Skip to content

fix(release): refresh crate observation before authorize - #326

Merged
DecisionNerd merged 3 commits into
mainfrom
fix/325-refresh-crate-obs-before-authorize
Aug 1, 2026
Merged

DecisionNerd merged 3 commits into
mainfrom
fix/325-refresh-crate-obs-before-authorize

Conversation

@DecisionNerd

@DecisionNerd DecisionNerd commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Root cause of run 30715697365: after a 523s crates.io Retry-After wait, authorize for graphforge-search used a >10m-old observe-all snapshot, which plan_recovery rewrote to observation_stale → blocked_registry_state (indeterminate).
  • Live crates.io confirms graphforge-search is absent (404); no attempt/receipt orphan. Tag v0.5.1 stays at dd1fd8c.
  • Refresh each crate's live observation immediately before authorize; include observation reason in authorize failures; overlay release_action.py from main on recovery checkouts.

Test plan

  • python3 scripts/ci/test-release-publish-preflight.py
  • python3 scripts/ci/test-release-action.py
  • Required CI / CI Gate green on exact head SHA
  • After merge: one publish.yaml workflow_dispatch recovery for v0.5.1

Closes #325

Made with Cursor


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by CodeRabbit

  • Bug Fixes

    • Improved unsafe-publication error messages by including the planner’s reason, disposition, and current state.
    • Release authorization now clearly identifies stale registry observations and the blocked registry condition.
  • Tests

    • Expanded release workflow validation to confirm registry observations are refreshed and verified before authorization.
    • Added coverage for stale registry data and required release-action behavior on the main branch.

Note

Refresh crate observation before authorization in the crates publishing workflow

  • Before each crate node's authorization step, the workflow now fetches a live observation via release_registry.py observe --live and merges it into observations.json using jq, ensuring stale data does not affect authorization outcomes.
  • The recovery overlay step now also fetches scripts/ci/release_action.py from main, alongside scripts/publish_crates.py.
  • authorize() in release_action.py now includes the planner's decision.reason in ActionError messages when a node is not publishable, improving error visibility.
  • Behavioral Change: nodes with previously stale observations may now be blocked at authorization where they previously were not.

Macroscope summarized a68f4a9.

Long crates.io Retry-After waits can age the initial observe-all snapshot
past the 10m bound, so still-absent crates hard-fail as observation_stale.
Refresh each node live before authorize and surface the blocker reason.

Closes #325

Co-authored-by: Cursor <cursoragent@cursor.com>
@github-actions github-actions Bot added ci-cd CI/CD configuration changes tooling Developer tooling and automation release:none No release note or version impact labels Aug 1, 2026
@coderabbitai

coderabbitai Bot commented Aug 1, 2026 •

Copy link
Copy Markdown

Review Change Stack

Walkthrough

The release action now includes non-empty authorization reasons in unsafe-publication errors. Tests cover stale observations and verify that the crates workflow refreshes and observes the manifest before authorization.

Changes

Crates release authorization

Layer / File(s) Summary
Authorization reason reporting
scripts/ci/release_action.py, scripts/ci/test-release-action.py
Unsafe authorization errors include the decision reason. Tests verify rejection of stale crate observations with blocked_registry_state and observation_stale.
Crates observation preflight
scripts/ci/test-release-publish-preflight.py
Preflight tests verify the main-branch release action, release-node refresh, live observation, and observation before authorization.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 2 | ❌ 3

❌ Failed checks (2 warnings, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check ⚠️ Warning The description explains the root cause, changes, tests, linked issue, and pending validation, but it omits most required template sections. Complete the repository template, including change type, explicit changes, testing coverage, checklist items, performance impact, breaking changes, and reviewer notes.
Linked Issues check ❓ Inconclusive The code covers refresh ordering, contract tests, and blocker reasons, but workflow overlay behavior cannot be verified because publish.yaml was excluded by path filters. Review .github/workflows/publish.yaml and confirm the main-branch overlay, unchanged age checks, and preservation of the v0.5.1 tag.
✅ Passed checks (2 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed The reported changes support the linked issue and remain focused on crate observation, authorization diagnostics, recovery behavior, and related tests.
Title check ✅ Passed The title clearly describes the main change: refreshing crate observations before authorization.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/325-refresh-crate-obs-before-authorize

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
scripts/ci/test-release-publish-preflight.py (1)

103-119: 🗄️ Data Integrity & Integration | 🔵 Trivial | ⚡ Quick win

Strengthen the per-node workflow contract assertion.

These checks validate text fragments only. They do not prove that the main-branch action is written to scripts/ci/release_action.py, that the live observation updates the observations.json consumed by authorize, or that the ordering holds inside every node iteration. Assert the complete commands within the publish loop and verify the overlay, refresh, and authorization sequence for the same node.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/ci/test-release-publish-preflight.py` around lines 103 - 119,
Strengthen the assertions in the preflight test around the publish loop: verify
the main-branch action command targets scripts/ci/release_action.py, and assert
the complete per-node sequence uses the same node for overlay, refresh, live
observation writing observations.json, and authorization consumption. Check
ordering within each node iteration rather than only comparing global string
positions, while preserving the existing command and token checks.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@scripts/ci/test-release-publish-preflight.py`:
- Around line 103-119: Strengthen the assertions in the preflight test around
the publish loop: verify the main-branch action command targets
scripts/ci/release_action.py, and assert the complete per-node sequence uses the
same node for overlay, refresh, live observation writing observations.json, and
authorization consumption. Check ordering within each node iteration rather than
only comparing global string positions, while preserving the existing command
and token checks.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 0aed9d0a-6355-46e6-89cd-f09983900e9a

📥 Commits

Reviewing files that changed from the base of the PR and between 023dfb8 and 655449c.

⛔ Files ignored due to path filters (1)
  • .github/workflows/publish.yaml is excluded by !**/.github/**
📒 Files selected for processing (3)
  • scripts/ci/release_action.py
  • scripts/ci/test-release-action.py
  • scripts/ci/test-release-publish-preflight.py

DecisionNerd and others added 2 commits August 1, 2026 14:18
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-cd CI/CD configuration changes release:none No release note or version impact tooling Developer tooling and automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(release): refresh crates observation before authorize after Retry-After waits

1 participant