Feature 09: Rollout integration — registration audit, policy wiring, e2e, CI #15

Closed
opened 2026-09-04 04:25:13 +00:00 by crueber · 4 comments
Owner

Feature 09: Rollout integration — registration audit, policy wiring, e2e, CI

Spec: docs/features/09_rollout.md (normative plan of record) §§4–7.
Rollout: Wave E in docs/features/09_rollout.md §3 (single integration agent). Depends on 01–08 all landed.

  • §4 touch-point audit: verify each frozen-code touch landed as a spec amendment — (1) checks:write capability + require_read↔visibility in internal/server/auth + internal/config token schema; (2) policy.json actor sources (team:, role:) + merge-time effects (require_checks, required-reviews) evaluated by the merge task, push path push-enforceable-only; (3) internal/server registers every RouteProvider (one block per package: identity, issues, pulls, review, checks, notify, releases, social) + per-user SSE mounts. Fix gaps in this change with doc amendments per AGENTS.md law 12.
  • Seam/invariant sweep (§5): bucket-only state (no survivor outside the store), WAL git-only (no collab WAL entries; PR refs only), push fast path gains zero bucket round trips (measure it), P3 immutable-events/CAS-headers everywhere, no LIST on git hot paths, tasks + SSE for all long/live work.
  • E2E scenarios (new internal/e2e cases or extended): org → team → repo bindings → issue → PR → review → checks → required-gates → merge → release → notification/webhook delivery, end to end on a real stack with real git. Include the closing-keyword path (fixes #N closes on merge) and fork → cross-fork PR.
  • Makefile/CI additions: make ci covers the new packages at the ≥95% gate; tiered-test docs (docs/go/15_testing.md) mention new suites; Woodpecker + GH workflow run them.
  • Rollout docs: 09 status flipped from "plan of record" to landed (or a landing note), §7 risks re-checked with measured outcomes, API-versioning statement (§6) confirmed additive-only.

Acceptance criteria

  • Audit table (§4 three touch points + §5 seven invariants) with file:line evidence per row in the PR description.
  • make ci green end to end (or the exact tiered equivalent); coverage gate holds for every new package.
  • E2E scenario passes on a rebuilt compose stack with real git + a webhook sink.
  • No new product surface — pure integration; any behavior fix ships with a spec amendment note.
# Feature 09: Rollout integration — registration audit, policy wiring, e2e, CI **Spec:** `docs/features/09_rollout.md` (normative plan of record) §§4–7. **Rollout:** Wave E in `docs/features/09_rollout.md` §3 (single integration agent). Depends on 01–08 all landed. ## Recommended implementation (verified against the doc) - **§4 touch-point audit:** verify each frozen-code touch landed as a spec amendment — (1) `checks:write` capability + `require_read`↔visibility in `internal/server/auth` + `internal/config` token schema; (2) `policy.json` actor sources (`team:`, `role:`) + merge-time effects (`require_checks`, `required-reviews`) evaluated by the merge task, push path push-enforceable-only; (3) `internal/server` registers every RouteProvider (one block per package: identity, issues, pulls, review, checks, notify, releases, social) + per-user SSE mounts. Fix gaps in this change with doc amendments per AGENTS.md law 12. - **Seam/invariant sweep (§5):** bucket-only state (no survivor outside the store), WAL git-only (no collab WAL entries; PR refs only), push fast path gains zero bucket round trips (measure it), P3 immutable-events/CAS-headers everywhere, no LIST on git hot paths, tasks + SSE for all long/live work. - **E2E scenarios (new `internal/e2e` cases or extended):** org → team → repo bindings → issue → PR → review → checks → required-gates → merge → release → notification/webhook delivery, end to end on a real stack with real git. Include the closing-keyword path (`fixes #N` closes on merge) and fork → cross-fork PR. - **Makefile/CI additions:** `make ci` covers the new packages at the ≥95% gate; tiered-test docs (`docs/go/15_testing.md`) mention new suites; Woodpecker + GH workflow run them. - **Rollout docs:** 09 status flipped from "plan of record" to landed (or a landing note), §7 risks re-checked with measured outcomes, API-versioning statement (§6) confirmed additive-only. ## Acceptance criteria - [ ] Audit table (§4 three touch points + §5 seven invariants) with file:line evidence per row in the PR description. - [ ] `make ci` green end to end (or the exact tiered equivalent); coverage gate holds for every new package. - [ ] E2E scenario passes on a rebuilt compose stack with real git + a webhook sink. - [ ] No new product surface — pure integration; any behavior fix ships with a spec amendment note.
Author
Owner

Starting Feature 09 (Wave E integration) on branch feat/integration from origin/main (8bacf03). Dirty worktree on feat/issues left untouched (recorded status before). Plan: §4 touch-point audit + §5 invariant sweep with file:line evidence, push-fast-path measurement, full-chain e2e extension, CI/coverage wiring, rollout doc updates. No new product surface.

Starting Feature 09 (Wave E integration) on branch feat/integration from origin/main (8bacf03). Dirty worktree on feat/issues left untouched (recorded status before). Plan: §4 touch-point audit + §5 invariant sweep with file:line evidence, push-fast-path measurement, full-chain e2e extension, CI/coverage wiring, rollout doc updates. No new product surface.
Author
Owner

Feature 09 ready for review: #20 (branch feat/integration → main). Audit table + invariant evidence + test results are in the PR description. Acceptance: audit table with file:line evidence ✓, make ci green (vet/race/cover-44pkgs/e2e/contract) ✓, full-chain e2e on live server + webhook sink ✓ (~2.2s wall), no new product surface (one race fix with 03 amendment) ✓. Not merging — awaiting review.

Feature 09 ready for review: https://git.packden.us/crueber/walhub/pulls/20 (branch feat/integration → main). Audit table + invariant evidence + test results are in the PR description. Acceptance: audit table with file:line evidence ✓, make ci green (vet/race/cover-44pkgs/e2e/contract) ✓, full-chain e2e on live server + webhook sink ✓ (~2.2s wall), no new product surface (one race fix with 03 amendment) ✓. Not merging — awaiting review.
Author
Owner

PR #20 review (scratch worktree @ b0925bd, go1.27.1, git 2.53.0). All checks done in /tmp/pr20; main worktree untouched, nothing committed.

VERIFIED CLEAN

  1. S4 audit file:line claims (spot-checked ~10, all accurate): CITokenScope internal/checks/model.go:134 exact; handler-side CI check internal/checks/service.go:165-183; Seam 2 ExtraCredential hook internal/server/auth.go:39-54 + registration cmd/walhub/checks.go:54; require_read gate internal/identity/gate.go CheckRead + internal/server/server.go readGate / internal/server/bind_api.go ReadGate+checkReadGate; team:/role: expansion + ProtectEffect.Evaluate ignoring RequireChecks internal/policy/effect_protect.go:154-157; merge-task gates internal/pulls/merge.go:159-168; key shapes internal/checks/checks.go:187-209. Touch-1 amendment (wct_ bucket token, not a Principal field) matches the code.

  2. Push fence SOUND (cmd/walhub/push_budget_test.go): countingStore wraps the one shared store behind reg+engine+env+collab, so any collab read counts. Overrides cover Get/Head/Put/Delete/List/ListPrefixes/Compose; GetBytes/PutBytes (internal/store/store.go:199,226) are package funcs delegating to the counted methods; SignedGetURL/AccelTarget are only reached from bundle/static serve paths, not receive-pack. Classifier covers every family I could enumerate (reviews live under pulls/, social/forks/ci_tokens under meta/, webhooks/collab-events/issues/releases/access.json/users/orgs all present; policy.json excluded by documented design). REPRODUCED EXACTLY: cold 8 ops / warm 9 ops / 0 collab, real git 2.53.0 over real HTTP receive-pack.

  3. Data race REAL + fix CORRECT: reverted internal/pulls/tasks.go to main in scratch -> TestCoverTaskEndSnapshotRace FAILS with WARNING: DATA RACE; restored -> passes -race. Discipline: end() now stamps Finished under rec.mu with lock order table->record; get() takes table->snapshot (same order); notice/setState/snapshot take record only. No record->table path.

  4. e2e GENUINELY END-TO-END (internal/e2e/collab_test.go): token-mode server subprocess (alice admin + bob writer), real git with preemptive Bearer header, real httptest webhook sink. Asserts every stage: issue num 1, PR num 2, blocked merge task -> error + unmerged, combined green after report, merge -> merged + issue closed + refs/heads/main advanced, tag/release/latest v1, tray non-empty, webhook body mentions repo, fork + cross-fork PR num 3. Full package: 8/8 PASS (46.5s), incl. TestE2E_CollabFullChain 8.21s.

  5. CI CORRECT: .github/workflows/docker.yml parses as valid YAML; added steps run real targets (make cover, make e2e). Makefile ci = vet test race cover contract e2e matches the 15_testing.md S7 block; .woodpecker/pipeline.yaml already runs cover/e2e/contract as separate steps so no change needed there. Dropping sim from the doc recipe is honestly justified (internal/sim does not exist yet).

  6. Fork deferral HONEST, not a scope cut: ForkExecutor nil is byte-identical on main and the PR branch (internal/pulls/merge.go:527-637 pre-existing); chain step 12 seeds the fork head by direct push and says so; 09 S7 + 03 Decisions record the deferral with the GC rule standing as the future contract.

  7. PURE INTEGRATION holds: zero new routes/fields/families/task kinds/policy effects in Wave E (collab.go chains existing handlers only; serve.go is a verbatim move into buildCollab/chainCollab; tasks.go is lock-only). 03's two endpoints are disclosed as own-wave additions.

  8. EVIDENCE E10 plausible: 8/9/0 reproduced to the op; chain wall here ~3s after the documented ~5s binary build vs 2.2s claimed (labeled this-run, same order).

NON-BLOCKING NOTES: (a) web/dist/.keep is tracked nowhere on main either, though AGENTS.md says it is - pre-existing drift, out of scope. (b) Bare-worktree e2e fails on /setup 500 until make web runs - expected per AGENTS.md; both pipelines build web before test, order holds.

TEST RESULTS: gofmt clean; go vet clean (cmd/walhub, internal/pulls, internal/e2e); TestPushFastPathZeroCollabRoundTrips -race PASS; internal/pulls -race -short PASS (97.8% cover); internal/store contract PASS; internal/e2e full PASS 8/8.

MERGE RECOMMENDATION: ready to merge.

PR #20 review (scratch worktree @ b0925bd, go1.27.1, git 2.53.0). All checks done in /tmp/pr20; main worktree untouched, nothing committed. VERIFIED CLEAN 1. S4 audit file:line claims (spot-checked ~10, all accurate): CITokenScope internal/checks/model.go:134 exact; handler-side CI check internal/checks/service.go:165-183; Seam 2 ExtraCredential hook internal/server/auth.go:39-54 + registration cmd/walhub/checks.go:54; require_read gate internal/identity/gate.go CheckRead + internal/server/server.go readGate / internal/server/bind_api.go ReadGate+checkReadGate; team:/role: expansion + ProtectEffect.Evaluate ignoring RequireChecks internal/policy/effect_protect.go:154-157; merge-task gates internal/pulls/merge.go:159-168; key shapes internal/checks/checks.go:187-209. Touch-1 amendment (wct_ bucket token, not a Principal field) matches the code. 2. Push fence SOUND (cmd/walhub/push_budget_test.go): countingStore wraps the one shared store behind reg+engine+env+collab, so any collab read counts. Overrides cover Get/Head/Put/Delete/List/ListPrefixes/Compose; GetBytes/PutBytes (internal/store/store.go:199,226) are package funcs delegating to the counted methods; SignedGetURL/AccelTarget are only reached from bundle/static serve paths, not receive-pack. Classifier covers every family I could enumerate (reviews live under pulls/, social/forks/ci_tokens under meta/, webhooks/collab-events/issues/releases/access.json/users/orgs all present; policy.json excluded by documented design). REPRODUCED EXACTLY: cold 8 ops / warm 9 ops / 0 collab, real git 2.53.0 over real HTTP receive-pack. 3. Data race REAL + fix CORRECT: reverted internal/pulls/tasks.go to main in scratch -> TestCoverTaskEndSnapshotRace FAILS with WARNING: DATA RACE; restored -> passes -race. Discipline: end() now stamps Finished under rec.mu with lock order table->record; get() takes table->snapshot (same order); notice/setState/snapshot take record only. No record->table path. 4. e2e GENUINELY END-TO-END (internal/e2e/collab_test.go): token-mode server subprocess (alice admin + bob writer), real git with preemptive Bearer header, real httptest webhook sink. Asserts every stage: issue num 1, PR num 2, blocked merge task -> error + unmerged, combined green after report, merge -> merged + issue closed + refs/heads/main advanced, tag/release/latest v1, tray non-empty, webhook body mentions repo, fork + cross-fork PR num 3. Full package: 8/8 PASS (46.5s), incl. TestE2E_CollabFullChain 8.21s. 5. CI CORRECT: .github/workflows/docker.yml parses as valid YAML; added steps run real targets (make cover, make e2e). Makefile ci = vet test race cover contract e2e matches the 15_testing.md S7 block; .woodpecker/pipeline.yaml already runs cover/e2e/contract as separate steps so no change needed there. Dropping sim from the doc recipe is honestly justified (internal/sim does not exist yet). 6. Fork deferral HONEST, not a scope cut: ForkExecutor nil is byte-identical on main and the PR branch (internal/pulls/merge.go:527-637 pre-existing); chain step 12 seeds the fork head by direct push and says so; 09 S7 + 03 Decisions record the deferral with the GC rule standing as the future contract. 7. PURE INTEGRATION holds: zero new routes/fields/families/task kinds/policy effects in Wave E (collab.go chains existing handlers only; serve.go is a verbatim move into buildCollab/chainCollab; tasks.go is lock-only). 03's two endpoints are disclosed as own-wave additions. 8. EVIDENCE E10 plausible: 8/9/0 reproduced to the op; chain wall here ~3s after the documented ~5s binary build vs 2.2s claimed (labeled this-run, same order). NON-BLOCKING NOTES: (a) web/dist/.keep is tracked nowhere on main either, though AGENTS.md says it is - pre-existing drift, out of scope. (b) Bare-worktree e2e fails on /setup 500 until make web runs - expected per AGENTS.md; both pipelines build web before test, order holds. TEST RESULTS: gofmt clean; go vet clean (cmd/walhub, internal/pulls, internal/e2e); TestPushFastPathZeroCollabRoundTrips -race PASS; internal/pulls -race -short PASS (97.8% cover); internal/store contract PASS; internal/e2e full PASS 8/8. MERGE RECOMMENDATION: ready to merge.
Author
Owner

Feature 09 complete: PR #20 reviewed clean on first pass (push-fence reproduced, race fix verified real, e2e 8/8), merged. Closing.

Feature 09 complete: PR #20 reviewed clean on first pass (push-fence reproduced, race fix verified real, e2e 8/8), merged. Closing.
crueber added this to the v1 milestone 2026-09-10 22:27:24 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
crueber/walhub#15
No description provided.