fix(release): refresh crate observation before authorize - #326
Conversation
Long crates.io Retry-After waits can age the initial observe-all snapshot past the 10m bound, so still-absent crates hard-fail as observation_stale. Refresh each node live before authorize and surface the blocker reason. Closes #325 Co-authored-by: Cursor <cursoragent@cursor.com>
WalkthroughThe release action now includes non-empty authorization reasons in unsafe-publication errors. Tests cover stale observations and verify that the crates workflow refreshes and observes the manifest before authorization. ChangesCrates release authorization
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 2 | ❌ 3❌ Failed checks (2 warnings, 1 inconclusive)
✅ Passed checks (2 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
scripts/ci/test-release-publish-preflight.py (1)
103-119: 🗄️ Data Integrity & Integration | 🔵 Trivial | ⚡ Quick winStrengthen the per-node workflow contract assertion.
These checks validate text fragments only. They do not prove that the main-branch action is written to
scripts/ci/release_action.py, that the live observation updates theobservations.jsonconsumed byauthorize, or that the ordering holds inside every node iteration. Assert the complete commands within the publish loop and verify the overlay, refresh, and authorization sequence for the same node.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/ci/test-release-publish-preflight.py` around lines 103 - 119, Strengthen the assertions in the preflight test around the publish loop: verify the main-branch action command targets scripts/ci/release_action.py, and assert the complete per-node sequence uses the same node for overlay, refresh, live observation writing observations.json, and authorization consumption. Check ordering within each node iteration rather than only comparing global string positions, while preserving the existing command and token checks.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@scripts/ci/test-release-publish-preflight.py`:
- Around line 103-119: Strengthen the assertions in the preflight test around
the publish loop: verify the main-branch action command targets
scripts/ci/release_action.py, and assert the complete per-node sequence uses the
same node for overlay, refresh, live observation writing observations.json, and
authorization consumption. Check ordering within each node iteration rather than
only comparing global string positions, while preserving the existing command
and token checks.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 0aed9d0a-6355-46e6-89cd-f09983900e9a
⛔ Files ignored due to path filters (1)
.github/workflows/publish.yamlis excluded by!**/.github/**
📒 Files selected for processing (3)
scripts/ci/release_action.pyscripts/ci/test-release-action.pyscripts/ci/test-release-publish-preflight.py
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Summary
Retry-Afterwait, authorize forgraphforge-searchused a >10m-old observe-all snapshot, whichplan_recoveryrewrote toobservation_stale→blocked_registry_state (indeterminate).graphforge-searchis absent (404); no attempt/receipt orphan. Tagv0.5.1stays atdd1fd8c.release_action.pyfrom main on recovery checkouts.Test plan
python3 scripts/ci/test-release-publish-preflight.pypython3 scripts/ci/test-release-action.pypublish.yamlworkflow_dispatch recovery for v0.5.1Closes #325
Made with Cursor
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by CodeRabbit
Bug Fixes
Tests
Note
Refresh crate observation before authorization in the crates publishing workflow
release_registry.py observe --liveand merges it intoobservations.jsonusingjq, ensuring stale data does not affect authorization outcomes.scripts/ci/release_action.pyfrom main, alongsidescripts/publish_crates.py.authorize()in release_action.py now includes the planner'sdecision.reasoninActionErrormessages when a node is not publishable, improving error visibility.Macroscope summarized a68f4a9.