Skip to content

release: attest bounded v1.5 canary equivalence - #1049

Merged
jeffhuber merged 1 commit into
mainfrom
codex/v150-canary-equivalence
Sep 19, 2026
Merged

jeffhuber merged 1 commit into
mainfrom
codex/v150-canary-equivalence

Conversation

@jeffhuber

Copy link
Copy Markdown
Contributor

Problem and result

The accepted v1.5.0 paid completion and cancellation canaries used immutable candidate 3ac84902, while the later release-closeout source changed only audit publication, release-readiness, workflow templates, packaged release docs, and metadata. The existing qualification contract requires exact final-candidate bytes, but the authorized provider campaign has no remaining recovery creates.

This PR adds a narrow v1.5.0 carry-forward rule and a fail-closed compare-canary-surface attestation. It requires ancestor lineage, identical wheel inventory and metadata headers, byte-identical operational members, a closed ten-member audit/release/docs allowlist, exact-final-candidate private acceptance, audit-receipt replay, and count-preserved campaign evidence. Any Slack, supervisor, provider, CLI, persistence, state, dependency, entry-point, unknown, or added member change refuses carry-forward and requires newly authorized canaries.

The current retained-candidate comparison passes with exactly ten changed members and 335 byte-identical members. This PR does not publish, tag, invoke Slack, or create a provider session. After merge, its own final candidate must be built once and compared directly with the retained canary candidate.

Validation

  • 25 passed, 76 subtests in tests/test_release_v150.py
  • 363 passed, 945 subtests in release-hygiene coverage
  • 70 passed, 378 subtests in release identity and v1.4.2 regression coverage
  • 40 passed, 297 subtests in audit-publication and package-lineage coverage
  • Ruff and git diff --check
  • migration release-readiness --json: PASS
  • Real retained-candidate comparison: PASS, 10 changed / 335 unchanged wheel members

Supports #920 and #923.

@gitar-bot

gitar-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your team has used its included automatic processing for this billing period (headroom scales with your seat count). You can still comment "Gitar review" to run one anytime, and automatic reviews resume on their own by October 1. Add seats for more headroom.
Learn more

Code Review ✅ Approved

🔴 High risk

Adds v1.5.0 canary equivalence attestation with a narrow carry-forward rule and fail-closed comparison, requiring exact byte-identity on operational members and a closed allowlist of audit/release/docs changes. Comprehensive test coverage validates the retained-candidate comparison (10 changed / 335 unchanged members) and release-hygiene requirements. No issues found.

Review coverage

Rules No rules evaluated

Functional validation Not enabled · Set up

Options

Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@github-actions

github-actions Bot commented Sep 19, 2026

Copy link
Copy Markdown

Codex audit (merge-authority lane)

Head SHA: 0673d4e803b32c72746bfa36b367cf102603338e
Verdict: PASS
Review details remain in the local audit artifact.
Publication workflow: .github/workflows/local-audit-publication.yml at 5dac2a48839b3111441aca9a7f61b1a4e91ac445

@github-actions

github-actions Bot commented Sep 19, 2026

Copy link
Copy Markdown

Claude audit (merge-authority lane)

Head SHA: 0673d4e803b32c72746bfa36b367cf102603338e
Verdict: PASS
Review details remain in the local audit artifact.
Publication workflow: .github/workflows/local-audit-publication.yml at 5dac2a48839b3111441aca9a7f61b1a4e91ac445

@jeffhuber
jeffhuber enabled auto-merge (squash) September 19, 2026 14:09
@jeffhuber
jeffhuber merged commit 197c0c6 into main Sep 19, 2026
27 checks passed
@jeffhuber
jeffhuber deleted the codex/v150-canary-equivalence branch September 19, 2026 14:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant