Skip to content

Require one approval for an owner-configured Ship run - #748

Merged
shiny-code-app[bot] merged 4 commits into
mainfrom
work/747-single-release-approval
Oct 3, 2026
Merged

shiny-code-app[bot] merged 4 commits into
mainfrom
work/747-single-release-approval

Conversation

@shiny-code-app

@shiny-code-app shiny-code-app Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

A multi-channel Ship run currently asks for release approval again as each signing or upload job reaches release. This change keeps the required review on Validate Release Intent and lets its successful channel calls use release-channels after the owner configures that environment and sets RELEASE_CHANNELS_CONFIGURED=true.

The four reusable channel workflows select the environment from GitHub's caller workflow reference. Direct dispatches of Release, Mac upload, companion upload, and TestFlight keep release review; App Store Review submission and screenshots always keep their separate review. Before owner setup, all channels retain the existing reviewed path. Deleting the activation variable restores it without deleting credentials. Cancelling Ship prevents TestFlight from starting; reruns of an approved Ship reuse that run's approval.

The approval-graph linter runs in CI, checks successful intent/guard dependencies, standalone routing, skipped/echoed/tolerated guards, alternate secret expressions, and unclassified direct channel-environment access. Its all-channel structural dry run derives one reviewed Ship job from the parsed graph and prints referenced secret names per environment without values. Mutation fixtures replace the obsolete positive workflow-text assertion that every channel uses literal environment: release. Documentation and .github/github.json describe the contract, local lint command, and owner setup.

Validation: full commit gate passed (including 1,203 Swift tests; product source is unchanged); initial 117 focused Python release tests passed. A later run had 116 passing tests plus the known one-second watchdog scheduling race; the isolated retry passed, and no watchdog/test timing was changed. Current approval fixtures, real-workflow lint and actionlint pass. Final exact-worktree JetBrains inspection is GREEN for the 12 new/revised helper, fixture, configuration and documentation files, with cleanup complete. The broad inspection was RED: 12 new warnings were fixed, while 191 existing warnings remain in the old test file where this diff only deletes one obsolete test. Markdown lint has four pre-existing line-length warnings, reproduced on the base; new prose is clean. CI is running on 92665c3682fb821b34dbaa36a855fb4e5294f50f.

Anthropic claude-opus-5-5 reviewed three snapshots, including this exact head. No blocking or medium defects were reported. All demonstrated current-path issues were fixed. A reproduced computed-environment-name gap requiring a future trusted-main workflow change is deferred to the unstarted follow-up below; protected-main workflow edits remain the documented trust boundary. The local-gate placement point is retained deliberately: real-workflow lint is documented, separately executed locally, and mandatory in CI, avoiding unrelated fixture/dependency coupling in commit-gate tests. Invalid/empty YAML fails closed; cosmetic traceback handling is declined. Review evidence and dispositions are recorded in the PR comments.

Refs #747. The issue remains open for Chris's hand step with exact environment, secret-placement, branch-rule and activation-variable clicks. The bot could read environment protection but secret-name/variable APIs returned 403; setup is owner-confirmed, never inferred. No secret value was read or copied, no environment/access was changed, and no release was dispatched. The active 1.0.69 release session, run, worktree and installed Production runtime remain untouched. This repository has no DIRECTION.md; the Director's overall direction applies, including the spare-capacity admission recorded in the claim.

Code follow-ups recorded without starting implementation: #736 #749 #750

@shiny-code-app

shiny-code-app Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Another-provider review: Anthropic claude-opus-5-5 reviewed 5663dcb and then integrated 2e05ebe read-only. No blocking, high, or medium defect was reported. The first review's four low findings were addressed: documented reruns under the original approval; printed secret names for both environments and clarified populating both; reproduced and fixed six checker gaps; made TestFlight cancellation effective with !cancelled().

The second review found two remaining checker issues, now fixed in 92665c3: standalone secret jobs require successful guard dependencies, and approval counts/standalone routes are derived from parsed jobs. Mutation fixtures cover dropped standalone dependencies and always() bypass. The third low point—real-workflow lint runs in CI rather than inside the default local commit gate—is deliberately retained: the standalone lint command is documented in release docs and .github/github.json, has been executed locally on this head, and is required in CI. Putting it inside fixture copies of the commit gate would add a Python dependency and the entire workflow inventory to unrelated cache-namespace tests; a local gate alone is not claimed as the structural proof. No finding is declined as untested; this is a bounded, fail-safe gate-placement choice.

Final current-head inspection and another-provider review are running before the push. Previous 12-file inspection was GREEN with successful cleanup; broad existing test-file noise is tracked in #749 and the host-load watchdog race in #736. No release is dispatched, and owner access setup still waits on Chris.

@shiny-code-app

shiny-code-app Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Exact-head review completed: Anthropic claude-opus-5-5 read 92665c3682fb821b34dbaa36a855fb4e5294f50f; no blocking or medium findings. Current approval/failure/cancellation/setup boundaries were verified by source review. Final 12-file inspection is GREEN, zero findings, with helper-owned project cleanup complete.

Disposition of final low findings: calculated channel-environment access in a future newly merged workflow is reproduced and deferred to #750 without implementation; current workflows do not expose it and protected-main source changes remain the documented trust boundary. Real-workflow lint remains a separately executed/documented local command plus required CI step, for the gate/fixture coupling reason recorded above. Empty/non-mapping YAML already fails closed, so cosmetic traceback handling is declined; it is not described as a passing invalid-input test. No release or environment change was used to validate these claims. Live one-prompt behavior remains unproven until Chris completes setup and a later authorized release runs.

@shiny-code-app

shiny-code-app Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

The Owner decision replaces this PR's duplicate-store hand setup. This PR was already merged when the Supervisor routed that instruction to this session; the source correction is #751. It keeps all GitHub release secrets in existing release, with secretless reviewer gates in release-approval, including standalone workflows. Earlier release-channels/duplicate-secret/activation instructions are superseded. No release or environment change has been performed. The historical-rerun migration finding is recorded for the Director in direction#24.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant