Repository navigation
Require one approval for an owner-configured Ship run - #748
Conversation
|
Another-provider review: Anthropic The second review found two remaining checker issues, now fixed in Final current-head inspection and another-provider review are running before the push. Previous 12-file inspection was GREEN with successful cleanup; broad existing test-file noise is tracked in #749 and the host-load watchdog race in #736. No release is dispatched, and owner access setup still waits on Chris. |
|
Exact-head review completed: Anthropic Disposition of final low findings: calculated channel-environment access in a future newly merged workflow is reproduced and deferred to #750 without implementation; current workflows do not expose it and protected-main source changes remain the documented trust boundary. Real-workflow lint remains a separately executed/documented local command plus required CI step, for the gate/fixture coupling reason recorded above. Empty/non-mapping YAML already fails closed, so cosmetic traceback handling is declined; it is not described as a passing invalid-input test. No release or environment change was used to validate these claims. Live one-prompt behavior remains unproven until Chris completes setup and a later authorized release runs. |
|
The Owner decision replaces this PR's duplicate-store hand setup. This PR was already merged when the Supervisor routed that instruction to this session; the source correction is #751. It keeps all GitHub release secrets in existing |
A multi-channel Ship run currently asks for release approval again as each signing or upload job reaches
release. This change keeps the required review onValidate Release Intentand lets its successful channel calls userelease-channelsafter the owner configures that environment and setsRELEASE_CHANNELS_CONFIGURED=true.The four reusable channel workflows select the environment from GitHub's caller workflow reference. Direct dispatches of Release, Mac upload, companion upload, and TestFlight keep
releasereview; App Store Review submission and screenshots always keep their separate review. Before owner setup, all channels retain the existing reviewed path. Deleting the activation variable restores it without deleting credentials. Cancelling Ship prevents TestFlight from starting; reruns of an approved Ship reuse that run's approval.The approval-graph linter runs in CI, checks successful intent/guard dependencies, standalone routing, skipped/echoed/tolerated guards, alternate secret expressions, and unclassified direct channel-environment access. Its all-channel structural dry run derives one reviewed Ship job from the parsed graph and prints referenced secret names per environment without values. Mutation fixtures replace the obsolete positive workflow-text assertion that every channel uses literal
environment: release. Documentation and.github/github.jsondescribe the contract, local lint command, and owner setup.Validation: full commit gate passed (including 1,203 Swift tests; product source is unchanged); initial 117 focused Python release tests passed. A later run had 116 passing tests plus the known one-second watchdog scheduling race; the isolated retry passed, and no watchdog/test timing was changed. Current approval fixtures, real-workflow lint and actionlint pass. Final exact-worktree JetBrains inspection is GREEN for the 12 new/revised helper, fixture, configuration and documentation files, with cleanup complete. The broad inspection was RED: 12 new warnings were fixed, while 191 existing warnings remain in the old test file where this diff only deletes one obsolete test. Markdown lint has four pre-existing line-length warnings, reproduced on the base; new prose is clean. CI is running on
92665c3682fb821b34dbaa36a855fb4e5294f50f.Anthropic
claude-opus-5-5reviewed three snapshots, including this exact head. No blocking or medium defects were reported. All demonstrated current-path issues were fixed. A reproduced computed-environment-name gap requiring a future trusted-main workflow change is deferred to the unstarted follow-up below; protected-main workflow edits remain the documented trust boundary. The local-gate placement point is retained deliberately: real-workflow lint is documented, separately executed locally, and mandatory in CI, avoiding unrelated fixture/dependency coupling in commit-gate tests. Invalid/empty YAML fails closed; cosmetic traceback handling is declined. Review evidence and dispositions are recorded in the PR comments.Refs #747. The issue remains open for Chris's hand step with exact environment, secret-placement, branch-rule and activation-variable clicks. The bot could read environment protection but secret-name/variable APIs returned 403; setup is owner-confirmed, never inferred. No secret value was read or copied, no environment/access was changed, and no release was dispatched. The active 1.0.69 release session, run, worktree and installed Production runtime remain untouched. This repository has no
DIRECTION.md; the Director's overall direction applies, including the spare-capacity admission recorded in the claim.Code follow-ups recorded without starting implementation: #736 #749 #750