feat(release): manifest-driven publish kit with non-disclosing preflight - #507
feat(release): manifest-driven publish kit with non-disclosing preflight#507randlee wants to merge 40 commits into
Conversation
QA Gate: FAILPR: #507 ( Reviewer results
Blocking finding — ATM-QA-001
The Remediation: drop the backslash-escaped inner quotes at line 45 to match the pattern already used elsewhere in the file. Deliverable completion: 8/11 (72.7%)Below 100% — does not meet the PASS bar per QA policy regardless of the blocking finding above. Independent verification of comp's self-reported validationReviewed independently rather than accepted as-is, per task instruction. req-qa's blocking finding was reproduced directly (not a reviewer tooling-gap artifact) via manual shell reproduction of the exact substitution pattern. Filed by quality-mgr per sprint_review gate. Full per-reviewer detail available on request. |
QA Recheck Gate: FAILPR: #507 ( Reviewer results
Status of originally-tracked fixed_findings
New blocking finding — ATM-QA-002
Remediation: update the test assertion to expect the corrected (bare-first-component) output, consistent with the manifest validator's enforced first-component safety and the fix's intended design. This is a test-only fix, not a design reversal — do not revert the template to the old quoted-first-component form, as that reintroduces the original invalid-Ruby bug. Deliverable completion: 7/7 (100%) per req-qa's requirements-section traceOverall gate is FAIL despite 100% requirements-section coverage, because a required regression test fails on live CI at the reviewed commit — never mergeable with red CI regardless of deliverable percentage. Filed by quality-mgr per sprint_review recheck gate. |
QA Recheck2 Gate: PASSPR: #507 ( Reviewer results
ATM-QA-002 — FIXEDFix commit Remaining open items (non-blocking, carried forward, not required for this PR)
Deliverable completion: 7/7 (100%)All required reviewers PASS, deliverable completion at 100%, CI fully green at the actual PR head SHA. Merge-ready. Filed by quality-mgr per sprint_review recheck2 gate. |
Authoritative sprint doc for the PR #507 follow-up: extend non-disclosing preflight through all publishing subagents, link publish-kit-requirements.md into top-level req/ADR docs, and add a written agent eval plan. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
QA Verdict — Sprint PUBLISH-KIT-AGENT-EVAL-HARDENING — FAILFollow-up to already-PASSed PUBLISH-KIT-PREFLIGHT-HARDENING (baseline Deliverables: 7/10 fully present (70%) — below the 100% threshold required for PASS. 2 blocking findings open. Reviewer verdicts
Blocking findings (both independently verified against the live worktree, not accepted on reviewer say-so)ATM-QA-001 (Blocking, req-qa) — Yet three normative docs affirmatively claim this exists:
And The Python side ( Remediation: Extend ATM-QA-002 (Important, req-qa) — sprint closure checklist item 5 ( ARCH-001 (Blocking, arch-qa, RULE-013) — Remediation: Flip both frontmatter fields to a terminal status now that their checklists are fully checked (or explain why they remain open). ARCH-002 (Important, arch-qa) — non-blocking coverage-depth note: Non-disclosure / scope guard: holds
CINot re-verified this round pending fix — reviewer-run fmt/clippy/test checks were clean at Merge readiness: not ready. 2 blocking findings across 2 independent reviewers, both independently confirmed against the live worktree. |
QA Recheck Verdict — Sprint PUBLISH-KIT-AGENT-EVAL-HARDENING — FAIL (narrowed significantly)Recheck of fix commit Both prior blocking findings: RESOLVED (independently re-verified)
Reviewer verdicts
Why this is still FAIL: one incomplete deliverableATM-QA-003 (Important, non-blocking on code, blocking on deliverable completion) — Required correction: Update Resolved reviewer disagreement (independently verified, not deferred to reviewer authority)Three reviewers converged on the same fact — Non-blocking carryoverARCH-002 — the deny-release gate's own bash control-flow ( Non-disclosure / scope guard: holdsConfirmed again this round — no credential values reach the new Merge readiness: not ready — one narrow doc-citation gap remains. Both structural blockers from the prior round are genuinely fixed. Recommend a fast one-line doc fix and immediate re-recheck (rust-qa-agent's this-round CI result can likely be cited directly rather than requiring a fresh run). |
QA-RECHECK (ATM-QA-003) flagged that the Validation Evidence section only cited the pre-fix commit. Cite the fix commit's independently-confirmed fmt/clippy/test/scripts results from both comp and quality-mgr's rust-qa-agent. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
QA Verdict — Sprint PUBLISH-KIT-AGENT-EVAL-HARDENING — PASSSecond recheck of docs-only fix commit Reviewer verdicts — all 4 PASS
Full sprint history now closed
CI: greenAll 12 checks pass at head SHA Non-disclosure / scope guard: holdsReconfirmed no credential values reach any new code path; Deliverable completion: 5/5 (100%). 0 blocking findings. CI green. Merge-ready pending human/team-lead approval per standing policy. |
QA: PUBLISH-KIT-AGENT-EVAL-FIX-001-QA — FAILReviewed (as dispatched): fix commit Reviewer results
Independent verification (quality-mgr)Confirmed directly against the worktree and
VerdictFAIL — not on the merits of EVAL-001/002/003 (those are genuinely fixed), but because:
Recommendation: freeze the branch, correct the EVAL-003 fix-description to cite |
QA: PUBLISH-KIT-AGENT-EVAL-FIX-001-QA-2 — PASSReviewed: commit Reviewer results
Independent verification (quality-mgr)
VerdictPASS — all three EVAL findings (EVAL-001, EVAL-002, EVAL-003) genuinely fixed and independently re-verified by all 4 reviewers plus quality-mgr directly. The prior round's two process defects (branch drift mid-review, wrong path citation) are both resolved: the branch is stable and the citation now matches the real shipped path. Merge-ready pending explicit human/team-lead approval. |
Critical review QA: PR #507 gap vs per-channel-agent direction — commit
|
QA: PUBLISH-KIT-CHANNEL-REWORK — commit
|
QA Verdict:
|
QA Verdict:
|
QA Verdict:
|
QA Verdict:
|
QA Verdict:
|
QA Verdict — d0facaf (PR #507) — FAIL (Blocking)Scope: Recheck of Reviewer results
Independent verification (quality-mgr, closing req-qa's two gaps)
Gate reasoningPer standing policy, CI status does not gate the QA↔dev iteration loop in the abstract — but this is not an abstract "CI is red" flag. It's a concrete, root-caused, reproducible functional regression in the exact code path this commit changed, independently confirmed by direct test execution. That makes it a real Blocking finding, on par with req-qa/arch-qa's own code-level findings, not a CI-polling concern. Required fix: Update Non-blocking carryover
Merge-readiness: Blocked. Requires the render.rs fixture fix, a green |
QA Verdict — 325183c (PR #507) — PASSScope: Recheck closing the sole Blocking finding from the Verification (quality-mgr, direct)
No prior req-qa/arch-qa findings were reopened by this fix (mechanical fixture correction, no template/manifest/doc changes) — direct verification is sufficient; no reviewer re-dispatch needed this round. Merge-readiness: Code/test gate clear. Pending: platform |
QA Verdict — f26cc8a (PR #507) — FAIL (Blocking)Scope: New deliverable — publisher output-contract fix for a Luna durable-eval-discovered ambiguity (skipped checks required to be tagged Blocking finding (quality-mgr, independently confirmed)
Root cause: comp's claim (" Required fix: update Important — converged across 3 independent reviewers (arch-qa, simplification-reviewer, req-qa)
Required fix: add Important (req-qa)
Required fix: add a Validation Evidence entry for Minor
Clean
Gate reasoningOne genuine, independently-executed test regression (Blocking) plus a 3-way-converged unresolved cross-document contract gap and a stale sprint-doc closure record (both Important) put this well below the 100% deliverable-completion bar required for PASS. Merge-readiness: Blocked pending: (1) fix the stale pytest assertion and confirm |
QA Verdict — a847d58 (PR #507) — PASSScope: Fix-round closing all 3 findings from the Reviewer results
Independent verification (quality-mgr)
Non-blocking follow-up (Important, arch-qa, independently confirmed)
Merge-readiness: Code/test/doc gate clear. Pending: platform |
QA verdict: PR #507 @
|
QA verdict: PR #507 @
|
QA verdict: PR #507 @
|
QA verdict: PR #507 @
|
QA verdict: PR #507 @
|
Summary
release_trackselection (allstableentries for stable tags; onlyprereleaseentries for prerelease tags), and per-formulabinaries. Each selected formula is rendered, Ruby-validated, and committed.test_binarydefaults to the first binary; legacybinaryentries normalize for vendor compatibility.No tag, dispatch, or publication was performed by this PR.
Validation
python3 -m pytest scripts/tests/test_release_artifacts.py -q— 36 passedjust testgit diff --checkjust lint— locally blocked by the pre-existingcargo-denyCLI incompatibility (--configis rejected); this PR does not change that tooling.