Repository navigation
ci(release): gate tag on github, document the release process - #893
Conversation
|
NEEDS CHANGES on 1. "The guard is moot by construction" on the tag-push path is wrong, and it is a mechanism error rather than wording. I measured it: The guard checks 2. "Editing 3. The tag name does not choose the version. Every downstream reference is 4. The sweep missed And a miss of my own, which the review caught: #888's body still recommended the hand-retag. I withdrew it in a comment but left the body saying it, so the issue and this doc disagreed in public. Body now corrected — struck through, with the reason it is both forbidden and non-functional. Confirmed and needing no rework: the one-approval closure is necessary and sufficient (checked against live environment settings — Three non-blocking items also sent back: the OIDC claim says a missing |
`required_reviewers` was already removed from `conda-tag`, `pypi` and `anaconda` (settings only, done outside this change), leaving one approval on `github-release`. `tag` still depended on `version_check` alone, so it would start the moment that job finished -- before the one remaining approval -- and push a commit to `main` plus a `conda-*` tag. Fix: `needs: [ github, version_check ]`. Swept the job-level comments (above `jobs:`, and on `github`, `tag`, `pypi`, `conda`) that described the old four-approval, two-wave arrangement, including three stale rationales in `tests/project/test_release_gates.py`'s own docstrings. Added `tests/project/test_release_gates.py::TestGatedJobsDependOnGithub`: every existing test in that module passes unchanged if `tag`'s `needs:` is reverted to `[ version_check ]` -- the exact regression #887 fixes -- because none of them read `needs:` at all. The new test asserts every gated job's `needs:` closure includes `github`. Added `docs/source/releasing.rst`: the only manual step is bumping `pcapkit.__version__`, and by hand only if `CITATION.cff` moves with it in the same commit, since the release path's own test gate runs the full suite and fails loudly otherwise. Documents both ways a release starts -- pushing a `v*` tag chooses the commit, not the version, since every tag/release name is built from `pcapkit.__version__` and never from `github.ref_name` -- why one approval on `github-release` covers the whole pipeline, and precautions/recovery including the still-open #888 silent-skip gap. Registered in `docs/source/index.rst`. Build: `sphinx-build -b html` -- 58 warnings before and after, same set. `python -m unittest tests.project.test_release_gates` -- 15 passed (confirmed the new test fails alone if the `needs:` fix is reverted, and that all 15 pass with it restored). Closes #887
1a55fe6 to
cc14e8a
Compare
|
GOOD TO GO on The gate hole is genuinely closed, and I reproduced it. Patched Exactly one failure, and it is the new test, naming the offending job. Before this PR all 13 tests passed with the regression present — so the file now asserts the half of the gate that moved from The three corrections are in and the old wording is gone —
The author also found corroboration I had not asked for: Every line citation was re-derived after the comment sweep shifted the file by +4, which is the kind of thing that silently rots: Also fixed: three stale four-approval rationales in Unpublished and unmerged, yours to merge — it closes #887, and unblocks #888. |
Please follow the guide below
make pylint,make mypy,make isort)make testpasses, and a test case covers the changedocs/source/changelog/and regeneratedCHANGELOG.md, if the change is user-visible -- N/A -- changelog centralised in docs(changelog): shared 1.5.0 changelog — long-lived, merges last (#610, #616, #617, #618, #620) #657What is the purpose of your pull request?
fixfeatperfrefactortestdocscichoreDescription of your pull request and other information
Closes #887.
Settings already dropped
required_reviewersfromconda-tag,pypiandanaconda, leaving one approval ongithub-release. This PR does the rest:tagdepended onversion_checkalone, so with its own reviewer gone it would start before the one remaining approval and push a commit tomainplus aconda-*tag. Nowneeds: [ github, version_check ]. Swept the job-level comments describing the old four-approval arrangement, including three stale rationales intests/project/test_release_gates.py's own docstrings.tests/project/test_release_gates.py::TestGatedJobsDependOnGithub: every prior test in that module passes unchanged iftag'sneeds:is reverted to[ version_check ](the exact regression ci(release): one approval for the whole release, not four separate environment gates #887 fixes), since none of them readneeds:. The new test closes that gap.docs/source/releasing.rst: the only manual step is bumpingpcapkit.__version__(and only by hand ifCITATION.cffmoves with it, since the release path runs the full test suite and fails loudly otherwise). Documents both ways a release starts -- pushing av*tag chooses the commit, not the version, since every tag/release name is built frompcapkit.__version__and never fromgithub.ref_name-- why one approval covers the whole pipeline, and precautions/recovery including the still-open fix(ci): a half-finished release leaves a v* tag that makes every retry skip silently #888 gap.sphinx-build -b html: 58 warnings before and after (same set).python -m unittest tests.project.test_release_gates: 15 passed (confirmed the new test fails alone on the revertedneeds:, and all 15 pass with it restored). Did not run the full suite.