Skip to content

Cover computed channel environment names in approval lint #750

Description

@shiny-code-app

Outcome

Improve structural detection of computed release-channels names in newly added workflows without changing the approved one-approval Ship contract or restricting unrelated environments without their supported route.

Evidence

Anthropic claude-opus-5-5 reviewed #748 at 92665c3 on 2026-10-03. No blocking or medium findings were reported. One low finding remains: the checker catches a literal release-channels in an unclassified workflow but a future PR could add environment: ${{ format('release-{0}', 'channels') }} or select the name through a variable and pass that check.

The fixture scenario is reproducible. It requires a new trusted, reviewed commit on protected main; no current workflow uses this path. Existing channel workflows still choose their environment by the Ship caller identity and successful approved intent dependencies. docs/release.md explicitly records protected-main workflow changes as the trust boundary; GitHub environment branch rules cannot bind a workflow filename.

Search of the open/closed planning inventory found no existing issue for computed release environment names. #747 owns the approved release change, #749 owns unrelated existing test inspection noise, and #695/#579 are closed test audits.

Current Status

State: Complete. CP-750-D1 merged #758 with a normal merge commit at 58bb12d. Finish line met: computed selectors fail behavioral fixtures/CLI lint over actual workflows; unrelated literal and fixed-namespace routes are documented; approved #747 graph and credential boundaries unchanged.
Passed: Final reviewed head ea0a67f had 4/4 green PR checks; exact landing CI 37168208664 and CodeQL 37168208663 passed. Full commit gate included Swift build/1,205 tests; final Python gate, 7 approval tests (32 refused selector forms and 8 accepted unrelated routes), real workflow lint, CLI planted regression and actionlint passed. Two unchanged Markdown MD013 lines reproduced on base. Docs/github.json current.
Review: Anthropic claude-fable-5-1 reviewed initial/final heads read-only; no blocking findings or bypass/policy expansion. Hyphen compatibility fixed. Pre-existing external reusable-workflow visibility is reproduced as source-lint blindness, not a live credential bypass, and deferred without starting to #757. Cosmetic invalid-name diagnostics retained; bare choice selectors have the supported namespace route. PR watcher confirmed merged/stop_pr_closed. No matching background review is observable; commissioned reviews completed.
Inspection: UNKNOWN, not GREEN. First attempt waited out shared lifecycle-lock contention. Final explicit four-file attempt project_open_blocked before native analysis, retry=false; Python preparation succeeded without tracked/index/untracked mutation, cleanup deferred. The trial expressly permits continuing with IDE-related UNKNOWN. Recurrence recorded on jetbrains-inspection-api#433 comment 5975362264; whole-project inspection not run for this four-file validation-tooling change.
Next action: None for #750 source. Supported cleanup recovery stays with #433: once exact route/ownership prerequisites resolve, reconcile lease 0ca4b08a-679b-415f-9d83-c362e39391f9 and helper SDK, then fresh contents/live-use checks and named dev-worktree retire. No force removal or manual lease edit.
Retained: Own clean local branch work/750-computed-environments and locked Developer-Artifacts worktree with generated .idea/.venv/.build state until supported cleanup. GitHub automatically removed the merged remote branch; all source is durable in PR/landing ancestry. No task processes remain after closeout; scratch evidence conclusions recorded in issue/PR before disposal.
Local default: Primary main clean at b459894, deliberately stale under no-primary-edit authority; fast-forward before default-branch work/audits. Installed app/runtime and unrelated work untouched; no installed-runtime reconciliation applies to validation-tooling changes.
Security: Zero open CodeQL alerts observed; sanitized secret scanning unavailable for this public repository, not clean.
Blocked by: No source or Director decision. Retained cleanup prerequisite only, tracked in #433.
Waiting for: Nothing from Chris. No release, dispatch/rerun, deploy, publication, tag, access/credential or production action occurred.
Admission: direction#16 / overall Order 3 unused-capacity rule recorded in claim 5975214119; claim released in comment 5975461760.
Last verified: October 3, 2026, exact landing checks and fresh Git/GitHub evidence.

Next action

Reproduce the calculated-name fixture, choose a bounded check compatible with supported future environment workflows, and review any approval-policy extension under the repository's direction and model-review rules. A blanket ban on every new environment expression is not adopted here. Do not add a permission bypass or execute a release.

Finish line

A computed channel-environment regression fails a behavioral fixture and real-workflow lint, supported unrelated environments have a documented route, and no current approval or credential boundary is weakened. Any new policy beyond #747's decision is escalated before implementation.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    planDurable planning issueplan:donePlan completed or superseded

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions