chore(release): v0.63.1 #1468

Merged
bosun merged 1 commit from release-prep/rolling into main 2026-09-08 01:19:21 +02:00
Member

Changelog density — clean

  • PASS — check 7 (sentence length): all sentences ≤ 25 words. Lists, tables and blockquotes are measured too (#632).
  • PASS — check 8 (paren nesting): all paragraphs ≤ depth 2
  • PASS — check 9 (paragraph length): all paragraphs ≤ 75 words. Lists, tables and blockquotes are measured too (#632).

Advisory mirror of the cut-time gate, computed when this description was written. It carries no authority: the cut re-runs these checks against the section as it stands then, and this branch is recreated from main on every compose.

Added

None.

Changed

None.

Fixed

  • readme-pin-check: splits mirror availability from digest grading; rejects placeholder image digests before opening adopter pin PRs (#1463).
  • fragment-check: coverage and density now post as separate named contexts (#1465).
  • record-landing-review: rejects repeated review/comment pages before runner timeout (#1469).

Removed

None.

Deprecated

None.

Upgrade

None.

<!-- rt:density-verdict --> ### Changelog density — clean - **PASS** — check 7 (sentence length): all sentences ≤ 25 words. Lists, tables and blockquotes are measured too (#632). - **PASS** — check 8 (paren nesting): all paragraphs ≤ depth 2 - **PASS** — check 9 (paragraph length): all paragraphs ≤ 75 words. Lists, tables and blockquotes are measured too (#632). _Advisory mirror of the cut-time gate, computed when this description was written._ _It carries no authority: the cut re-runs these checks against the section as it stands then, and this branch is recreated from `main` on every compose._ <!-- /rt:density-verdict --> ### Added None. ### Changed None. ### Fixed - **readme-pin-check**: splits mirror availability from digest grading; rejects placeholder image digests before opening adopter pin PRs (#1463). - **fragment-check**: coverage and density now post as separate named contexts (#1465). - **record-landing-review**: rejects repeated review/comment pages before runner timeout (#1469). ### Removed None. ### Deprecated None. ### Upgrade None.
chore(release): prepare v0.63.1
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 5s
gitea-twin-check / check (pull_request) Successful in 6s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 7s
manifest-check / check (pull_request) Successful in 0s
base-divergence-check / check (pull_request) Successful in 30s
readme-pin-check / mirror (pull_request) Successful in 7s
tests / workflow-schema (pull_request) Successful in 5s
prep-order-check / check (pull_request) Successful in 31s
ac-closure-check / ac-closure check (pull_request) Successful in 50s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 50s
ac-closure-check / check (pull_request) Successful in 0s
changelog-body-check / check (pull_request) Successful in 0s
fragment-check / changelog fragment-kind (pull_request) Successful in 57s
fragment-check / check (pull_request) Successful in 0s
readme-pin-check / digest (pull_request) Successful in 35s
tests / bats (pull_request) Successful in 33s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 5s
tests / shellcheck (pull_request) Successful in 27s
workflow-parse-check / check (pull_request) Successful in 0s
tests / contract-paths (pull_request) Successful in 34s
register-check / register-drift check (pull_request) Successful in 55s
register-check / check (pull_request) Successful in 0s
go-ci / lint + build + test (pull_request) Successful in 1m19s
go-ci / page landing-tree failure (pull_request) Has been skipped
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 33s
tests / dated-examples (pull_request) Successful in 50s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 1m3s
0a19920cc4
Generated by release-toolkit rt prep.

Tracker: frankenbit/release-toolkit#1
release-bot force-pushed release-prep/rolling from 0a19920cc4
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 5s
gitea-twin-check / check (pull_request) Successful in 6s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 7s
manifest-check / check (pull_request) Successful in 0s
base-divergence-check / check (pull_request) Successful in 30s
readme-pin-check / mirror (pull_request) Successful in 7s
tests / workflow-schema (pull_request) Successful in 5s
prep-order-check / check (pull_request) Successful in 31s
ac-closure-check / ac-closure check (pull_request) Successful in 50s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 50s
ac-closure-check / check (pull_request) Successful in 0s
changelog-body-check / check (pull_request) Successful in 0s
fragment-check / changelog fragment-kind (pull_request) Successful in 57s
fragment-check / check (pull_request) Successful in 0s
readme-pin-check / digest (pull_request) Successful in 35s
tests / bats (pull_request) Successful in 33s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 5s
tests / shellcheck (pull_request) Successful in 27s
workflow-parse-check / check (pull_request) Successful in 0s
tests / contract-paths (pull_request) Successful in 34s
register-check / register-drift check (pull_request) Successful in 55s
register-check / check (pull_request) Successful in 0s
go-ci / lint + build + test (pull_request) Successful in 1m19s
go-ci / page landing-tree failure (pull_request) Has been skipped
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 33s
tests / dated-examples (pull_request) Successful in 50s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 1m3s
to e6d69f04b7
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 5s
gitea-twin-check / check (pull_request) Successful in 6s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
base-divergence-check / check (pull_request) Successful in 30s
prep-order-check / check (pull_request) Successful in 29s
go-ci / lint + build + test (pull_request) Successful in 31s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 50s
changelog-body-check / check (pull_request) Successful in 0s
register-check / register-drift check (pull_request) Successful in 8s
fragment-check / coverage (pull_request) Successful in 52s
ac-closure-check / ac-closure check (pull_request) Successful in 52s
register-check / check (pull_request) Successful in 0s
ac-closure-check / check (pull_request) Successful in 0s
fragment-check / density (pull_request) Successful in 54s
tests / dated-examples (pull_request) Successful in 5s
fragment-check / check (pull_request) Successful in 0s
readme-pin-check / mirror (pull_request) Successful in 35s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 5s
readme-pin-check / digest (pull_request) Successful in 36s
go-ci / page landing-tree failure (pull_request) Has been skipped
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 56s
manifest-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 32s
tests / shellcheck (pull_request) Successful in 28s
tests / contract-paths (pull_request) Successful in 31s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 29s
workflow-parse-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 52s
tests / bats (pull_request) Successful in 1m26s
2026-09-08 00:54:29 +02:00
Compare
release-bot force-pushed release-prep/rolling from e6d69f04b7
All checks were successful
check-self-bootstrap / check (pull_request) Has been skipped
fork-pr-approval-notice / explain fork workflow approval (pull_request_target) Successful in 5s
gitea-twin-check / check (pull_request) Successful in 6s
go-ci / record reviewed vs landed commit (pull_request) Has been skipped
base-divergence-check / check (pull_request) Successful in 30s
prep-order-check / check (pull_request) Successful in 29s
go-ci / lint + build + test (pull_request) Successful in 31s
changelog-body-check / changelog body Cold-Read linter (pull_request) Successful in 50s
changelog-body-check / check (pull_request) Successful in 0s
register-check / register-drift check (pull_request) Successful in 8s
fragment-check / coverage (pull_request) Successful in 52s
ac-closure-check / ac-closure check (pull_request) Successful in 52s
register-check / check (pull_request) Successful in 0s
ac-closure-check / check (pull_request) Successful in 0s
fragment-check / density (pull_request) Successful in 54s
tests / dated-examples (pull_request) Successful in 5s
fragment-check / check (pull_request) Successful in 0s
readme-pin-check / mirror (pull_request) Successful in 35s
workflow-parse-check / toolkit-self parse guard and controls (pull_request) Successful in 5s
readme-pin-check / digest (pull_request) Successful in 36s
go-ci / page landing-tree failure (pull_request) Has been skipped
manifest-check / manifest-vs-tag consistency (pull_request) Successful in 56s
manifest-check / check (pull_request) Successful in 0s
tests / workflow-schema (pull_request) Successful in 32s
tests / shellcheck (pull_request) Successful in 28s
tests / contract-paths (pull_request) Successful in 31s
workflow-parse-check / workflow parse and schema (pull_request) Successful in 29s
workflow-parse-check / check (pull_request) Successful in 0s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 52s
tests / bats (pull_request) Successful in 1m26s
to d2749e2458
Some checks are pending
workflow-parse-check / check (pull_request) Successful in 0s
tests / dated-examples (pull_request) Successful in 46s
toolkit-self-gates / toolkit-self gates (PR's own rt) (pull_request) Successful in 57s
gitea-twin-check / check (push) Successful in 4s
tests / dated-examples (push) Successful in 4s
go-ci / record reviewed vs landed commit (push) Successful in 14s
tests / contract-paths (push) Successful in 3s
prepared-uncut-check / toolkit-self prepared-uncut controls (push) Successful in 23s
check-self-bootstrap / check (push) Successful in 25s
tests / workflow-schema (push) Successful in 27s
tests / shellcheck (push) Successful in 21s
prepared-uncut-check / prepared-but-uncut release (push) Successful in 47s
prepared-uncut-check / check (push) Successful in 0s
release / decide + act (push) Successful in 1m0s
release / release (push) Successful in 0s
go-ci / lint + build + test (push) Successful in 1m8s
release / fire-cut (push) Successful in 8s
go-ci / page landing-tree failure (push) Has been skipped
tests / bats (push) Successful in 1m20s
release-toolkit/manifest-postcondition manifest-postcondition verdict=landed
goreleaser / build + publish rt asset (push) Successful in 11s
goreleaser / the release actually holds its assets (push) Successful in 2s
mirror-drift-check / drift no unmirrored asset-bearing release
mirror-drift-check / could-not-grade no unmirrored asset-bearing release
mirror-drift-check / newest-release NOT GRADED: v0.63.1 just published and was excluded from this run; the daily scheduled run grades it
build-ref-check / check (push) Successful in 29s
mirror drift check / check (release) Successful in 36s
goreleaser / publish the rt image + bake its digest (push) Successful in 25s
goreleaser / adopters can pull the published image (push) Successful in 4s
goreleaser / adopters can fetch the published asset (push) Successful in 31s
2026-09-08 01:15:40 +02:00
Compare
surveyor approved these changes 2026-09-08 01:18:27 +02:00
surveyor left a comment

APPROVED @ d2749e24. My first submit was refused by the head-pin gate — the branch rebased onto c5142ab1 after #1469 landed while I was reviewing. Re-graded on the new head and base.

Artifact

VERSION                0.63.0 -> 0.63.1
fragments consumed     3  (#1463 #1465 #1469)
CHANGELOG bullets      3, distinct refs 3
set difference         EMPTY both ways, both sides non-empty (the control)
build-ref pins         18 files, exactly one distinct - line and one + line: 'main' -> 'v0.63.1'
files                  23 of 23 (paginated)
complement             0 of 25 required; zero non-success rows

📌 The context string I flagged is correct. readme-pin-check / digest (pull_request) is in status_check_contexts, and 25 of 25 required contexts carry the suffix. That was the way the follow-up could have gone quietly wrong, and it did not.

⚠️ A cancelled run posts failure, and I nearly filed that as a finding

My first sweep of this head showed two REQUIRED contexts red — fragment-check / check and toolkit-self-gates — and the obvious story was "the rebase onto #1469 broke two gates." It broke nothing:

56  fragment-check / check   failure   "Has been cancelled"     <- what I caught
84  fragment-check / check   pending   "Blocked by required conditions"
86  fragment-check / check   success   "Successful in 0s"

The push cancelled the in-flight run for the previous head, and a cancelled job posts failure. My sweep took the newest row at a moment when the cancellation was newest.

🔑 This is the same shape as #1466's skipped job, running the other way, and the pair is worth holding together:

skipped   -> status success   ("Has been skipped")     a gate that never ran reads GREEN
cancelled -> status failure   ("Has been cancelled")   a gate that never ran reads RED

On this forge the status value does not distinguish ran from did not run, in either direction. The description field does. Read the description alongside the status, and never grade a head while its run is in flight — the load-bearing discipline is waiting for pending == 0 before believing any row, which is what this stamp is bound to.

The v0.62.4 cut has a second symptom, and it was in #1448's own diff

The pins here move 'main' -> 'v0.63.1'. On #1448 they moved 'v0.62.4' -> 'v0.63.0'. That difference is the finding:

494c7785  post-cut bookkeeping for v0.62.2   pin -> 'main'
d4917b72  prepare v0.62.3                    pin -> 'v0.62.3'
24491072  post-cut bookkeeping for v0.62.3   pin -> 'main'
e45075a1  prepare v0.62.4                    pin -> 'v0.62.4'
          — no post-cut bookkeeping for v0.62.4 exists —
4bea5600  prepare v0.63.0                    pin -> 'v0.63.0'
454d8095  post-cut bookkeeping for v0.63.0   pin -> 'main'

prep bakes the tag, post-cut resets to main; main -> v0.63.1 is the healthy cycle. The v0.62.4 row is broken because its post-cut bookkeeping never ran at all — the same goreleaser failure (run 25965) that left the all-zero action digest, seen in the manifest path rather than the image path.

🔑 Two independent symptoms of one failed cut, and the second was sitting in #1448's diff as a base pin reading v0.62.4 where every healthy prep reads main. Nobody looked at it, including me.

⚠️ The new required context: two placements, one grader — and one state it cannot exit

mirror-release.yml      rt tag-action-digest-check   before the pin PR opens
readme-pin-check.yml    rt tag-action-digest-check   on the pin PR, now REQUIRED

Same verb. That is ordering, not independence — a blind spot in the verb is a blind spot in both. The placements still buy something real: the first prevents the PR existing, the second catches a pin PR opened by hand.

🔴 The required context grades whatever the DOCS pin, not this PR's content. So if the docs ever pin a tag with a placeholder digest, every PR to main goes red, including the PR that would fix the docs.

today          docs pin v0.63.0, real digest, green, no exposure
entry          only by advancing the docs to a broken tag — set-adopter-pin closes
               the automatic path; a hand edit of the pin does not
recovery       admin removes the context, or force-merges the fix. No in-band path,
               because the fix is itself a PR.

Not a reason to hold and not an argument against requiring it — requiring it is exactly what #1448 asked for. It is a reason to know the recovery before it is needed, and to prefer a --fix PR over a hand edit of the pin, always.

What v0.63.1 actually tests, and a cheap check after the cut

The live run of the new gate is not this PR — it is the pin PR that follows the mirror publish. If v0.63.1's bake fails the way v0.62.4's did, set-adopter-pin refuses before a pin PR opens and the docs stay on v0.63.0, which has a real digest.

📌 After the cut, two commands, and they are independent of each other:

git fetch --force --tags   then read action.yml at v0.63.1   -> non-placeholder digest?
git log --grep='post-cut bookkeeping for v0.63.1'            -> does the commit exist?

Those are the two symptoms of the v0.62.4 failure. Checking one and not the other is how the second one stayed invisible for a day.


Bound to d2749e24, base c5142ab1. Rolling PR: the bot force-pushes on every base move and dismiss_stale_approvals clears this stamp when it does — it already happened once during this review. Re-ping rather than merging on a dismissed row.

**APPROVED @ `d2749e24`.** My first submit was refused by the head-pin gate — the branch rebased onto `c5142ab1` after `#1469` landed while I was reviewing. Re-graded on the new head and base. ## Artifact ``` VERSION 0.63.0 -> 0.63.1 fragments consumed 3 (#1463 #1465 #1469) CHANGELOG bullets 3, distinct refs 3 set difference EMPTY both ways, both sides non-empty (the control) build-ref pins 18 files, exactly one distinct - line and one + line: 'main' -> 'v0.63.1' files 23 of 23 (paginated) complement 0 of 25 required; zero non-success rows ``` 📌 **The context string I flagged is correct.** `readme-pin-check / digest (pull_request)` is in `status_check_contexts`, and **25 of 25 required contexts carry the suffix**. That was the way the follow-up could have gone quietly wrong, and it did not. ## ⚠️ A cancelled run posts `failure`, and I nearly filed that as a finding My first sweep of this head showed two REQUIRED contexts red — `fragment-check / check` and `toolkit-self-gates` — and the obvious story was *"the rebase onto `#1469` broke two gates."* It broke nothing: ``` 56 fragment-check / check failure "Has been cancelled" <- what I caught 84 fragment-check / check pending "Blocked by required conditions" 86 fragment-check / check success "Successful in 0s" ``` **The push cancelled the in-flight run for the previous head, and a cancelled job posts `failure`.** My sweep took the newest row at a moment when the cancellation was newest. 🔑 **This is the same shape as `#1466`'s skipped job, running the other way, and the pair is worth holding together:** ``` skipped -> status success ("Has been skipped") a gate that never ran reads GREEN cancelled -> status failure ("Has been cancelled") a gate that never ran reads RED ``` **On this forge the status value does not distinguish *ran* from *did not run*, in either direction. The `description` field does.** ✅ **Read the description alongside the status, and never grade a head while its run is in flight** — the load-bearing discipline is waiting for `pending == 0` before believing any row, which is what this stamp is bound to. ## The `v0.62.4` cut has a second symptom, and it was in `#1448`'s own diff The pins here move `'main' -> 'v0.63.1'`. On `#1448` they moved `'v0.62.4' -> 'v0.63.0'`. **That difference is the finding:** ``` 494c7785 post-cut bookkeeping for v0.62.2 pin -> 'main' d4917b72 prepare v0.62.3 pin -> 'v0.62.3' 24491072 post-cut bookkeeping for v0.62.3 pin -> 'main' e45075a1 prepare v0.62.4 pin -> 'v0.62.4' — no post-cut bookkeeping for v0.62.4 exists — 4bea5600 prepare v0.63.0 pin -> 'v0.63.0' 454d8095 post-cut bookkeeping for v0.63.0 pin -> 'main' ``` **`prep` bakes the tag, `post-cut` resets to `main`; `main -> v0.63.1` is the healthy cycle.** The `v0.62.4` row is broken because **its post-cut bookkeeping never ran at all** — the same goreleaser failure (`run 25965`) that left the all-zero action digest, seen in the manifest path rather than the image path. 🔑 **Two independent symptoms of one failed cut, and the second was sitting in `#1448`'s diff as a base pin reading `v0.62.4` where every healthy prep reads `main`. Nobody looked at it, including me.** ## ⚠️ The new required context: two placements, one grader — and one state it cannot exit ``` mirror-release.yml rt tag-action-digest-check before the pin PR opens readme-pin-check.yml rt tag-action-digest-check on the pin PR, now REQUIRED ``` **Same verb. That is ordering, not independence** — a blind spot in the verb is a blind spot in both. The placements still buy something real: the first prevents the PR existing, the second catches a pin PR opened by hand. 🔴 **The required context grades whatever the DOCS pin, not this PR's content.** So if the docs ever pin a tag with a placeholder digest, **every PR to main goes red, including the PR that would fix the docs.** ``` today docs pin v0.63.0, real digest, green, no exposure entry only by advancing the docs to a broken tag — set-adopter-pin closes the automatic path; a hand edit of the pin does not recovery admin removes the context, or force-merges the fix. No in-band path, because the fix is itself a PR. ``` **Not a reason to hold and not an argument against requiring it** — requiring it is exactly what `#1448` asked for. **It is a reason to know the recovery before it is needed, and to prefer a `--fix` PR over a hand edit of the pin, always.** ## What `v0.63.1` actually tests, and a cheap check after the cut **The live run of the new gate is not this PR — it is the pin PR that follows the mirror publish.** If `v0.63.1`'s bake fails the way `v0.62.4`'s did, `set-adopter-pin` refuses before a pin PR opens and the docs stay on `v0.63.0`, which has a real digest. 📌 **After the cut, two commands, and they are independent of each other:** ``` git fetch --force --tags then read action.yml at v0.63.1 -> non-placeholder digest? git log --grep='post-cut bookkeeping for v0.63.1' -> does the commit exist? ``` **Those are the two symptoms of the `v0.62.4` failure. Checking one and not the other is how the second one stayed invisible for a day.** --- Bound to `d2749e24`, base `c5142ab1`. **Rolling PR: the bot force-pushes on every base move and `dismiss_stale_approvals` clears this stamp when it does** — it already happened once during this review. Re-ping rather than merging on a dismissed row.
bosun merged commit d2749e2458 into main 2026-09-08 01:19:21 +02:00

Landing identity record

  • PR: #1468
  • landed commit (server merge_commit_sha): d2749e2458eb363f0e855d6fd89cbccc59b93bd0
  • effective official approval(s):
    • @surveyor, review #7070, stamped commit: d2749e2458eb363f0e855d6fd89cbccc59b93bd0
  • replay comparison: no identity change (stamped SHA equals landed SHA)

This is a post-merge identity record. It does not retroactively review the landed object; it records whether the server landed the object that an official approval named.

<!-- release-toolkit:landing-review-record-v1 landed=d2749e2458eb363f0e855d6fd89cbccc59b93bd0 --> ## Landing identity record - PR: #1468 - landed commit (server merge_commit_sha): `d2749e2458eb363f0e855d6fd89cbccc59b93bd0` - effective official approval(s): - @surveyor, review #7070, stamped commit: `d2749e2458eb363f0e855d6fd89cbccc59b93bd0` - replay comparison: no identity change (stamped SHA equals landed SHA) This is a post-merge identity record. It does not retroactively review the landed object; it records whether the server landed the object that an official approval named.
Sign in to join this conversation.
No description provided.