Moving a consumer between ceremony versions is a hand-written 12-to-19-file PR, twelve times per release — and two boards are 15 and 17 releases behind #555
Replies: 4 comments
Ruled — minted as #560 + #561. And § 5 is still open: your agreement does not reach it, and I am not picking it for you.@danmt The buildOne epic with #552, not two. You ruled that thread's B four minutes later, and bootstrap and upgrade are the same operation with one of them starting from empty. Two builds would put the migration ladder in two places.
§ 3 is what shaped it. The refusal ships before a single migration does, so on the day #561 merges it can safely move The later rows are deliberately not minted yet. Their specs depend on #561's shipped refusal table — that table is what tells us what a ladder step has to look like — and Two acts in the epic are yours and pass no mint door: creating the template repository and marking it 🧭 needs-ruling — may a generated pin-bump PR take a reduced panel, or auto-merge once green?Re-asked, because it is a second question and a bare agreement with the § 1–§ 4 recommendation does not answer it. § 5 was flagged as "a ruling, not a build" and it needs no build at all: Options: Recommend: B, and not C yet. A generated pin-bump's diff is machine-verified — ⚖️ The status quo is not "A". It is "whoever is around decides per-PR", and that is the real argument for ruling this either way: Blocked: nothing. No board waits on this and nothing is minted anywhere for it. #560 and #561 are correct under every option — the tool opens PRs and says nothing about who reviews them — and this changes no ceremony code either way: it is a value in twelve consumers' caller stubs. Default: none — hard block. Who may merge what without review is org policy, and its cost lands outside the work. Under #526 the 24h and past-24h rungs do not fire on a hard block and triage never picks it; what I owe instead is a published re-read of this default against what has landed. And no rung falls here in any case: a discussion carries no This thread stays open — it is where the § 5 question now lives, and #560 is where the ruled half lives. Answered by |
📎 Correction + the re-read I owed on § 5 — the ruled half moved to #568, and the hard block still holds@danmt No new question, and nothing about your 1. The pointer —
|
| fact | then | now (2026-08-31T23:4xZ) |
|---|---|---|
consumers setting auto_merge or auto_merge_release |
0 of 12 | 0 of 13 — re-measured across every board carrying a ceremony uses: line, plus ceremony's own caller, which passes no with: block either |
| the toggles themselves | shipped since 0.7.7, off by default |
unchanged in 0.7.8 — no merge-toggle entry in that release's changelog section, and labels-sweep.yml's inputs are byte-identical |
| new instances of the PR class | box#183, la-familia-incubator#7 at zero verdicts; rig#202, landing-site#41 at a full round |
none. No board has bumped to 0.7.8: the twelve pin-bump PRs this release owes are all still ahead |
The default still holds, and I am not picking it. Nothing that landed makes the decision reversible-inside-the-PR, which is the only thing that would move it off a hard block. The re-measurement is neutral: the class has gained no member, so the "same class of PR, opposite treatment, in the same week" evidence is exactly as strong and no stronger than when I posted it.
Two things did change the picture slightly, and both are worth your eye rather than being buried:
- The twelve bumps this release owes are not ordinary bumps. #588, minted today off discussion #585, measures that
bin/ceremony-upgradecannot perform a single move to0.7.8from any of the 18 source tags —0.7.8carries aMIGRATIONSrow of its own, so every consumer's next bump crosses it and is refused. So the0.7.8wave is hand-written, not machine-written, which weakens option B's premise for this wave specifically: B's argument was that a generated diff is machine-verified. It does not weaken B for the waves after the ladder lands, and it is not a reason to prefer C. martin-reyes-barbershopis a thirteenth board, at0.3.0, missed by my2026-08-29census of twelve. It changes no argument here; it makes the fan-out one board larger.
Blocked: still nothing. #568's rows are correct under every option — the tool opens PRs and says nothing about who reviews them — and no issue anywhere is gated on this. No rung falls: a discussion carries no needs-ruling label and no labeled event, so nothing expires against you and silence has no timer. I will post the next re-read if something lands that moves it, and not otherwise.
This thread stays open — § 5 is unanswered and this is its venue.
Written by heavy-duty/ceremony triage, 2026-08-31T23:5xZ. No label moves and no attention is set: #568 is an unassigned epic and this comment delivers no assignee's next move.
🔁 Re-read — the sentence that weakened option B is now false, and § 5 has become a live question with a price@danmt My What I wrote, and why it is no longer true
That was correct when written and is now false. #602 merged Re-measured live this tick, running the shipped command at
So "not a single move" has become nine of eighteen source tags perform something, and eight of them land at And it holds against a real tree rather than a fixture. Fed What that does to § 5, which is the only thing still open hereB's premise for this wave is restored. B's argument was that a generated diff is machine-verified; the It also gives § 5 a concrete price for the first time. The question — may a generated pin-bump PR take a reduced panel or auto-merge once green? — now stands over eight identical, machine-generated diffs, each currently owed a draft and up to three verdicts, on boards where zero of twelve consumers set I am not re-asking, and I am not recommending anything new. § 5's options and my recommendation stand exactly as written; only the fact that weakened one of them has gone. Where the arc stands, so the pointer resolves to a stateThe ladder is three of eight Blocked: still nothing. #568's rows are correct under every § 5 answer, #605 and #606 are claimable now, and no issue anywhere is gated on this. No rung falls: a discussion carries no This thread stays open — § 5 is unanswered and this is its venue. Written by |
Uh oh!
There was an error while loading. Please reload this page.
🧭 needs-ruling — moving a consumer between ceremony versions is 12–19 files and a review round, twelve times per release. Eighteen releases in, three boards are 1, 15 and 17 releases behind. What replaces the hand-written pin-bump PR?
Options: A —
ceremony upgrade <tag>, a command in ceremony run against a consumer checkout · B — a reusable upgrade workflow a consumer dispatches with a target tag, which opens its own PR · C — release-time fan-out: ceremony's own release dispatches B into every registered consumer · D — a fleet duty increwthat sweeps consumers and opens the PRsRecommend: A, then B, with C as the payoff. A is the whole substance; B is a thin wrapper around it; C is a
forloop overrepos.txt. D re-implements B and C on a different engine and makes the fleet a dependency of the ceremony.📌 And a second, cheaper half that is already built and unused:
labels-sweep.ymltakesauto_mergeat0.7.7and zero of the twelve consumers set it. See § 5 — that half is a ruling, not a build.Blocked: nothing, and nothing is minted anywhere for this. Not a member or gate of #528 — @danmt's
12:43:12Zfreeze means nothing minted after it joins that cut.Default: none. How the fleet moves between versions is org shape. No rung falls here — a discussion carries no
needs-rulinglabel and nolabeledevent (#526).Analysis — the measurement, why
sedis the wrong tool, and what each option costs@danmt,
2026-08-29:Filed separately from #552 at @danmt's framing — "regardless of the template stuff". #552 asks how a new repository arrives governed; this asks how an existing one moves. They converge on one command (§ 6), and that is an argument for building it, not for merging the threads: the hard parts are different, and this one is recurring where #552's is one-time.
1. The cost, measured
Eighteen releases:
0.1.00.2.00.3.00.4.00.4.10.5.00.6.00.6.10.6.20.6.30.7.00.7.10.7.20.7.30.7.40.7.50.7.60.7.7. Twelve governed boards.A pin bump is not a one-liner. Six real ones:
box#183— 0.7.4box#220— 0.7.6rig#202— 0.7.4 → 0.7.7incubator#232— 0.7.4landing-site#41— 0.7.4 → 0.7.7la-familia-incubator#7— 0.7.712–19 files, usually three review verdicts. It is every ceremony
uses:in the tree (7 to 12 of them, and the same-tag rule means all or none), plus the.ceremony/mirror re-sync, plus — sometimes — a migration.2. The drift is the proof that this cost is real and unpaid
0.7.7infra,la-familia-infra,la-familia-incubator,landing-site,lafamilia-site,rig,box,incubator,rig-templates0.7.6crew0.3.0martin-reyes-barbershop0.1.0castNothing noticed, because nothing looks.
casthas been on the first release ever cut for the entire life of this repository — it predates the two-caller split,triage-actors=,panel[<login>]=, theissues:trigger and fragment-mode changelogs.crew— the fleet itself — is behind by one and has been since0.7.7shipped.3.⚠️ Why
sed 's/0.7.4/0.7.7/g'is the wrong tool, and this is the load-bearing findingdocs/CONSUMERS.mdcarries ten "available atXand later" notes. Those are migrations, not substitutions, and several are silently destructive if a pin moves past them without the accompanying edit:0.4.1(labels.yml — detach the reconcile sweep from PR-triggered runs so queue displacement never lands a cancelled check on a PR #209) — the two-caller split. "One atomic PR with exactly four edits": bump every ref, add a newlabels-sweep.yml, move the hourly cron off the labels caller (never copy — "a consumer that copies the sweep caller and leaves the old schedule gets DOUBLE sweeps"), and addactions: write. A bare pin bump past0.4.1takes the trigger job red on every PR and issue event and stops event-woken sweeps entirely.0.2.0(feat: reconcile the issue work queue #32) —triage-actors=becomes mandatory. Its absence is a parse failure, not an ignored setting.0.5.0(actions/labels-reconcile + BUILDER.md/REVIEWER.md — per-author review panels: labels.conf gains panel[<login>]=, resolved at the one point the required set is computed #224) —panel[<login>]=rows. On an earlier pin a bracketed row is "a parse failure, not an ignored setting… the reconcile job dies on every PR event and every sweep until the row is removed, so the whole label board goes down."0.3.0(labels/scope clobbers a label written while it runs — the ceremony PR can silently loserelease#130) —.github/labeler.yml's accepted shape narrows. Any other labeler key now fails the run loudly instead of being half-honoured.0.6.0(RELEASES.md — the release-management doctrine: epic ladders, gates, release-init, primary windows — one flow for the family #248) —RELEASES.mdjoins the vendored set, so the mirror gains a file.So
cast's0.1.0→0.7.7move crosses at least four migrations, two of which take its board down if done naively. A tool that only rewrites refs would break the two consumers that need it most.⚖️ That is also the design: the real content of this tool is a per-tag migration ladder, and ceremony already has one — written as prose in
CONSUMERS.md. The work is turning those paragraphs into ordered, executable steps that a machine applies and that refuse rather than guess where a human decision is genuinely owed (a runner tier, a new panel row). That is a real build, and it is the reason this is worth doing once centrally instead of twelve times by hand.4. What each option costs
ceremony upgrade <tag>. A command in this repository, run against a consumer's checkout: rewrite every ceremonyuses:to one tag, rundocs-sync --fix, apply each intervening tag's migration in order, refuse loudly where a decision is owed, print what it did. The builder reviews the diff and opens the PR. All the substance lives here, tested here, released here — the same place the migrations are written. Cost: a real build (the ladder, tests, docs, a tag) and it still needs somebody to run it twelve times.forloop once B exists; the honest costs are that ceremony gains a cross-repo write (a PAT, or a GitHub App, sinceGITHUB_TOKENcannot reach another repository) and a registry of consumers it does not currently have.crew.shared/bin/duty.shexists andrepos.txtis already the registry, so this is the cheapest to start. But it puts ceremony's migration knowledge in a second repository, re-implements C on a different engine, and makes the ceremony's upgrade path depend on the fleet being up. It also inherits the fleet's own constraint: fork PRs plus triage-only tokens.5. 📌 The review half is already built and nobody turned it on
labels-sweep.ymlat0.7.7declaresauto_merge(off|merge|squash|rebase) andauto_merge_release, withoffthe default. Measured across all twelve consumers this pass: none sets either.A generated pin-bump PR is exactly the class this exists for — its diff is machine-written and machine-verified (
docs-sync --checkproves the mirror matches the pin;ciproves the guards pass), and the fleet is already treating these as low-review, just informally and inconsistently:box#183andla-familia-incubator#7merged with zero verdicts, the latter 99 seconds after opening, whilerig#202andlanding-site#41took a full three-bot round for the same mechanical change.⚖️ So the second question, and it needs no build: may a generated pin-bump PR take a reduced panel or auto-merge once green? That is the difference between twelve PRs to draft and review and twelve PRs that land themselves, and it is worth ruling whichever way — the status quo is that this decision is being made per-PR by whoever is around.
6. How this meets #552
Bootstrap and upgrade are the same operation, one of them starting from empty. A consumer at
0.1.0moving to0.7.7crosses the same migrations a fresh repository skips by starting at the top; a fresh repository is the degenerate case where every migration applies to an empty tree.So A is the first milestone of both threads. #552 recommends a thin template repo whose
initworkflow calls abootstrapin ceremony; that command and this one are one command with two entry points. Neither thread should be built without the other's ask in view, and neither is blocked by the other.7. What this does not propose
@mainand floating majors stay forbidden (#1 D2).All reactions