Skip to content

fix(autorelease): email publish runs, set Latest, and resume finalize - #164

Merged
loadinglucian merged 2 commits into
mainfrom
fix/autorelease-final-gaps
Sep 29, 2026
Merged

loadinglucian merged 2 commits into
mainfrom
fix/autorelease-final-gaps

Conversation

@loadinglucian

@loadinglucian loadinglucian commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Publish runs never sent their digest email, because the watcher dispatches them with GITHUB_TOKEN and GitHub starts no workflow_run for those, so the publish workflow now calls the email workflow from its own last job and the watcher keeps workflow_run. Publication now sets make_latest explicitly (true only for the highest published version, revisions included), a finalize rerun reuses a record already on main or withdraws what an earlier attempt left and reports recorded from main, and every record merge asserts Protected controls.

It also fixes the literal \n in the sealed-patch PR body, forces the tracking-ref fetch before both --force-with-lease pushes, drops the unused repair: and auth_failure: action-key families, including from the verifier's cross-repo filename check, which pairs with Bigpixelrocket/mise-php#35 (the pipeline is safe in either merge order, but verify-autorelease-system from php-bin main fails against mise-php#35 until this PR is in), corrects the stale mise-php snapshot digest in the admin evidence, and makes the failing-install test check the refused copy. No recipe input changes, so nothing is rebuilt.

Summary by CodeRabbit

  • New Features
    • Published releases are now marked as the latest release only when their version is newer than other eligible releases.
    • Email digests are sent after watcher and publish attempts, with retries for temporary delivery failures.
  • Bug Fixes
    • Re-running a publish attempt now avoids creating duplicate release records and cleans up leftover release requests before retrying.
    • Release records are checked against the published version and available asset details before being treated as complete.

Publish runs are dispatched with GITHUB_TOKEN, so GitHub never started the
workflow_run digest for them. The publish workflow now calls the email
workflow from a final always() job with the conclusion its jobs reached, and
publish is no longer a workflow_run trigger, so each run attempt is emailed
once.

Publication sets make_latest explicitly: true only when no published release
sorts above the version, comparing major, minor, patch and revision
numerically, so a rebuild of an older branch no longer takes the Latest badge.

A finalize rerun now recognizes a record already on main for exactly this
release, withdraws a PR or branch an earlier attempt left on its run-scoped
branch, and reports recorded from main whenever the attempt did not merge.
Every single-record merge asserts Protected controls.

Also: the sealed-patch PR body gets real newlines, both force-with-lease
pushes fetch their tracking ref with a forced refspec, the unused repair and
auth_failure action-key families are removed, the stale mise-php snapshot
digest in the admin evidence is corrected, and the failing-install packaging
test asserts the refused copy.
@loadinglucian loadinglucian self-assigned this Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: dac94a74-fe3b-454c-b1a1-97f35c8bef64

📥 Commits

Reviewing files that changed from the base of the PR and between 2b3add3 and 5a105b5.

📒 Files selected for processing (3)
  • .github/workflows/autorelease-email.yml
  • AUTORELEASE.md
  • tests/test_autorelease.py

Limit details: You’ve used all 5 included reviews currently available. Your 55 included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The changes update release ordering and event-record validation. Publish finalization handles existing records and stale run-specific pull requests. Publish attempts invoke the email workflow directly, while watcher completions continue to trigger it through workflow events.

Changes

Auto-release lifecycle

Layer / File(s) Summary
Release ordering and Latest flag
autorelease/_state.py, scripts/publish-release, tests/test_autorelease.py, AUTORELEASE.md
Release ordering compares numeric major, minor, patch, and revision values. Draft publication sets GitHub’s Latest flag based on that ordering.
Release-record and action-key validation
autorelease/_state.py, autorelease/control.py, autorelease/_validation.py, autorelease/verify.py, schemas/autorelease-plan.schema.json, docs/autorelease-admin-evidence.json, tests/test_autorelease.py
The release-recorded command checks completed records against the action key, version, and optional asset digests. Validation and schema rules no longer accept repair or auth_failure action keys.
Rerun-safe workflow finalization
.github/workflows/autorelease-publish.yml, .github/workflows/autorelease-implement.yml, .github/workflows/autorelease-watch.yml, AUTORELEASE.md, tests/test_autorelease.py
Publish finalization reuses a matching record on main or replaces a prior attempt’s pull request and branch before creating a new one. Workflow branch fetches and protected-control checks are updated.
Completion email routing
.github/workflows/autorelease-email.yml, .github/workflows/autorelease-publish.yml, AUTORELEASE.md, tests/test_autorelease.py
The email workflow handles watcher completion events and reusable calls. It retries transient delivery failures with an idempotency key for each run attempt.

Packaging failure test

Layer / File(s) Summary
Packaging failure assertion
scripts/test.sh
The fixture reports the failed copy operation. The test checks for that error and verifies that no archive-creation message appears.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~50 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant PublishWorkflow
  participant WatcherCompletion
  participant EmailWorkflow
  PublishWorkflow->>EmailWorkflow: Call with run metadata and conclusion
  WatcherCompletion->>EmailWorkflow: Completion event with run metadata
Loading

Merge Risk: ⚪ Minimal · up to 5a105

No actionable merge-blocking risk is established by the reviewed changes; the inspected fallback and email-routing behavior match their stated contracts.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 14.71% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 34 functions across 6 files. (2 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the primary changes: publish-run email delivery, release Latest handling, and finalize rerun behavior.
Description check ✅ Passed The description provides a detailed summary of the changes, their rationale, compatibility context, and the fact that recipe inputs are unchanged. It omits the template's explicit Verification and Sec…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 14.71% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 34 functions across 6 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Usage-based review receipt

Note

This review was completed with usage-based billing: files reviewed beyond your plan's included limits are billed at $0.25/file. View usage-based billing.


Comment @coderabbitai help to get the list of available commands.

@loadinglucian
loadinglucian merged commit 5d37091 into main Sep 29, 2026
4 checks passed
@loadinglucian
loadinglucian deleted the fix/autorelease-final-gaps branch September 29, 2026 14:44
loadinglucian added a commit that referenced this pull request Sep 29, 2026
* origin/main:
  fix(autorelease): email publish runs, set Latest, and resume finalize (#164)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant