Repository navigation
feat: implement issue #1046 — canary gate: a v-scoped channel tag shadows the release tag in _gh_candidate_cut_date, so any cross-repo agent adopting v<M>-<tier> channels is permanently BLOCKED (indeterminate) — blocks #1592 - #1051
Conversation
…dows the release tag in _gh_candidate_cut_date, so any cross-repo agent adopting v<M>-<tier> channels is permanently BLOCKED (indeterminate) — blocks #1592
|
ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing |
🤖 CodeAnt AI — Review Status
|
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
|
Important Approval pendingCodeRabbit has no unresolved comments, but it could not review the latest commit because the review limit was reached. Follow the review guidance in this comment to continue. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Code Review
This pull request addresses an issue where v-scoped channel tags shadow actual release tags during candidate cut date resolution, causing the rollout gate to get stuck at BLOCKED. The fix introduces a strict release tag suffix filter (_is_release_tag_suffix) and updates both the local and GitHub API resolution paths, accompanied by comprehensive test coverage. The review feedback suggests simplifying nested double quotes in parameter expansions and improving BATS assertions by checking for exact non-zero exit statuses to prevent false positives from execution errors.
CodeAnt Nitpicks1 code suggestion1. The shared stub returns an annotated release for every
|
Superseded by automated re-review at
|
Superseded by automated re-review at
|
|
CI checks on this PR are still running. Once they complete, re-mention Posted by the donpetry-bot PR-review cascade. |
Dev-Lead — review-changes (applied)Changes committed and pushed. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
Superseded by automated re-review at
|
|
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
|
Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-09-01T03:27:58Z. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: 087878d2786eca83c1abdbb2434d96dbd46a4fa6
Review mode: triage-approved (single reviewer)
Summary
Re-review at head 087878d (prior fix-request was at 576d04a, cycle 3/3). The sole failing gate from the prior review — the unresolved codeant-ai pagination thread at tests/canary_rollout.bats:3576 — is now marked resolved; all 5 review threads on the PR are resolved. The delta since the prior reviewed SHA is exclusively two merges of main (bringing in the already-merged, unrelated #1050 and #1053); the PR's own diff (scripts/canary-rollout.sh, scripts/lib/canary-rollout.sh, tests/canary_rollout.bats) is byte-identical to what was verified last cycle. The #1046 fix is sound: _is_release_tag_suffix filters both the cross-repo API path (with --paginate) and the same-repo for-each-ref path to strict vMAJOR.MINOR.PATCH release tags, the local path only trusts an annotated tag's dereferenced commit + tagger date, and regression tests cover the shadow ordering, the only-channel-tag case, and pagination. All decision gates pass — approving.
Linked issue analysis
Closes #1046 (v-scoped channel tag such as dev-lead/v139-next shadows the release tag in candidate cut-date resolution, wedging the canary gate at BLOCKED indeterminate). Substantively addressed: (1) cross-repo API path filters matching-refs results to immutable release suffixes before matching, with --paginate so a release ref pushed past page 1 by channel refs is not dropped; (2) the same strict filter on the local for-each-ref path; (3) the local path uses only the annotated tag's tagger date, skipping lightweight release-named tags, with the commit-date fallback unchanged; (4) regression tests reproduce the exact live shadow ordering for both paths. The live re-seed of dev-lead/v139-* remains a post-merge verification step outside this PR, as noted last cycle.
Findings
Prior findings — all resolved:
- gemini test-assertion threads (2): fixed (
-eq 1assertions), threads resolved. - gemini nested-quote suggestions (2): correctly refuted by owner, threads resolved.
- codeant-ai pagination gap (Major, tests/canary_rollout.bats:3576): fix (--paginate + pagination-guard test) verified last cycle; the thread — the single failing gate at 576d04a — is now marked resolved.
New issues: none. The delta 576d04a...087878d contains only two clean merges of main (unrelated, already-merged #1050 and #1053); no changes to this PR's files.
Non-blocking notes:
- MCP secret-scanning tool unavailable in this run; the gitleaks CI check passed at head.
- A prior sweep run withheld approval because advisory bots (CodeRabbit/Codex/Qodo) were rate-limited; substantive advisory coverage exists from CodeAnt and Gemini across 3 review cycles, and CodeRabbit reports no unresolved comments.
CI status
All validation checks green at head 087878d: Lint, ShellCheck, bats (both jobs), CodeQL, Analyze (actions), SonarCloud (Quality Gate passed), Secret scan (gitleaks), Agent Security Scan, AgentShield, duplicate-decl-gate, SonarCloud Code Analysis, dependency-audit (npm audit pass; other ecosystems skipped), pr-auto-review, CodeRabbit. The only non-green entries are dev-lead / dispatch and dev-lead / ci-relay runs CANCELLED — concurrency-superseded agent-automation dispatches, not CI validation. mergeStateStatus=BLOCKED reflects the pending required review, not failing checks.
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.
Resolves the conflict in tests/canary_rollout.bats by keeping BOTH test blocks: #1046's `_is_release_tag_suffix` suite (landed on main via #1051) and this PR's `_is_evicted_run` suite. Both branches appended to the same region of the file; neither change touches the other's code. Hand-resolved because dev-lead's rebase dispatch was itself cancelled by a concurrency eviction (run 33462968616) — the exact defect this PR fixes. Verified on the merged tree: - _is_evicted_run declared 1x, _is_release_tag_suffix declared 1x - 9 + 3 tests present, no duplicate @test names, no conflict markers - duplicate-decl-gate (live on main since #1033) passes - bash -n clean; no repeated statement blocks
Addresses the review nit on tests/canary_rollout.bats. A generic `-ne 0` lets a script error (syntax error, command-not-found) pass as a expected failure; `-eq 1` pins the contract. Verified every non-eviction path returns exactly 1 before tightening: cancelled+3, success+0, failure+0, empty count, non-numeric count, missing arg, and no args all exit 1. Matches the convention already used by the _is_release_tag_suffix suite that landed on main via #1051.



User description
Closes #1046
Implemented by dev-lead agent. Please review.
CodeAnt-AI Description
Prevent v-scoped channel tags from being mistaken for release tags during canary rollout checks
What Changed
vMAJOR.MINOR.PATCHrelease tagsv139-nextno longer override release tags or produce an empty cut dateImpact
✅ Canary gates no longer remain indeterminate because of channel tags✅ Accurate release cut dates for rollout health checks✅ Reliable local and cross-repository rollout detection💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.