Skip to content

Complete the published v1.0.0 tag/Action replay after the ordinary CI pin repair #570

Description

@pengfei-threemoonslab

Remaining work after publication — 2026-09-14

The original ordinary-CI pin-selection defect is fixed by #616 and shipped in v1.0.0. Installing the public wheel (d34012cad8164a8b9c092ad3512e4b15ec36989b330f7ce6c60c13156babd771) and generating normal CI selects bace7c1871834e0b3eb98e6f60c0627725c53a59 and package 1.0.0. #777 updated current source/documentation pins.

What is still unproven against the literal acceptance below is the post-publication execution of the real tag/Action. Smoke 34900819498 exercised the candidate before publication; the post-publication comment records the PyPI/local replay and pin resolution. Both are useful; neither is evidence of a new post-publication hosted Action run.

Acceptance for closure

P1 in the first post-release integration wave under #778. This observation does not block the supported local, nonblocking #653/#571 pilot. #781 is a distinct defect in optional bundled prompts/recipes; it does not reopen the fixed ordinary CI renderer.

Original defect and implementation record (historical)

Selected candidate scope — 2026-09-11

The owner selected repository-independent advisory host-review readiness (#643) before adoption expansion. This issue remains required: validate the exact candidate in its real distribution channel, including post-publication download and actual Action replay. Qualification and independent signing are additional obligations for the qualified channel, not evidence that a synthetic preview smoke can manufacture. Preserve applicable publication integrity controls in either channel.

Problem

The source-tree repair for #506 makes the generated Action ref resolvable, but a frozen release wheel carries that previous-release constant permanently. A user installing the new release can get an older engine in the CI workflow it generates.

Delivery and hosted evidence — 2026-09-09

#616 was merged after subsequent review fixes at 59eae9194fd02a591afa3d6a350457e7d0c50552 (final PR head 74726e18a22ab2bf99fe569a3019bd8fc29ecf30). Its final-head CI, Shipgate and self-dogfood runs passed. #614 subsequently landed the host-discovery contract; current main for the evidence below is ed97340226dd85ba22693c333004be2d06255d23.

The first actual Release Engine Smoke run 34435280857 completed successfully on that exact main commit. Both candidate and downstream jobs passed. The workflow exercised the real composite Action, not only a local script replay. Its uploaded wheel and reports were downloaded and inspected:

  • package 0.16.0, runtime contract 33; embedded source commit and generated Action ref both ed97340226dd85ba22693c333004be2d06255d23;
  • wheel SHA-256 42e86430c6a05a756f5e5fe1dcb9963a5186ffd808dfda657d9896258c93094d, matching the actual downloaded bytes; WHEEL metadata records the locked hatchling 1.32.0 backend;
  • installed CLI and Action have identical full engine identity (engine_distribution_sha256: sha256:6c1f4dc1edf5da312021e2a249b892ed5562ae7fc67c85a84761e0bb113708da), equal compared capability results and the expected blocked refund case with SHIP-ACTION-DESTRUCTIVE-ROLLBACK-MISSING;
  • local_and_action_agree: true, qualified: false, qualification_claim: "none: synthetic distribution smoke only" in the actual distribution artifact.

This replaces the earlier default-branch dispatch 404 as the current hosted-smoke status. The older local hash 951f49f9… remains tied to its old commit and, as the subsequent review established, hatchling 1.31.0; it is not the release-backend artifact and is not relabeled as this run.

Keep #570 open. This proves the merged mechanism on the named unqualified development candidate. The actual frozen candidate needs its own pre-publication run and unchanged bytes through the publication path selected in #648; the real published-tag/download observation remains unperformed. For qualified publication, qualification and signing must preserve the same bytes too; no missing qualified evidence is counted as complete. No release was published or signed by this smoke.

Evidence — main 452bdeb

  • src/agents_shipgate/published_release.py:18–20 says the published-version constants are updated after the tag, never before. They currently name v0.15.0 / contract 10.
  • src/agents_shipgate/cli/discovery/ci_workflow.py:49–53 always uses that constant unless an operator supplies an override.
  • action.yml:341–344 installs the Action checkout by default, so the old ref selects the old engine.
  • A later main-only constant update cannot change the already qualified/signed/published wheel's bytes.

This is a distinct lifecycle gap from #506's nonexistent-tag failure. A source/preview must avoid an unpublished release ref; an installed final release must not silently select a previous contract that does not meet the required floor.

Required implementation

Give workflow pin selection an explicit, reproducible release-provenance rule. Distinguish development/preview builds from an actual final distribution without a runtime network lookup, clock-dependent answer or post-signing wheel rewrite. Preserve the existing explicit override and honest contract-floor diagnostics.

Design the validation order so it does not require a nonexistent tag before publication: before the tag, exercise the candidate Action via its immutable commit with the exact candidate wheel in a disposable downstream repository; after publication, exercise the real tag and downloadable wheel. A resolvable old pin is insufficient if it cannot evaluate the reviewed capability class.

Acceptance

  • Installing the final candidate wheel and generating CI selects the intended release engine/contract once that release is published.
  • Source checkouts and unqualified previews retain a resolvable, accurately described path; no fabricated preview tag or future-tag default.
  • The downstream smoke records installed version, runtime contract, Action ref and engine output on a supported capability change; local and CI coverage agree.
  • The exact wheel hash stays unchanged through the actual selected publication path; validation never “fixes” a published wheel. Qualified publication additionally preserves those bytes through qualification and signing.
  • Pre-publication candidate and post-publication tag smoke are both specified and exercised by the release owner before declaring rollout complete.

Sequencing

P1 selected v1.0 distribution blocker under #643. Coordinate #569 compatibility and #648 publication before final source/wheel freeze. The existing preview can be tested now; selecting a stable advisory 1.0 tag requires the actual #648 contract to be implemented first. Today's qualified v* path still requires #509/#510 and their real evidence. A roadmap decision does not bypass it. #506 remains closed for its delivered source-tree repair.

Activity

  1. added this to the v1.0 milestone on Sep 8, 2026
  2. added
    bugSomething isn't working
    P1Next after P0; blocks other work or ships a misleading result
    area:initinit / detect / manifest generation
    area:releaseRelease pipeline, packaging, and safety qualification
    on Sep 8, 2026
  3. pengfei-threemoonslab commented on Sep 9, 2026

    @pengfei-threemoonslab
    ContributorAuthor

    Implementation routing at main 15b317a36f54506f2cd68bbfe922fde947b535b1:

    An independent design review confirmed the frozen-wheel failure and selected an explicit candidate-build source record: record the verified complete source commit in the wheel, generate advisory CI against that immutable Action SHA, and keep the existing published-release fallback for ordinary source/preview builds. A present invalid candidate record must refuse CI generation. The record must participate in engine identity and in the candidate/rebuild byte comparison; nothing rewrites the qualified wheel after signing. The Action needs paired local-wheel/path-and-SHA256 inputs so the pre-publication smoke can execute the exact candidate bytes rather than reinstalling an older package or rebuilding the source.

    The complete implementation also requires wiring this mode into .github/workflows/release-verify.yml. Preflight of the full concrete file plan returned control.state=human_review_required, all permissions false, because that file matches protected .github/workflows/*.yml. Per the current AGENTS.md preflight routing contract, no implementation files were edited. This is a protected-workflow human route, not a failed test or a completed distribution fix; independent coding-agent review cannot clear it. The plan was not narrowed to omit the required release-workflow consumer.

    After the human-owned route is resolved, implement and test the build record, selection/invalid-record handling, exact-wheel Action install, provenance validator and release-workflow integration together. Validate full/shallow and no-Git/dirty builds, real installed-wheel generation, digest mismatch refusal, and local/CI capability evidence. Actual pre-publication Action-SHA/candidate-wheel smoke and post-publication tag/downloaded-wheel smoke remain release-owner evidence. #570 stays open and blocks final source/wheel freeze; no tag, release or qualification claim was made.

  4. pengfei-threemoonslab commented on Sep 9, 2026

    @pengfei-threemoonslab
    ContributorAuthor

    The implementation is published in #616 at 4583be1; independent PR review loop 1 is in progress. A real stamped wheel built from this exact clean commit and installed in a fresh environment now generates the matching Action SHA plus package version, and its installed CLI half completed the disposable refund-PR smoke. Exact local Action-step comparison is running separately.

    The GitHub-hosted manual smoke was actually attempted on the PR branch and returned HTTP 404: workflow release-engine-smoke.yml not found on the default branch. It has not run remotely. Automatic approval review separately rejected adding a PR trigger to the protected workflow; that rejected change is absent. The concrete PR can be reviewed, but current verifier permissions retain human merge authority. This issue remains open for the hosted pre-publication observation and the eventual unchanged generated-workflow/published-tag/download observation; no synthetic smoke is counted as qualification.

  5. pengfei-threemoonslab commented on Sep 9, 2026

    @pengfei-threemoonslab
    ContributorAuthor

    Implementation checkpoint — final PR #616 head 6788be9069f2f7f008f1cb688fb735588bcebbc1.

    The candidate build record, paired exact-wheel Action installation, generated Action SHA/package-version selection and manual distribution smoke are implemented. All three permitted independent PR review/address rounds are complete; the second round's sole test-reference correction was independently rechecked and resolved, and the final roadmap review found no actionable issue.

    A new wheel built from this exact head completed a local installed-CLI/checked-in-Action replay in a disposable downstream clone: identical full engine identity and contract 32, with the expected blocked refund result. Wheel SHA-256: 951f49f9132aac593fe2b44cc8c95db65e9679b7c1afd2677b4f5a8ec530135c. This evidence is synthetic and unqualified. The final-head CI run is 34409146965; its complete suite/coverage result is still pending, while Shipgate, self-dogfood, Windows launcher and clean-checkout launcher checks have passed.

    Keep this issue open. Current verifier control is review_publishable, denying merge/completion. The actual manual hosted dispatch returned 404 because the new workflow is absent from the default branch; it must be exercised after human review/merge. The later real-tag/downloaded-package observation must use the unchanged generated workflow after publication. No local replay substitutes for those observations or for #512/#509 qualification. The additional PR-trigger edit was rejected by automatic approval review and is absent. Newly observed fixture-summary overflow is separately deferred in #617; the old shared corruption-drill defect remains #615.

  6. pengfei-threemoonslab commented on Sep 9, 2026

    @pengfei-threemoonslab
    ContributorAuthor

    Final CI is now complete at 6788be9069f2f7f008f1cb688fb735588bcebbc1: all applicable tests and aggregate coverage passed. See the final PR validation record for exact runs and current control. The remaining human-merge, hosted-smoke and real-publication observations above are unchanged; #570 remains open.

  7. pengfei-threemoonslab commented on Sep 10, 2026

    @pengfei-threemoonslab
    ContributorAuthor

    The first actual hosted distribution smoke has now passed: run 34435280857, source ed97340226dd85ba22693c333004be2d06255d23. I downloaded and checked the uploaded wheel and reports, including the locked hatchling 1.32.0 backend, source/Action SHA, full matching engine block, contract 33 and expected blocked refund result. The current issue body records the exact wheel digest and remaining acceptance.

    This is evidence from the real composite Action on GitHub, replacing the earlier default-branch 404. It remains an explicitly unqualified development-candidate smoke, not the final v1.0 qualification or post-publication test. #570 stays open; the final frozen candidate must be exercised again and its bytes retained through signing/publication.

  8. pengfei-threemoonslab commented on Sep 11, 2026

    @pengfei-threemoonslab
    ContributorAuthor

    Current internal candidate replay — 2026-09-11

    Release Engine Smoke 34651534187 passed both jobs on CI-accepted main 7a4adda4caab5ab5abf54747d4991a225eff1547. This is an internal development candidate, following the owner's ordinary advisory 1.0 publication decision; no outsider-facing preview or release was published.

    • Downloaded wheel: agents_shipgate-0.16.0-py3-none-any.whl, SHA-256 f288bcbb5517eae3293576645544055f9ca4d4b2de0ca56684ae42cd20a3d39b; WHEEL generator hatchling 1.32.0.
    • Embedded source and actual Action ref both name that commit; runtime contract 33, report 0.43. The installed CLI and actual composite Action agree, including engine distribution identity sha256:87889269f661e752f2547554418aae3efd4e3ebfd8bdec1562d6c55efe6fc73d and the expected blocked refund case. Uploaded distribution-evidence.json records local_and_action_agree: true, qualified: false.
    • Installed the downloaded wheel with ordinary pip dependency resolution into a fresh local Python virtualenv, outside the source checkout. In a disposable Git repository containing only a Claude Code permission file, agents-shipgate diff --json reports a comparable unchanged surface with zero rows (3.15 seconds). After changing Bash(pytest *) to Bash(*), the same command reports two grant-change rows (1.57 seconds). No manifest, baseline, init, or policy declaration was needed. These local timings are observations, not a performance qualification.

    The two host comparisons are synthetic first-value checks, not the 30-repository #660 corpus, user adoption evidence, or a safety qualification. This wheel predates the pending #683 fix. The final frozen 1.0 candidate must repeat distribution checks and retain its bytes through publication; post-publication PyPI/tag replay and the stable advisory publisher remain open under #570/#648. Keep both issues open.

  9. pengfei-threemoonslab commented on Sep 14, 2026

    @pengfei-threemoonslab
    ContributorAuthor

    Post-publication replay — v1.0.0, 2026-09-14

    The released wheel's bytes were unchanged through publication, and its generated CI selects the released engine.

    Stage Wheel sha256
    Release Engine Smoke 34900819498 on bace7c18 d34012cad8164a8b9c092ad3512e4b15ec36989b330f7ce6c60c13156babd771
    Advisory rehearsal 34901034922, provenance identical_bytes same
    PyPI agents-shipgate==1.0.0 (the only file) same
    GitHub Release v1.0.0 wheel asset same

    A fresh virtualenv outside any checkout installed agents-shipgate==1.0.0 from PyPI:

    • --version reports Agents Shipgate 1.0.0; contract --json reports contract 39, report schema 1.0.
    • First value. A disposable repository widened .claude/settings.json from Bash(pytest *)/Read(src/**) to Bash(*)/Read(**)/WebFetch(*). agents-shipgate diff --base HEAD --json returned a comparable result with 5 rows in 1 second.
    • Generated Action ref. The installed package's _meta/release-source.json records source_commit: bace7c1871834e0b3eb98e6f60c0627725c53a59. ci_workflow._action_ref() returns that commit, not the wheel's older LATEST_PUBLISHED_VERSION (0.15.0). The commit is on main, identical to its tip, with action.yml present, so the pin resolves.
    • init --ci --write on the host-only replay repository wrote nothing, by design: "Host-only discovery does not need a manifest. No setup files were written." The Action ref was therefore checked from the installed package directly.

    Acceptance on this release:

    • Installing the final wheel and generating CI selects the intended release engine: the released source commit.
    • The exact wheel hash stayed unchanged through the selected advisory publication path; no validation rewrote a published wheel.
    • Pre-publication candidate smoke (34900819498) and post-publication download replay (above) were both exercised.

    Repository docs, examples and prompts still pin v0.15.0 until the follow-up pin PR merges. That does not affect what the published wheel generates.

    🤖 Generated with Claude Code

  10. changed the title [-]A released wheel permanently generates CI pinned to the previous release[/-] [+]Complete the published v1.0.0 tag/Action replay after the ordinary CI pin repair[/+] on Sep 15, 2026
  11. pengfei-threemoonslab commented on Sep 15, 2026

    @pengfei-threemoonslab
    ContributorAuthor

    Status — 2026-09-14. The post-publication hosted tag/Action replay is still not performed: the owner decided on 2026-09-14 to skip the hosted run for now. #780's recipe PR (#786) supplies the recipe and local evidence only; it is not the literal published-Action observation this issue requires, which remains open.

  12. pengfei-threemoonslab commented on Sep 22, 2026

    @pengfei-threemoonslab
    ContributorAuthor

    Post-publication hosted Action replay — published v1.1.0, 2026-09-22

    Owner decision, 2026-09-22: the published v1.1.0 Action and package are accepted in place of the literal v1.0.0 wording in this issue's acceptance. v1.0.0 was not run, and the issue body is unchanged. This is the same hosted run recorded on #780 (#780 (comment)); no second harness was built.

    Recorded provenance

    Item Value
    Tag resolution refs/tags/v1.1.0 → annotated tag 39514a0a4e2aa8c3bab7c41c46db0997b980c8a1 → refs/tags/v1.1.0^{} e3c6cb0c7657d9c53d4e29b2061d04dcf99a4e9b
    Action ref and resolved SHA ThreeMoonsLab/agents-shipgate@v1.1.0 → e3c6cb0c7657d9c53d4e29b2061d04dcf99a4e9b (9 runs). @e3c6cb0c7657d9c53d4e29b2061d04dcf99a4e9b → the same SHA (run 35774401670)
    Source SHA e3c6cb0c7657d9c53d4e29b2061d04dcf99a4e9b, from the runner's Download action repository line and the installed package's _meta/release-source.json
    Installed version agents-shipgate==1.1.0 from PyPI, installed with python -P -m pip install (Downloading agents_shipgate-1.1.0-py3-none-any.whl (2.6 MB)); tool.version 1.1.0
    Runtime contract 40 (verifier schema 0.20)
    Wheel digest sha256 038bdb4650d45d9c81996f60d33781b5671bfb57f006233f80e74db8a7377d33 (2,624,635 bytes). Not observed in the run (#855): no log line or artifact carries a wheel or engine-distribution digest. The value is PyPI's only 1.1.0 file (uploaded 2026-09-22T18:47:16Z, before the first run). It matches the v1.1.0 GitHub Release asset digest and a local download, whose 609 installed files match its RECORD
    Runs 10, all success; see the table

    Scenarios

    "Local 1.1.0" is the installed PyPI 1.1.0 CLI (diff --workspace <clone at the run's merge commit> --base <the run's base> --json), compared with verifier.json host_comparison as a whole ordered object.

    # Scenario PR Run Result Local 1.1.0
    1 Widening and deny → allow move 1 35773922210 ⚠ moved, ⚠ widened, coverage block, review question equal
    2 Second push to PR 1 1 35774315551 Same comment edited in place, no duplicate equal
    3 Narrowing Bash(npm:*) → Bash(npm test:*) 2 35774377665 narrowed, no ⚠ equal
    4 Remote MCP server 3 35774380269 ⚠ high / added, URL path redacted equal
    5 README-only 4 35774385937 Compact no-change status equal (0 rows)
    6 Invalid .mcp.json 5 35774387791 Unavailable: head_inventory_incomplete equal
    7 fetch-depth: 1 6 35774393068 Unavailable: shallow_history Differs, as expected: full history gives comparable, 4 rows; a depth-1 local diff refuses with exit 2
    8 Fork PR 9 35774429059 Read-only token, 403, review in job summary and artifact equal
    9 Import markers in the PR 7 35774396881 No marker in any log or artifact; PyPI install equal
    10 Full-SHA uses: ref 8 35774401670 Same commit as the tag; settings result equals scenario 1's equal

    Acceptance for closure

    1. Met under the owner's decision, with one caveat. The real published composite Action ran with the public PyPI release in a disposable public fixture. Tag resolution, source SHA, installed version, contract and run URLs are recorded above. The caveat: the wheel digest comes from PyPI, the release asset and a local download, not from the run itself (A shipgate_version Action run records no digest of the engine it installed #855).
    2. Met.
      • Supported capability-change results match the installed 1.1.0 CLI as whole objects (scenario 7 differs only because the local CLI refuses a shallow clone).
      • The tag convenience ref (@v1.1.0) and the immutable SHA ref both resolved to e3c6cb0c.
      • The generated default is the immutable SHA. With the installed 1.1.0, init --minimal --ci --write writes uses: ThreeMoonsLab/agents-shipgate@e3c6cb0c7657d9c53d4e29b2061d04dcf99a4e9b with shipgate_version: "1.1.0". That holds only in a repository without an existing Shipgate workflow; with one present it reports skipped_cross_reference. Host-only init --ci [--write] writes nothing, by design.
      • No wheel was rewritten or republished: PyPI has one 1.1.0 file, with the same digest as the release asset.
    3. Met with this record. It is linked from Epic: v1.0 M3 delivery record — published; final Action replay remains #646 and Epic: advisory v1.0 delivery record — finish the published Action replay #643. The defects reproduced in this run each have their own bounded issue: Host-only Action runs print an empty status, zero severity counts and nonexistent artifact paths in the job summary #854, A shipgate_version Action run records no digest of the engine it installed #855, Fork-fallback job summary renders the limitation as raw text and prints '## Agents Shipgate' literally #856, control.reason counts rows but calls them changes ('4 change(s)' beside '2 changes (from 4 rows)') #857, An unrelated added allow rule splits a widened replacement into 'added' plus a misleading 'removed' #858, Workflow capability rows open with an unlabelled aggregate access value ('write, ...') #859.

    For the historical acceptance list in the body, not re-established for 1.1.0 here:

    • "Generated CI selects the intended release engine" holds for 1.1.0.
    • "Exact wheel hash unchanged" is shown only between PyPI and the release asset. The 1.1.0 pre-publication candidate hash was not checked.
    • For "pre-publication candidate and post-publication tag smoke", only the post-publication half is evidenced here. The 1.1.0 pre-publication half is not established by this record.

    Closing under the owner decision above: the published tag/Action replay this issue exists for is performed and recorded here. The one caveat, a wheel digest the run does not itself record, is tracked in #855.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1Next after P0; blocks other work or ships a misleading resultarea:initinit / detect / manifest generationarea:releaseRelease pipeline, packaging, and safety qualificationbugSomething isn't working

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions