fix(release): prepare immutable wheel publication for retry-stacking repair - #1229
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedNext included review available in 21 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (8)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (11)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough구조화 합성의 429 응답 처리와 후보 재시도 동작을 변경했습니다. 릴리스 workflow는 재현 가능한 Python wheel을 빌드하고, wheel 및 SHA-256 manifest를 릴리스 자산으로 검증·게시합니다. 릴리스 노트에는 GitHub 본문 길이 제한 처리를 추가했습니다. Changes구조화 합성 429 복구
검증된 wheel 릴리스
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to No identified issue blocks merging this preparation change. Publication remains a separate step with its stated prerequisites. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The changes add useful checks before publication and bound provider retries. Two conditional risks remain: callers of one server can affect one another through shared cooldown state, and a release can become public before its final asset verification finishes. Neither is established as an active exploit. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The 0.2.0 CHANGELOG section renders to 125,639 characters, over GitHub's 125,000-character Release body cap. The publish job pushes the tag before `gh release create`, so the HTTP 422 would strand a tag-only publication that fails again on every resume. Cut an oversized section on a line boundary and link the complete CHANGELOG.md at the exact release commit. Refs #1083. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0133Ho5SSJztqLorCccrvJcy
|
@coderabbitai review |
|
|
@coderabbitai review |
|
Scope
Prepare the canonical owner release path for Issue #1083. This PR is stacked on #1209 so its release changes can be reviewed separately from that PR's CI and runtime repairs.
0.2.0Python wheel from the exact release commit, require two byte-identical builds at that commit's fixed timestamp, record its SHA-256 digest, and carry both into the existing immutable GitHub Release publication flow.uvbuild and install check.Local verification
uv sync --python 3.12 --locked --extra api --extra db --extra queue --group dev --group native-builduv run --no-sync maturin develop --locked --release --features pyo3/extension-module --manifest-path rust/decision_receipt/Cargo.tomlactionlint .github/workflows/release.ymlpassed.fc68f66b: full suite 5,073 passed, 5 skipped, exit code 0.f51d846c960d4004c5bc8ebd4be171889c7fe948752292cdd2342adfea155ef4). The wheel remained pure Python, installed in an isolated Python 3.12 target, and reported package version0.2.0.Merge and release boundary
#1209 must first reach protected
main. Retarget this PR tomainafterward and require its own current-head hosted checks and independent review before merge. Merging this PR prepares release machinery; it does not itself publish a tag or close #1083. A separate maintainer dispatch on protectedmainremains necessary for the immutable release and downstream consumer migration.Refs #1083.
429 successor before publication
Noema's
orchestrator/freeJSON-schema flow exposed a separate all-429 final-synthesis gap. PR #1251 carries its bounded recovery, with source-side full-suite validation. This release workflow PR can prepare publishing independently, but the Issue #1083 artifact must be built from a protected descendant containing #1251, with fresh exact-head release checks and a new consumer review verdict. Thefc68f66blocal wheel is a reproducibility check of this PR's earlier head, not the final published artifact.Current-head follow-up — 2026-09-26
At
5c4db18b2a7f0427fbbd3ab0ce19b733ab7e2574, the release verifier limits its SBOM lookup to successfulsecurity.ymlpush runs onmainfor the exact source commit. A scheduled run on the same SHA can no longer take the place of the certified push run. The scheduled-run-first execution regression passes; the release test set reports 146 passed (process exit 0),actionlint .github/workflows/release.ymlpasses, andgit diff --checkis clean.Two builds from separate clean
git archivetrees at that exact SHA and fixedSOURCE_DATE_EPOCHwere byte-identical to each other and to a worktree build:contextual_orchestrator-0.2.0-py3-none-any.whl, SHA-256be80e38e1b7d89db850e3ec0a6505c62d9e31bdb0939b441d6b6fc7bd2404100. An isolated Python 3.12 install identified onecontextual-orchestrator==0.2.0distribution. This is local candidate evidence, not a published artifact or a first-release version decision. ADR 0137 in draft #1257 still lists the no-tag first-version choice as unresolved.Hosted Security and Quality run
36237432504completed successfully on this exact head: Tests and package quality, Property and coverage-guided fuzzing, Rust workspace gate, and CodeQL, supply chain, and SBOM all reportSUCCESS. This establishes this PR head's Security result, not release readiness. There is still no independent PR review. Protected review, #1209 integration, the required release gate repair #1259, the package/licence path #1225/#1226, the required PyPI path #1258, full-scope SBOM evidence, and downstream released-contract checks remain separate release conditions. Do not dispatch publication from this PR head.Summary by CodeRabbit