Problem
Three crates are in the publish plan but absent from every release inventory that has to agree with it. crate-publish-plan.py list emits 20 crates. The inventories carry 17.
Missing everywhere: graphforge-discovery, graphforge-observability, graphforge-portable-oci.
All three are genuine publish-required dependencies, so excluding them from the plan is not an option. They are dependencies of graphforge-api and graphforge-cli.
Inventories that disagree
| Location |
Holds |
Should hold |
release_candidate_manifest.CRATES |
17 |
20 |
clean-env-verify.DEFAULT_CRATES |
17 |
20 |
The same three crates also lack a NOTICE file
release_candidate_manifest._validate_crate requires Cargo.toml, LICENSE and NOTICE inside every packaged .crate. Of the 20 publishable crates, exactly these three have no NOTICE. The other 17 all do, which is what makes the omission legible: the release plumbing was never extended when these crates were added.
LICENSE is fine. It is pulled in automatically from the workspace license-file key.
Impact
The assembly job copies all 20 .crate files into the candidate. The offline rehearsal step then validates each one and fails on the first unknown identity:
release-rehearsal: unexpected crates.io package identity: graphforge-discovery
Fixing only the inventory moves the failure one step along, to the missing NOTICE. Both halves have to land together.
This sits behind #1370 and #1372 in the same job, so it is not yet reachable in CI.
Requirements
- Add the three names to both inventories.
- Add a
NOTICE to each of the three crate directories, matching the content the other 17 carry.
- Extend whatever license gate walks package directories so the three stay honest rather than silently drifting again.
- Prefer deriving the inventories from the publish plan over maintaining a third hand-written list, if that can be done without weakening the fail-closed checks.
Acceptance criteria
Relationships
Child of #1359. Blocks the epic's close condition. Ordered after #1370 and #1372.
Problem
Three crates are in the publish plan but absent from every release inventory that has to agree with it.
crate-publish-plan.py listemits 20 crates. The inventories carry 17.Missing everywhere:
graphforge-discovery,graphforge-observability,graphforge-portable-oci.All three are genuine publish-required dependencies, so excluding them from the plan is not an option. They are dependencies of
graphforge-apiandgraphforge-cli.Inventories that disagree
release_candidate_manifest.CRATESclean-env-verify.DEFAULT_CRATESThe same three crates also lack a NOTICE file
release_candidate_manifest._validate_craterequiresCargo.toml,LICENSEandNOTICEinside every packaged.crate. Of the 20 publishable crates, exactly these three have noNOTICE. The other 17 all do, which is what makes the omission legible: the release plumbing was never extended when these crates were added.LICENSEis fine. It is pulled in automatically from the workspacelicense-filekey.Impact
The assembly job copies all 20
.cratefiles into the candidate. The offline rehearsal step then validates each one and fails on the first unknown identity:Fixing only the inventory moves the failure one step along, to the missing
NOTICE. Both halves have to land together.This sits behind #1370 and #1372 in the same job, so it is not yet reachable in CI.
Requirements
NOTICEto each of the three crate directories, matching the content the other 17 carry.Acceptance criteria
release_candidate_manifest.CRATESandclean-env-verify.DEFAULT_CRATESboth agree withcrate-publish-plan.py list.Cargo.toml,LICENSEandNOTICEpresent.Relationships
Child of #1359. Blocks the epic's close condition. Ordered after #1370 and #1372.