Releases: heavy-duty/ceremony
Release list
0.7.8
Added
- Adoption now ends by recording the board in the operator's catalog:
docs/CONSUMERS.md's bootstrap and conversion checklists both carry the
step, and neither names a repository or a filename as the destination
(#576). - The cost of skipping it is stated where the step is: a board absent from
the catalog is not enumerated by the censuses that a taxonomy change, a
pin bump or a label retirement each run first (#576). - Added a sweep-derived
builderowner-class label as the complement of hand-setoperator. (#562). bin/ceremony-upgrademoves a consumer's every ceremonyuses:reference to
one tag and re-syncs the doctrine mirror by callingdocs-sync --fix.
--checkis the default and changes not one byte;--source <dir>previews
a move against an unreleased ceremony tree (#561).- The pin move refuses where it would cross a migration — a tag whose
docs/CONSUMERS.mdnote asks something of the consumer's tree — naming every
crossed tag in order with its section, and refuses a tree with no pin, an
ungradeable pin, a target that was never cut, and a downgrade (#561). - A refused move leaves the tree byte-identical, however deep the refusal
comes from:--fixsnapshots everything it anddocs-synccan touch before
the first byte, verifies the rewrite against the plan it announced, and
restores the snapshot on any failure — adocs-syncrefusal included (#561). docs-syncgains a third file class, the guarded scaffold: ceremony owns a
marked block in the consumer's.github/pull_request_template.mdand the
consumer owns every byte outside it, so a repo-specific template stops
drifting from the engine that renders into it (#559).- The scaffolded set is read from the pin's
docs/SCAFFOLDED.txt, so a bump
that adds or drops one re-shapes it with no second list; the bump and the
docs-sync --fixrun are one PR (#559). docs-sync --fixnow says where its changes landed when a guarded scaffold
is among them, instead of reporting.ceremony/for work outside it; a run
with no scaffold work prints the sentence it always has (#559).- A fleet-worked repository with no ceremony pin reads doctrine at the latest published, non-draft, non-prerelease ceremony release tag rather than
main, anddocs/CONSUMERS.mdnames the command that resolves it (#558).
Changed
TRIAGE.md's builder-owned paragraph no longer assumes every builder
session has the same boundary: such a criterion may require a named session
capability, and where it does it says so in its own text (#575).- That statement carries three things — builder-owned and not operator-owned,
the capability required, and that a builder lacking it releases the claim
rather than substituting documentation for the evidence (#575). - The reach axis stays two-valued: a named capability is a property of the
criterion and not a third owner class, so an issue whose criteria name one
is builder-owned like any other (#575). - Clarify that
operatorcovers external conditions only the operator can resolve, while excluding third-party waits (#573). - Made the fleet-wide claim-slot assertion an explicit precondition and documented recovery from a false assertion. (#565).
- Document that doctrine-mirrored repositories carry a release caller even without artifact publication, and make
docs-syncsay so when it is missing (#553). - Retired creation of the
post-mergequeue row while leaving existing consumer label objects in place, and clarified re-flag ladder carve-outs. (#540, #544). - Triage now splits after-close work at the mint: a criterion whose evidence cannot exist before the PR merges is not carried by the issue at all, but minted as its own issue declaring the first as its blocker (#151, #536).
- The successor issue carries the outstanding criteria verbatim, has one owner class, and names its evidence surface, its command or observation, and its wake condition (#536).
- A same-repo PR always carries
Closes #N. A criterion a builder cannot check before the merge is a defect in the issue, reported to triage, never a reason to writeRefs #N(#151, #536). Refs #Non an acceptance-criteria PR is no longer blessed by the reviewer authority list; the shape is now the round-cap cut predecessor's alone (#536).- The
post-mergecompletion queue is retired; merge-door splitting now keeps after-close work out of the closing issue entirely (#538, #540). TRIAGE.md's reach axis names no repealed mechanism: reach is the one axis classified at mint. The three-part evidence rule, #491's issue-level reversal and the verbatim relocation are unchanged (#536).- Let triage batch relocated operator-owned criteria when one invocation on the same evidence surface proves them, while keeping batching optional and forbidding cross-surface batches (#532).
- Require shared operator issues to enumerate criteria per origin and let each gated issue declare the shared operator node alone (#532).
- A
needs-rulingflag borne by an issue whose escalation readsDefault: none — hard blockno longer fires the ladder's 24h and past-24h rungs. The flag waits for the human and no timer replaces them (#490, #526). - The setter now owes a published re-read of the default at each of those two rungs — the 12h rung's act extended, so the carve-out adds a duty rather than removing one (#490, #526).
- Record why the late rungs are carved out: their safety is the merge gate, and on an issue there is no second look, so the pick is terminal (#490, #526).
- State the carve-out's three exclusions. A PR-borne flag runs the full ladder; an issue-borne timed reversible default still expires at 0–12h; the 0–12h and 12h rungs are unchanged on every surface (#526).
- Say in one sentence that a discussion carries no
labeledevent and therefore no ladder, which the anchor rule already implied (#490, #526). TRIAGE.mdoutcome 3's past-24h duty to pick now reads as conditional rather than unconditional, matching the ladder's two other copies (#526).- Relocate operator-owned acceptance criteria into their own issue instead of holding the original open: the remainder is left wholly PR-checkable and its PR merges with
Closes #N(#488, #525). - Require the relocation to happen before the merge, and to enumerate the moved criteria one at a time on both the new issue and the original (#488, #525).
- An issue is now builder-owned or operator-owned and never both, replacing the rule that a lone operator-owned criterion left the issue unmarked (#491, #488).
- Read issue ownership off its criteria's class. The two axes stay independent per criterion; only the issue level collapses (#491, #488).
- Give a relocated issue
ready+operatorat its own mint, carrying the evidence surface, the command or observation, and the wake condition (#488, #525). - Add the
builder-owned issue -> operator-owned issue -> gated issuegraph to Dependencies. The gated issue declares the operator-owned one alone (#488, #525). - Rewrite builder park shape 3 as the transient wait for triage's relocation, keeping its number. An operator-owned remainder no longer parks a finished claim (#488, #336).
- Make a governed board's label-taxonomy repair operator-owned and exempt it from issue minting when required queue labels are missing (#524).
Fixed
- Put the engine-mediated panel-request exception beside the review-round instruction it qualifies, so builders signal and mark ready while the engine requests reviewers (#574).
changelog.d/README.mdanddocs/CONSUMERS.mdnow state the entry bound
changelog-armedhas always enforced: at most 300 characters, counted after
continuation lines are joined and whitespace collapsed, so it bounds the
whole entry and never one line of it (#571).- The citation rule is stated as its admitted shape rather than as a
prohibition: exactly one issue-citation group ends an entry, with the final
.after it, and that group may carry several comma-separated references,
cross-repo ones included. A second group anywhere is what fails (#571). - The conversion checklist no longer reads as though deriving a filename were
all an entry's own#Nhas to satisfy: a moved## Unreleasedentry meets
both entry rules too, and one citing several issues folds them into its
single closing group (#571). - Release closed issues' queue labels, assignees and attention in the sweep; pin bumps deliver the repair while triage covers older boards. (#549).
- The 24-hour ruling comment now asks the setter to re-read an issue-borne hard block instead of instructing withdrawn builder and triage picks; pull requests and timed issue defaults retain the full ladder (#537).
- The 7-day ruling nudge no longer counts the flag-setter's own comments as
activity, so the party owing a published re-read can no longer silence the
reminder addressed to the party owing the decision (#526, #534). - The ruling clock now runs from the current
needs-rulinglabeledevent
instead of falling back to the item's creation date, so a long-open item
flagged an hour ago is no longer reported as quiet for months (#534). - The
operatorlabel description restoresor observation, the string #508
decided and the build dropped, so the row a consumer's board renders is no
longer narrower than theLABELS.mdandTRIAGE.mddoctrine it summarizes
(#508, #530). - The five-round cap now lets a passing fifth round hand off and cuts only if a later push would open round six on that pull request (#523).
- The issue-flow reconciler no longer reports
reconciled.over a board write
it lost: each staged write's status is tested, the failing act is named
without its comment body, and the pass summary counts the issues affected
(#519). - A lost board write still leaves the remaining staged effects applied and the
hourly sweep green, so nothing is rolled back and one skipped issue still
never reddens a run (#95, #101, #51...
0.7.7
Fixed
- The
operatorcore label's description measured 106 characters, over
GitHub's 100-character cap, soPOST /labelsanswered422and every fresh
taxonomy bootstrap died on that row. It is reworded and unchanged in meaning
(#508). bootstrap_labels()created labels in a loop with no per-row tolerance, so
underset -ethat one422aborted the run (#508).- Every row after the failing one was therefore never attempted — including the
consumer's wholescope:*set, which is appended after the core rows (#508). - The loop now logs a failed row and continues, matching the contract the retire
loop below it already had, and fails the run at the end with every missing row
named in one line (#508). test/labels-reconcile.test.shnow asserts the cap across the whole core
registry, so a future over-long row reds here rather than in a consumer's
first bootstrap (#508).- The label taxonomy bootstrap runs in its own
labels-sweep.ymljob under
its own concurrency group, so an operator'sbootstrap=yespress is no
longer evicted from the sweep's shared queue and cancelled with no steps
(#506, #503). - The
reconcilesweep keepsgroup: labels-reconcileand never
bootstraps: it passes the literalbootstrap: "no", and the gate that
computed that value now decides whether the bootstrap job runs (#506). actions/labels-reconcileacceptsbootstrap_only, off by default,
which upserts the taxonomy and returns before reading the pull request
list. No consumer caller, input or permission changes (#506).- The bootstrap press now reports whether it survived the queue.
docs/CONSUMERS.mdtold an operator to re-dispatch after a pin bump and
stopped there, andgh workflow runprints the same confirmation whether
the run executes or is evicted (#505, #503). - Both documented run resolvers select the operator's own run by
actor.login
over the REST API.--event workflow_dispatchwith--limit 1takes the
trigger job's dispatch on any board with traffic, so the on-boarding block
could report a false green (#505). - A
cancelledconclusion is stated to mean the taxonomy was not touched, and
the retry sits beside thecore_label_rows()hand-create for an operator who
has lost several presses (#505). ### The pin-bump procedurenames the re-dispatch it owes and links the
verification block; a grep of it forbootstrapreturned nothing before
(#505).- The
missing core label(s)warning no longer reads as "your pin is wrong" to
an operator whose pin is right: it names queue eviction as a cause and points
at the verified press (#505). - The release-shape guard now says so on the pull request. Its
::warning::
attaches to the sweep's own check run on the default branch, so it reached no
surface a builder, a reviewer or the merger reads: it fired 21 times over
ceremony#500, which merged unlabelled and published nothing (#130, #501). - That notice is posted once per episode and retracted when
releasearrives;
a PR that loses and regains the label is told again. The annotation stays
beside it, and the reconciler still never writes the label — notice is not a
guess (#501). docs/CONSUMERS.mdnamed no surface for that notice, which made its claim
that the sweep says so first true of nothing a consumer could read (#501).
0.7.6
Added
- Let release callers declare a logged non-release tag namespace while the
empty default keeps every unmatched tag failure unchanged (#497). - Document the return path for doctrine: a consumer blocked by the vendored
set raises a discussion here, in a four-part shape, and cites it where the
local workaround lives. The generated.ceremony/README.mdnow names and
links that flow (#492). - Add an
operatorissue-owner label, owner-neutral ready semantics, and a
quiet-work nudge for operator-owned issues (#491). - Triage classifies every acceptance criterion at mint by who can produce its
evidence, not only by when it can be checked. Evidence needing a surface a
builder's session cannot reach is operator-owned, and says so, with its
command and its wake condition, in its own text (#487). - The drill record carries a sixth and last section,
## Known gaps— coverage
no probe drives at all, declared with a repeatable--gap '<title>|<body>'
and rendered on every emission, with or without one (#484). - A gap renders as
- **<title>** — <body>and the parse cuts at the first
** —, so a body may carry that sequence and a title may not — refused
when the gap is declared and again when it is rendered (#484). drill/rehearsal.sh --amend-record <path> --gap …adds a gap to a committed
record by re-rendering it: no probe, no scratch repo, no network call. It
refuses a record that does not already round-trip (#484).
Fixed
0.7.5
Added
- Add independent release auto-merge and release-dispatch controls to the labels sweep (#468, #458, #464).
- Allow opted-in consumers to dispatch a release pinned to its merged commit, while keeping non-opted-in callers dry (ceremony#467, ceremony#458).
- A
post_merge_workflowinput on the labels sweep, empty by default. When set,
a successful auto-merge dispatches that workflow, restoring the
push-triggered run aGITHUB_TOKENmerge does not raise (#461, #458). - The dispatch fires only after a merge that landed, goes through
run()so
DRY_RUN=1narrates it, and a failed dispatch is one log line naming the PR,
the workflow and the reason — never a failed pass (#461). - The auto-merge provenance comment now says when the same pass requested the
human's review moments earlier, and omits the line when it did not (#461,
#458). - The labels reconciler now performs the merge its
auto_mergeverdict
authorises: last in the pass, behind a confirmation read of the PR's state,
head andreleaselabel, pinned to the graded head, and throughrun()so
DRY_RUN=1narrates instead of merging (#460, #458). - A merge GitHub refuses is logged on one line and never retried in the pass; a
merge that lands posts one comment naming the head, the method, the toggle
that authorised it and thedecide_stateverdict that triggered it (#460). - Add an inert, opt-in auto-merge verdict with fleet-author and mergeability gates (#459, #458).
Changed
- The consumer guide now gates fleet-worked repositories on a sourced minimum
label set, a verified taxonomy bootstrap, and only thenrepos.txt
registration, preventing partial claims on unprepared boards (#474, crew#459). - Doctrine now states "only humans merge" conditionally: nine sites across
AGENTS.md,REVIEWER.md,LABELS.md,FLEET.mdandCONTRIBUTING.md
nameauto_merge, itsoffdefault and that it is the consumer's setting
(#462, #458). FLEET.mdkeeps its identity invariant and gains the workflow token's own
sentence beside it: no fleet identity gains a permission in this arc
(#462, #458).docs/CONSUMERS.mdgains the auto-merge operating manual — the two inputs,
the two caller permissions, the five refusals, the push-run cost and the
approval-latency note (#462, #458).- The ceremony fleet roster now admits both builder identities to service
builder-raisedrerun-owedrequests without changing either builder's
review panel (#452, #424, #435). docs/CONSUMERS.mdnow states the board-shape tripwire set as the four
families0.7.4ships,stalledincluded, with its three-term firing
condition, its head-only placement, and how it reconciles with
blocker:ci-redandrerun-owed(#448, #440, #441).
Fixed
labels-reconcilenow marks the human review request it makes itself, with
a hidden comment marker, and withdraws only what it marked once the round
stops passing. A maintainer's request carries no mark and is never withdrawn
(#479).- A machine-made request no longer reads as a maintainer's deliberate early
claim: a round with a required verdict missing lands onstate:addressing
withblocker:unrequestedinstead of telling the human a head nobody
reviewed is theirs to merge (#479). - Map changes to the fleet doctrine file to the documentation scope (#476).
labels-reconcilenow bootstraps the taxonomy only when the caller asks
for it.bootstrap=nowas unobeyable: the gate read the event name, and
every trigger-woken sweep is aworkflow_dispatch(#472, #466).- A ceremony pin bump that adds a core label no longer installs it on the
next board event. Dispatch the sweep caller, asdocs/CONSUMERS.mdsays;
the scheduled sweep warns until you do (#472, #466). CONTRIBUTING.md's roster now agrees withpanel=: the departed
grok-bot-andresmgslrow is gone, and the panel rule names no verdict
count — the required set is the review bench minus the PR's author, with
which rows are the bench made explicit so triage is not read into it
(#456).ci-rerun's fleet roster now names each identity once, in the order the
conf names it:load_fleetdedups on append, so a repo whose per-author
panel[<login>]=rows repeat itspanel=reviewers reads a clean list in
the gate-1 refusal comment. Admission is unchanged (#453, #424).
0.7.4
Added
- The issue-flow sweep flags a stalled chain head: a blocker chain three or
more issues deep, counting the head, whoseclaimedhead has a red open PR.
Comment-only, on the head alone, naming the remedy — service the red, or
re-order the chain (#440, #426). lib/checks.sh— the rollup classifier both reconcilers now source, so the
tripwire grades a head with the same instrument that decides
blocker:ci-redand the two can never disagree (#440, #136, #139, #208).- Flag idle queues, deeply serial blocker chains, and dependency cycles from the issue-flow sweep's existing board snapshot (#426).
- Triage now puts measured flow-wide breakage at the front of a collision
chain while ordinary work keeps arrival order (#425). - Front-row insertion records its evidence and edge direction, preserves a
claimed issue's labels, and orders overlapping work at merge (#425). actions/ci-rerun: a base-repo workflow that servicesrerun-owedby
starting the rerun a fork PR's author cannot. Its job holdsactions: write
for one run, checks out nothing from the head, and runs no PR-authored code
(#424).- Four gates, all measured at service time and none inherited from the label:
the actor is a fleet identity in.github/labels.conf, the head still is the
one the evidence names, the run concludedfailure, and it is on attempt 1
(#424). - A started rerun removes
rerun-owedand comments the new attempt's URL; a
refusal leaves the label standing and comments which gate refused and what a
human would have to do. There is no schedule and no retry — the workflow acts
on one label event and stops (#424). - Consumers get the servicing at their next pin bump:
docs/CONSUMERS.md
carries the caller stub and thepermissionsblock, without which the
workflow refuses every time (#424). - Only a run created before the evidence comment that names the head is a
rerun candidate: apull_request_targetrun carries the head's SHA, so the
workflows the label event itself wakes are in that list too and must never
be rerun in the red run's place (#424). rerun-owed: a PR-only label for a head that is red on a rerun no agent may
start. The builder sets it with evidence opening🔁 rerun owed at head <sha>; the reconciler clears it when that head's checks leave failing, or
when the named head is no longer the head (#423).- While
rerun-owedstands at a head,blocker:ci-redis not asserted there:
that label says the builder owes a fix, and on a fork PR's base-repo run the
builder owes nothing. It is not a blocker and never enters the set (#423). - A sixth park shape: a red head whose rerun is a right the builder does not
hold parks the claim and frees the build slot. Every other red head is still
the builder's, and theci-redwake skips the labelled one (#423). rerun-owedis not exempt from the 48-hour staleness clock: a head standing
under it still goesstale, and thatstaleasks for a poke of whoever
services the rerun, never a fix from the builder. A flag earns an exemption
only by carrying an escalation clock of its own (#423).
Changed
- Document the issue-flow sweep's comment-only idle, deep-chain and cycle
tripwires, including placement, shape-keyed deduplication and shared
threshold ownership (#441). - The
ci-rerunroster precondition indocs/CONSUMERS.mddrops its census
of the governed repositories'.github/labels.conffiles, which was false:
identities that build as well as review are named in the roster the gate
reads (#437). - In its place the paragraph gives a directive the reader runs against their
own conf — the three fields gate 1 reads — rather than a measurement of
other repositories that nothing re-checks when a roster changes (#437). - The one-build-at-a-time slot is stated as the builder's own, across every
repository they work in: the self-check is whether an unparked claim is
held anywhere, never whether the board in front of you is clean (#430). - The slot sentence stops carrying a second test for when a build ends. A
claim holds the slot until it is parked or released, so the park list is
the only definition of finishing and the two can no longer disagree (#430). - The claim comment now asserts the slot: no unparked claim in any
repository, naming any parked claims held elsewhere with their shape
(#430). AGENTS.md's router row now sends the builder to an ordered chain of PRs,
normally one — the fourth surface of the singular arithmetic, and the one
the mint's regex could not see behind its backtickedready(#420, #429).- One issue now means an ordered chain of PRs, normally one. A PR carries at
most five rounds; at the close of round 5 the builder continues the branch
in a successor PR and the predecessor closes as the ledger (#420). - The cap is a consensus-surface rule and not a byte defence: the longer a PR
runs, the harder it is to bring the whole panel onto one head (#417, #420). - A cut spends every approval. The review target becomes the successor, no
verdict is owed on the closed predecessor, and rounds are numbered per PR
so the successor's first round is round 1 (#420). - The issue gains a triage-maintained
## Pull requestslist in chain order,
present only once a chain exists and triggered by the builder's cut
comment; it is the only place a chain stays navigable (#420). - Triage now sizes accepted work for bounded review rounds and splits oversized work into ideally disjoint epic children, treating later round growth as evidence for the next mint (#419).
- The PR body's
## Round logis a rolling summary rather than a verbatim
mirror of each round's reply:### Current stateis rewritten every
round,### Roundsgains one row of facts plus two prose cells, and
handoff waits on those cells being filled (#418). - A round's reply shrinks to a short comment naming the round and the head,
so the comment thread stops growing with the body it used to duplicate
(#418).
0.7.3
Changed
- Made vendored review and release doctrine self-contained by replacing cross-repository references with local records. (#408).
Fixed
- Every early-exiting reader in
lib/changelog.shand the two label
actions is fed from a variable instead of a pipe. A reader that exits
early left its writer takingEPIPE, sopipefailfailed the pipeline
although the reader had succeeded (#364, #411). changelog-armedno longer fabricates a changelog shape violation
against a repository whose published section is large, and no longer
passes a real one in silence (#411).- A scope label whose glob matches early in a large PR's changed-file
list is applied instead of silently dropped (#411).
0.7.2
Added
- Add a guard that rejects unpinned third-party actions and reusable workflows (#399).
runner-isolatedtakespr-code-runner-labels: the runner labels a
consumer asserts PR-authored code may execute on. Empty by default, so a
caller passing nothing keeps the verdict it had on every file that
executes PR code; the axis correction above is what moves the rest
(#395).
Changed
- Pin checkout references to v4.4.0, including the refs-guard.yml upgrade from v4.2.2 (#399).
docs-syncnames the fault it saw: a 404 asks about the pin, a 5xx says
the pin is fine and the failure is transient, a connection failure claims
nothing about the ref, and an archive that will not unpack says so (#393).- Refuse a taken explicit drill fork ref before creating a scratch repository, and print a runnable retry using the first free paired attempt (#387).
Fixed
-
runner-isolatedreadsruns-on:in its block-mapping form: a
labels:key one level in is the runner spec's label set, in both of
its spellings — a value beside the key, or a sequence beneath it
(#402). -
A
pull_requestfile naming a self-hosted tier that way passed with an
empty allowlist and now fails. Vouch for the tier in
pr-code-runner-labels, or split the workflow (#402). -
runner-isolatedleaves aruns-on:mapping's other keys inert, so a
group:above or below thelabels:neither contributes a label nor
closes the window. A group namedself-hostedwith nolabels:key
still passes: a group name is not a label (#402, #395). -
runner-isolatedasks whether a file executes PR-authored code, not
whether it is PR-triggered: apull_request_targetfile that checks out a
PR ref now fails, and one that checks out none passes however it is
routed (#395). -
runner-isolatedreads a self-hosted label passed through awith:input,
the shape a reusable-workflow caller uses, so a label named there is judged
exactly as one named inruns-on:(#395). -
A label is read in whatever spelling it is written — quoted, flow, block
scalar, a flow collection opening on the line after its key, or an alias to
an anchor the same file defines — in awith:input and inruns-on:
alike (#395). -
A value written on the line after its key is read when it is a scalar as
well: a wrapped'["self-hosted","ci-runner"]'names its labels. A
*nameinside a quoted scalar stays that scalar's text (#395). -
A label opening with a dash is read whole, so
-self-hostedand a quoted
"- pr-runner"are vouched for by those exact strings; only a-YAML
uses as a sequence indicator is punctuation (#395). -
docs-syncretries the doctrine tarball (four attempts over ~15 s) and
downloads it to a file before extracting, so a transient 503 from GitHub's
archive endpoint no longer reds a consumer's required check (#393).
0.7.1
Added
- Let reusable labels, labels-sweep, and release callers route every job to a JSON-encoded hosted label or self-hosted label set (#383).
- Grade the drill record by re-render: CI parses a bare-version tree's record back into the inputs that would render it and requires the bytes back, so a hand-edited record fails where a shape check passed it (#313, #373).
Changed
BUILDER.mdtells a builder whose handoff was taken back to clear the
blocker rather than re-set the label, the stop condition the "optimistic
write" sentence left out (#377).- Make release-drill scratch repositories public by default, with an explicit private mode and records based on observed visibility (#372).
- Number rehearsal scratch attempts and route default names around archived leftovers without reclaiming repositories or refs (#371).
Fixed
- The reconciler says why it took a handoff back: a PR carrying
state:needs-humanthat degrades tostate:addressingbecause a
blocker:*stands now gets one PR comment naming the take-back, the exact
blockers standing, and the precondition (#377). - That comment is marked with the blocker set and the head SHA, so a sweep
posts it once per episode — a new head or a changed blocker set earns one
new comment, the same head with the same blockers never a second (#377). - It speaks only for a take-back that landed: a label edit that failed, or one
skipped because the repo has nostate:addressing, leaves the handoff
standing and says nothing — and marks no episode, so the pass where the edit
does land still speaks (#377). - The other three ways
state:needs-humandegrades — a draft, a pending
ruling, a directed hold — stay silent, each already carrying a visible
label that says why (#377). - Make drill probes fail on unread fragment, release, or branch data instead of scoring an answer no read established (#375).
- Setup aborts now emit separate, non-releasable evidence records and archive any scratch repository they created (#370).
- The drill instrument retries every read it makes after a write, bounded by
DRILL_READ_TRIESandDRILL_READ_NAP_SECONDS, so a stale or transient
answer from GitHub no longer aborts the setup (#369). - A drill read that never answers says so — naming the read, its target and
the attempt count — instead of asserting that the write it followed failed
(#369). drill_gh_softtells an absent answer from a failed one: a 404 is still
exit 0 and empty, and anything else is non-zero for the caller to retry or
abort on (#369).- A drill record no longer states what a read said when the read never
answered: the re-arm rows, the changelog comparisons and the label
confirmation before a merge each report the unread read instead of a claim
about the repository derived from it (#369). - A drill setup no longer writes on a read that never answered: an existence
read that fails to the end of its budget aborts the commit rather than
reading as "this repository is empty" and sending the bootstrap write to a
branch that already has a head (#369). - A candidate verification that read no workflow file refuses instead of
reporting the candidate SHA as verified — a verification that took no
measurement is not a verification (#369). - A disposal whose flag reads back
archived: falsefor the whole retry
budget is recorded as an archive that did not land, distinctly from a read
that never answered at all — the first is a measurement, the second is the
absence of one (#369).
0.7.0
Added
- The release drill rehearses the rc legs: an rc cut probe asserting a
prerelease, an untouchedCHANGELOG.mdand surviving fragments, and a
promotion probe asserting the assembled final section while the candidate
stays a prerelease (#321). drill/rehearsal.shruns the release drill: scratch repo, armed fixture,
caller stub at a rewritten fork pin, the six doctrine probes and the
record. Every refusal probe's nothing-created claim is a before/after tag
and release count (#313).- The instrument archives and never deletes, printing the operator's delete
step instead of retrying a 403 wall, and refuses to pin the caller stub at
a tag-named ref on this repo (#135, #313).
Changed
- Release-init step 1 now covers the member that arrives by re-opening a
closed issue: re-point its declaration at the epic and verify the parse
before the re-open, so the sweep cannot promote it in between (#325). - Release doctrine now covers cumulative prerelease cuts, deterministic rc
re-arming, and the changelog precondition for adopting that path (#322). - Release doors now publish candidates as prereleases with fragment-assembled notes and automatically re-arm the next candidate (#320).
- Changelog guards now preserve fragments and leave the changelog untouched for tag-only release candidates (#319).
- Release candidates now re-arm deterministically to the next numbered rc development tree (#318).
Fixed
- The issue-flow sweep survives a long release body: the membership record
reaches its parser from a variable rather than a pipe, so the parser's
boundingexitcan no longer break the writer feeding it (#364). - A pre-loop failure in that sweep names its stage — the board read, the
membership parse, or the flag computation — instead of a barejq
message and an exit code (#364). - Make the closing-issue graph authoritative for
Refspull requests and stop treating quoted closing keywords in code spans as defects (#359). - The epic task-list parse takes every CommonMark list marker, not just
-and*; rows and headings indented past three spaces open nothing
(#349). - Neither section parser reads a heading or a row inside a fenced code
block, and an indented heading now closes its section instead of running
the parse into the next one (#349). - Skip an issue when its dependency state cannot be read instead of accusing a valid blocker declaration (#345).
0.6.3
Changed
- A release issue records its window membership under a
## Membersheading, read by heading and one bare#Nper row; itsBlocked byline answers the predecessor gate and nothing else (#343). - The standing-window decision and the non-member flag read that record, with no fallback to the gate: a release issue that enumerates no membership stands no window and draws no flag (#343).
Fixed
- Prevent release-window carriers from joining their own gates and suppress stale board-flag claims after an issue pass changes queue state (#327).