ci: adopt the shared release flow (candidate / direct settle / publish) - #153
Conversation
Mutation testing - PASSNothing to test: no viable mutants were generated. |
Replaces hand-made tags and Releases with the org release pipeline from megaeth-labs/.github: a dispatched candidate PR bumps salt/Cargo.toml (and Cargo.lock via cargo update --workspace) and drafts CHANGELOG.md; merging cuts release-vX.Y.Z; a settle PR onto that branch finalises the entry; its merge creates the annotated tag and the GitHub Release. No upload targets: salt is consumed by git tag. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013eLFMaDpEwgDzyDBzCQzLH
Mutation testing - PASSNothing to test: no viable mutants were generated. |
Performance Benchmark ComparisonCompared Detailed Comparison
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
flyq
left a comment
There was a problem hiding this comment.
What it checked
- Template fidelity — diffed the three stamped workflows against megaeth-labs/.github/workflow-templates/release-{candidate,settle,publish}.yml. Only the intended deltas: $default-branch→main, VERSION/plain→salt/Cargo.toml/toml, the added setup-rust-toolchain step, bump_command, and the dropped commented-out settle_mode: direct. No accidental drift.
- bump_command: cargo update --workspace — tested empirically on a clean archive of HEAD: bumping salt/Cargo.toml to 1.0.7 moved Cargo.lock:995 from 1.0.6 → 1.0.7 with the other 72 deps untouched. --workspace correctly avoids churning the rayon = "*" requirement and the [patch.crates-io] git pins.
- version_file: salt/Cargo.toml — the toml regex ^version\s*=\s*" is line-anchored and first-match, so it hits [package] version at line 3; every dependency version = in that file is inline inside { … } and can't shadow it. banderwagon/ipa-multipoint/salt-macros are all still at 0.1.0, so salt is genuinely the only versioned crate.
- Seed CHANGELOG.md — prose with no ## sections falls through to the append branch, so v1.0.7 lands after the header; v1.0.8+ inserts above the first ## , newest-first. The changelog-copy step correctly no-ops on the first release since git show v1.0.6:CHANGELOG.md fails.
- Branch-name contracts, token plumbing, CI interaction — prefixes line up between the workflow ifs and what the actions produce; every privileged op runs on the app installation token so permissions: contents: read isn't under-scoped; mutation.yml already skips cleanly on a diff with no salt/src/** changes, so a bump-only candidate PR won't sit on the 330-minute gate.
Two things it considered and deliberately didn't raise: @main on the three shared actions (org policy — .github's README mandates it, so it's a tradeoff not a defect) and the missing concurrency: group (the templates omit it too; the only failure needs operator error plus tight timing).
Two notes for the PR body
- Prerequisite 4 ("depends on megaeth-labs/.github#25 for bump_command") is already satisfied — bump_command is live in action.yml on .github@main, wired through a Run bump command step. That line can be dropped.
- Unverified pre-flight: the cut job creates release-vX.Y.Z via POST /git/refs. Worth confirming the planned release-* ruleset doesn't enable Restrict creations, or that mega-maxwell is a bypass actor for creation — otherwise cut fails after the candidate PR has merged. The reviewer couldn't check this since the rulesets don't exist yet.
…lement Stamps the current org templates: candidate PR (version in salt/Cargo.toml, Cargo.lock via `cargo update --workspace`), cut, direct settlement gated by the `release` environment and an admin dispatcher, and the PR-mode publish workflow as the fallback. GitHub Release only; no publish targets. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 191554dd99
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| concurrency: | ||
| group: ${{ github.workflow }}-cut | ||
| cancel-in-progress: false |
There was a problem hiding this comment.
Avoid dropping queued release cuts
When three candidate PRs are merged while the first cut job is still running, the second job becomes pending and the third cancels and replaces it: cancel-in-progress: false protects only the running job, while GitHub permits only one pending job per concurrency group (GitHub concurrency documentation). Since every version shares this fixed group and pull_request.closed is not emitted again, the canceled candidate never gets its release-vX.Y.Z branch automatically; use per-release groups or another queue that preserves every cut event.
Useful? React with 👍 / 👎.
Installs the org release pipeline (megaeth-labs/.github) in salt, in the shape the other migrated repos use: trunk-first candidate, direct settlement gated by the
releaseenvironment, GitHub Release as the only publish target.release-candidate.yml: dispatch with a version → the app bumpssalt/Cargo.toml(the only versioned crate; the other three workspace members are internal path dependencies at 0.1.0), refreshesCargo.lockwithcargo update --workspace, drafts theCHANGELOG.mdentry from merged PR titles, and opens the candidate PR; merging it cutsrelease-vX.Y.Z.release-settle.yml: dispatch with the version and the release-branch tip → waits for thereleaseenvironment's reviewer, checks the dispatcher is an admin, commits the dated changelog entry to the release branch, creates the annotatedvX.Y.Ztag, and publishes the GitHub Release with the entry as notes.release-publish.yml: only serves PR-mode settlement; dormant here.CHANGELOG.md: new, preamble only; the first candidate fills it.Repository setup, done alongside this PR:
release branchandrelease tagrulesets (copies of mega-agents':release-*requires a reviewed PR,v*tags can only be created by the app or an admin, both with the Maxwell app as bypass actor), and thereleaseenvironment (reviewer Troublor, self-review allowed, deployments frommainonly). Nopublishenvironment and noon-release.yml, since nothing is uploaded anywhere.Previous releases here were hand-made tags with auto-generated notes (latest v1.0.6, a lightweight tag). From the next version on, the pipeline makes them; nothing legacy to remove.
🤖 Generated with Claude Code