructions, binary packaging docs, and changelog.
  • Local validation passed: full Reborn CLI suite (368), workspace all-target/all-feature Clippy with warnings denied, architecture tests (66), fmt, actionlint/YAML, pre-commit safety, and diff check.
  • Exact-head fork Release run 29690675159 passed all 7 canonical targets, including both musl portability checks and native smoke tests. All 8 legacy/publish jobs skipped; exactly 7 non-empty evidence artifacts were created; no rc.4 GitHub Release or checksum PR was created.
  • PR CI is green after rerunning one unrelated WebUI refresh flake: 59 passed, 6 expected skipped, 0 failed.

The PR is now ready for review and does not depend on #6122.

@ironloopai review

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
⚠️ Needs validation 0 0 0 6be18b3a15fe

Head: 6be18b3a15fe7284b9c61896f07ed9b15588024a
Next: Human review or validation is required before merging.

Run details

Status: Current
Needs human: no
Needs validation: yes

Summary

Static review found no actionable correctness or security defects in this focused six-file CI/documentation change. The legacy release DAG is disabled at its root while the Reborn seven-target compile caller remains active, and the Code Style roll-up now propagates workflow-only smoke failures.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
✅ Approved 0 0 0 6be18b3a15fe

Head: 6be18b3a15fe7284b9c61896f07ed9b15588024a
Next: No reviewer action needed.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

Approved. The focused six-file CI change correctly makes the legacy release DAG unreachable from its disabled plan root, preserves the active Reborn compile caller, keeps Docker release publishing independently disabled, and wires workflow-only changes into the required smoke-result roll-up.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/code_style.yml (1)

278-280: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Remove redundant corepack enable pnpm step.

corepack enable pnpm is already executed prior to setup-node (e.g., lines 268-270) to ensure the pnpm binary is available for cache hashing. Repeating it immediately after is dead logic.

  • .github/workflows/code_style.yml#L278-L280: remove the redundant Enable pnpm step in the clippy job.
  • .github/workflows/code_style.yml#L334-L336: remove the redundant Enable pnpm step in the clippy-windows job.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/code_style.yml around lines 278 - 280, Remove the
redundant “Enable pnpm” step from the clippy job in
.github/workflows/code_style.yml lines 278-280 and from the clippy-windows job
at lines 334-336; retain the earlier Corepack setup before setup-node in both
jobs.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/code_style.yml:
- Around line 278-280: Remove the redundant “Enable pnpm” step from the clippy
job in .github/workflows/code_style.yml lines 278-280 and from the
clippy-windows job at lines 334-336; retain the earlier Corepack setup before
setup-node in both jobs.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: aa9c1e1a-67ae-4544-86c3-30d62a6f41b1

📥 Commits

Reviewing files that changed from the base of the PR and between 8a79680 and 6be18b3.

⛔ Files ignored due to path filters (1)
  • CHANGELOG.md is excluded by !CHANGELOG.md
📒 Files selected for processing (3)
  • .github/workflows/README.md
  • .github/workflows/code_style.yml
  • .github/workflows/release.yml

@think-in-universe

Copy link
Copy Markdown
Collaborator

@claude review

@claude

claude Bot commented Jul 19, 2026

Copy link
Copy Markdown

Code Review: PR #6188

Found 6 issues across security, architecture, and test quality:

🔴 HIGH Priority

[HIGH:75] Logic error in code_style.yml rollup gate (lines 479-484)

The conditional exit structure is inverted:

if [[ "${{ needs.changes.outputs.has_code }}" == "false" ]]; then
  if [[ "${{ needs.changes.outputs.has_reborn_cli }}" == "true" && "${{ needs.reborn-cli-smoke.result }}" != "success" ]]; then
    exit 1
  fi
  echo "No code changes — style checks skipped correctly"
  exit 0
fi

When a PR touches only workflow files and Reborn CLI smoke fails, this job will exit 1 (line 483), but the outer block message says "checks skipped correctly". This is confusing and contradictory. The reborn-cli smoke check should be evaluated before entering the "no code changes" block, not nested inside it. The failure path needs a distinct error message.

Suggested fix: Move the reborn-cli smoke check outside the has_code == false block as a separate validation step.


[HIGH:95] Test belongs in architecture tier, not smoke suite

release_ci_skips_legacy_publish_dag_without_disabling_independent_docker_runs() (lines 6951–7055) validates workflow structure and CI boundaries, not Reborn CLI behavior. Per CLAUDE.md §Testing Discipline, architecture/composition boundaries belong in crates/ironclaw_architecture/tests/ (tier 3), not in the smoke.rs unit test suite.

This test should move to a dedicated CI contract validator (e.g., a GitHub Actions workflow job with YAML schema validation, or an architecture-tier test).


[HIGH:85] Test has incomplete dependency DAG verification

The test verifies that legacy jobs depend on plan, but doesn't verify they DON'T directly depend on reborn-binary-compile. If someone accidentally adds:

build-global-artifacts:
  needs: [plan, reborn-binary-compile]

The test would pass. Add a negative assertion: !legacy_job.contains("\n - reborn-binary-compile\n")


🟡 MEDIUM Priority

[CRITICAL:95] Test uses fragile substring matching for YAML structure

The assertion legacy_job.contains("\n - plan\n") (line 7017) is fragile to formatting changes. If someone reformats YAML to compact syntax or adds comments, the test breaks silently without validating the actual dependency graph. Consider using a YAML parser (serde_yaml) instead of string operations for robust validation.


[MEDIUM:80] Test-first discipline not followed

Per CLAUDE.md §Testing Discipline, infrastructure changes should start with a failing test, not add the test post-implementation. There's no evidence this test was written first and allowed to fail before the workflow changes were made.


[MEDIUM:75] No regression test marked; missing commit context

This is a high-risk change (disabling release artifact publication paths) but carries no [fix] tag in the commit message and no regression test context. Per repo convention, critical infrastructure changes should be marked with evidence of pre-fix test failure.


Summary

The PR's intent is clear and the core workflow changes are sound (disabling legacy paths with impossible guards, keeping architecture visible for rollback). The issues are organizational: the test should move to the architecture tier, the logic gate in code_style needs restructuring, and the test suite should use YAML parsing instead of string matching.

Recommend: Fix the code_style.yml logic gate (high priority), move the test to architecture tier, and consider YAML parsing for robustness.

@think-in-universe
think-in-universe added this pull request to the merge queue Jul 20, 2026
Merged via the queue into main with commit 51b6e4d Jul 20, 2026
71 of 73 checks passed
@think-in-universe
think-in-universe deleted the codex/issue-6160-skip-release-docker branch July 20, 2026 04:37

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-6188 — 6be18b3a Deployed Jul 19, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows scope: docs Documentation size: S 10-49 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants