Skip to content

fix(release): three crates are in the publish plan but missing from every release inventory #1373

Description

@DecisionNerd

Problem

Three crates are in the publish plan but absent from every release inventory that has to agree with it. crate-publish-plan.py list emits 20 crates. The inventories carry 17.

Missing everywhere: graphforge-discovery, graphforge-observability, graphforge-portable-oci.

All three are genuine publish-required dependencies, so excluding them from the plan is not an option. They are dependencies of graphforge-api and graphforge-cli.

Inventories that disagree

Location Holds Should hold
release_candidate_manifest.CRATES 17 20
clean-env-verify.DEFAULT_CRATES 17 20

The same three crates also lack a NOTICE file

release_candidate_manifest._validate_crate requires Cargo.toml, LICENSE and NOTICE inside every packaged .crate. Of the 20 publishable crates, exactly these three have no NOTICE. The other 17 all do, which is what makes the omission legible: the release plumbing was never extended when these crates were added.

LICENSE is fine. It is pulled in automatically from the workspace license-file key.

Impact

The assembly job copies all 20 .crate files into the candidate. The offline rehearsal step then validates each one and fails on the first unknown identity:

release-rehearsal: unexpected crates.io package identity: graphforge-discovery

Fixing only the inventory moves the failure one step along, to the missing NOTICE. Both halves have to land together.

This sits behind #1370 and #1372 in the same job, so it is not yet reachable in CI.

Requirements

  • Add the three names to both inventories.
  • Add a NOTICE to each of the three crate directories, matching the content the other 17 carry.
  • Extend whatever license gate walks package directories so the three stay honest rather than silently drifting again.
  • Prefer deriving the inventories from the publish plan over maintaining a third hand-written list, if that can be done without weakening the fail-closed checks.

Acceptance criteria

  • release_candidate_manifest.CRATES and clean-env-verify.DEFAULT_CRATES both agree with crate-publish-plan.py list.
  • A test fails when the publish plan and the inventories diverge, so the next crate addition cannot repeat this.
  • Each of the 20 publishable crates packages with Cargo.toml, LICENSE and NOTICE present.
  • The license gate covers the three added crate directories.

Relationships

Child of #1359. Blocks the epic's close condition. Ordered after #1370 and #1372.

Activity

  1. added
    bugSomething isn't working
    ci-cdCI/CD configuration changes
    on Sep 17, 2026
  2. added 2 commits that reference this issue on Oct 10, 2026
    d2a5f59
    f22a7c3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingci-cdCI/CD configuration changes

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions