Feature 09: rollout integration (docs/features/09) #20
No reviewers
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub!20
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/integration"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Feature 09: rollout integration (docs/features/09)
Wave E, pure integration — no new product surface. Spec:
docs/features/09_rollout.md§§4–7 (now landed with as-built amendments). One behavior fix ships with a spec amendment (see Deviations).§4 touch-point audit (as-built; amendments in 09 §"As-built amendments")
checks:writecapabilityPrincipalfield, not a config scope — bucket-nativewct_CI token, secret verified handler-side per repointernal/checks/auth.go:11-19,internal/checks/service.go:165-181,internal/checks/model.go:134, Seam 2 hookinternal/server/auth.go:39-54, registeredcmd/walhub/checks.go:chainChecksrequire_read↔visibilityinternal/identity/gate.go:31-49, seaminternal/server/server.go:50-51,internal/server/bind_api.go:57-63,99-107, wiredcmd/walhub/collab.go:buildCollab+cmd/walhub/serve.go:readGateOf, consultedinternal/server/smart.go,internal/server/lfs.go:53, per-packageCheckReadseamsStaticTokenunchanged (internal/config/config.go:28-34) — CI tokens are bucket objects, not configteam:/role:actor sourcesinternal/policy/expansion.go:9-46,internal/identity/gate.go:94-192, boundcmd/walhub/collab.go:buildCollab(apiEnv.GroupExpander)require_checks/required-reviewsinternal/policy/effect_protect.go:15,101-118,internal/policy/effect_required_reviews.go, seamsinternal/pulls/checks.go:18-38,internal/pulls/review.go, call siteinternal/pulls/merge.go:159ProtectEffect.Evaluatenever consultsRequireChecks(internal/policy/effect_protect.go:154-157); fencecmd/walhub/push_budget_test.gofails on any collab key touched by a pushcmd/walhub/collab.go:chainCollab(identity, issues, pulls, review, checks, releases, social, notify); SSEinternal/notify/http.go:tray/stream,internal/notify/collab.go:collabStream,internal/notify/stream.go; assembly extracted fromserveHTTPintobuildCollab(pure move) so the measured composition IS the shipped one§5 invariant sweep (09 §"Wave E verification" + EVIDENCE.md E10)
Bucket-only (families enumerated, fence-classified), WAL git-only (no collab import of
internal/wal; PR heads via the WAL funnelcmd/walhub/pulls.go:pullsPublisher), push +0 round trips (measured: cold 8 ops, warm 9 ops, 0 collab keys), P3/P4 discipline, no LIST on git hot paths (E4–E6), tasks+SSE (E7/E9; chain observes merge taskerrorthenok).E2E (
internal/e2e/collab_test.go, tiered perdocs/go/15_testing.md§5.4)Token-mode server (alice admin + bob writer), real git (preemptive Bearer header — git never answers a Bearer 401), real webhook sink: org→team→bindings→watch+webhook→issue #1→branch push→PR #2 (
fixes #1)→bob APPROVED review→policy (require_checks: [ci/build], blocked merge taskerror, reported success → combined green)→merge→issue closed→tag+release+latest→alice tray + webhook delivery→fork→cross-fork PR #3 (P2 numbering). Wall 2.2 s. As-built scope pinned in-test: fork manifest-sharing deferred (ForkExecutornil), so the fork head is seeded by direct push and the chain proves the cross-fork open path.CI
make ci→vet test race cover contract e2e(Makefile);coverauto-discovers all eight collab packages at ≥95%.race/cover/e2e/contractsteps already run the new suites by discovery.docker.ymltest job): addedmake cover+make e2e(e2e skips on old git).docs/go/15_testing.md§§1/5.4/7) describe the new suites;simnoted as not-yet-existing (e2e is the proofciruns until then).Test results
make vetclean;gofmt -lclean (make fmt's empty-list-wquirk is pre-existing).make coverexit 0 — 44 packages, everyinternal/...≥95% (pulls 97.8% with the new test).go test -race -short ./...exit 0 (after the race fix below).go test ./internal/e2e/...green 45 s (chain 7 s).make contractgreen;node --test web/test/unit/*.test.jsgreen (no web changes).Deviations (each with spec amendment, law 12)
checks:writeas-built differs from the 09 plan (Seam 2 shape + handler-side scope, noPrincipal/config field) — amendment in 09 §4.taskTable.enddata race (pre-existing, Wave C): stampedFinishedunder the table mutex while polls snapshot under the record mutex — caught once by-raceunder full-suite load, pinned byTestCoverTaskEndSnapshotRace(fails pre-fix, passes post-fix), lock rule in 03 Decisions. Same-shape latent notes (NOT fixed here):internal/notifyreturns the live webhook record but discards it at all production sites;internal/waluses its own broadcast protocol, unexamined.ForkExecutornil) — recorded in 09 §4 + §7 risk re-check (retention rule stands as contract, nothing shared yet so nothing to mis-collect).make fmtfails on a clean tree (gofmt -wwith empty list) — pre-existing, untouched.Hygiene
Dirty worktree on
feat/issuesuntouched (status identical before/after; all work in a separate worktree). No merge — review requested.