Skip to content

Release: qualify and publish basic supervised Slack ingress in v1.5.0 #923

Description

@jeffhuber

Canonical basic-Slack v1.5.0 release gate — owner-approved, reconciled 2026-09-17

This section supersedes older dependency and acceptance text below where it conflicts.

Final publication follows candidate canaries; the final published package is not a canary prerequisite. #921/#978, rich Slack UX, Slack Connect, public channels, broad provider selection and optional #951 are v1.5.1.

Part of #903 and roadmap #900.

v1.5.0 release and qualification

Dependencies

Final acceptance

  • Complete and cancel bounded work through the qualified Slack-to-supervisor path.
  • Verify signature/replay handling, durable receipt-before-ack, deduplication, retries, clarification answers and uncertain-create reconciliation.
  • Verify privacy, tenant isolation, retention/deletion, restart recovery, rate limiting and least-privilege scopes.
  • Verify local Board, stored metadata receipt and freshly observed hosted aggregate views independently.
  • Verify hosted deployment and rollback evidence.
  • Pass source/package builds, fresh install, upgrade and default/no-optional-provider rehearsals.
  • Include PR Fix Graphify inventory limits and frontend test discovery #1007's post-v1.4.2 Graphify compatibility fixes in the published release notes; rebuild only generations those gaps left affected/partial.
  • Obtain an independent exact-head release audit with zero P0/P1/P2 findings, green CI and authoritative gate.
  • Publish and verify v1.5.0 artifacts, then update Epic: Basic supervised Slack ingress for v1.5.0 #903/Roadmap through v1.5.0: bounded builders, Graphify, Board, and supervised Slack #900 with final evidence.

Paid completion/cancellation canaries require explicit campaign-wide caps. Provider exit, implementation completion, reviewed head, authorized/settled spend, stored receipt and fresh aggregate visibility remain separate evidence.


Owner-approved basic Slack release gate (2026-09-17)

Required dependencies

#951, #921, and #978 are v1.5.1 work and do not block v1.5.0.

Final acceptance

  • One private workspace and explicit immutable user/channel/repository policy pass.
  • Private start, status, answer, completion, and cancellation work through one qualified supervisor/hosted-builder path.
  • One capped completion canary reaches verified PR/head completion.
  • One capped cancellation canary records acknowledgement and observed provider exit.
  • Replay, deduplication, restart recovery, revocation, uncertain mutation handling, least privilege, and privacy pass.
  • Fresh default install remains Slack-free; opt-in fresh install and upgrade rehearsals pass.
  • Hosted rollout, rollback, disable, and uninstall evidence pass.
  • Source/package checks, independent exact-head release audit, CI, and authoritative gate pass.
  • v1.5.0 artifacts are published and independently reinstalled.
  • Roadmap through v1.5.0: bounded builders, Graphify, Board, and supervised Slack #900 and Epic: Basic supervised Slack ingress for v1.5.0 #903 receive final immutable evidence.

Activity

added
enhancementNew feature or request
serial-releaseSerialize because it changes release, gate, or final adoption posture
on Sep 12, 2026

jeffhuber commented on Sep 17, 2026

@jeffhuber
ContributorAuthor

v1.4.1 independent adoption feedback incorporated

The upgrade rehearsal confirmed the core install path, PyPI/tag/version alignment, doctor, lane status, session-lease guidance, and fresh Board startup. Follow-up is now mapped as follows:

The published v1.4.1 tag remains immutable. Current main has corrected prose; #1014 prevents recurrence for v1.5.0 rather than rewriting history.

jeffhuber commented on Sep 18, 2026

@jeffhuber
ContributorAuthor

Provenance convergence update: stage 1 of #1020 merged through #1021 at 1888cd4740da76cd03f7e062ef23c62f74f3a41e with green CI, exact-head Codex PASS and the authoritative gate. Stage 2 is now #1022 and is active in the Code Mower Codex builder lane. #1020 remains open until same-owner local audits publish through the trusted workflow without a routine override.

changed the title [-]Release: qualify and publish Slack session ingress in v1.5.0[/-] [+]Release: qualify and publish basic supervised Slack ingress in v1.5.0[/+] on Sep 18, 2026

jeffhuber commented on Sep 18, 2026

@jeffhuber
ContributorAuthor

Roadmap update: provenance stage 2 is complete. PR #1023 merged as a6b2e32804dcd16153fdcf4efe70c35e4fbe592e after exact-head Claude PASS, separate trust review PASS, green CI, and the one-time bootstrap owner override. The next #922 implementation PR is the live acceptance proof for workflow-attested local audits without routine owner identity override.

The narrowed v1.5.0 critical path is now: minimal #922 in parallel with #918 private admin readiness; immutable candidate artifacts; install/upgrade/rollback rehearsal; the two explicitly capped #920 canaries; exact-head release audit; publication; and independent reinstall verification.

jeffhuber commented on Sep 18, 2026

@jeffhuber
ContributorAuthor

Roadmap mapping update: #1027 is the single release-prep PR boundary for the immutable 1.5.0 candidate and its fresh-install, explicit Slack opt-in, v1.4.2 upgrade, disable/uninstall, rollback, package-inventory, and release-text rehearsals. It follows #1025/#1024, feeds #918 private acceptance and #920 capped canaries, and leaves tag/package publication to #923 after those gates pass.

jeffhuber commented on Sep 18, 2026

@jeffhuber
ContributorAuthor

Release dependency update: #1029 is required in the v1.5.0 candidate before the #1027 package/rehearsal PR freezes. It consumes the already-merged #1007 reader changes, adds readiness/query parity and actionable compatibility diagnostics, and must preserve usable bounded-partial query semantics. No private graph data or adoption evidence enters public artifacts.

jeffhuber commented on Sep 18, 2026

@jeffhuber
ContributorAuthor

v1.5.0 candidate and release-path reconciliation:

The remaining serialized path is now: finish fresh provider telemetry inventory and synthetic OAuth preflight; run #918's isolated private admin lifecycle plus rollback; obtain the explicit 1-ACU-per-canary / 2-ACU-total / zero-recovery authorization and run #920's completion and confirmed-cancellation canaries; perform the final exact-head release audit; publish; independently reinstall; then close #918/#920/#923/#903/#900. No live Slack qualification or paid provider result is claimed by this update.

jeffhuber commented on Sep 18, 2026

@jeffhuber
ContributorAuthor

Candidate invalidated before live Slack mutation

Live #918 preflight found a contract mismatch in the retained candidate: its generated Slack manifest sends OAuth directly to the application callback, while the reviewed privacy boundary requires the dedicated query-scrubbing relay as Slack's sole redirect. The current candidate therefore cannot pass both manifest matching and the OAuth telemetry privacy gate.

Candidate run 35317161869 and its wheel/sdist remain immutable evidence, but they are invalid for publication and must not be tagged, uploaded, or used for #918/#920. No Slack app was created and no paid provider work was spent before this stop.

Corrective PR: #1035

The PR pins the relay redirect and separately pins the application command/interactivity routes in unit and installed-wheel rehearsal checks. After exact-head independent review, green CI, and the authoritative gate, merge it and build one new immutable candidate from that merge SHA. Resume #918 and the authorized two-canary campaign only against those replacement bytes.

jeffhuber commented on Sep 18, 2026

@jeffhuber
ContributorAuthor

Replacement immutable v1.5.0 candidate verified after the Slack OAuth relay correction.

  • Source merge: 027a249115d77ba7ce576a854cc1e817b119d0f6 (PR Slack: route OAuth through the privacy relay #1035)
  • Candidate run: 35330007032, first attempt, success
  • Wheel SHA-256: b76519639391cd2a8cac9828d08401f92c785b75334bd665f8ef73d1dcf871db
  • Sdist SHA-256: 0ed172c1950133bbca19c9a990dc3dc96933ca05de576d08f09818e3294d01fa
  • Manifest kind/version: candidate / 1.5.0, release PR 1035
  • Rehearsal: PASS for fresh install, explicit private Slack setup, offline disabled state, the three required Graphify checks, 1.4.2 upgrade, disposable rollback, and uninstall; synthetic state preserved.

The earlier candidate from d66e01db remains invalid and must not be published or installed. Private acceptance, live Slack lifecycle, paid canaries, and publication remain pending against this replacement candidate.

jeffhuber commented on Sep 18, 2026

@jeffhuber
ContributorAuthor

Candidate run 35330007032 is now invalidated and must not be published or installed for live acceptance.

The replacement candidate correctly fixed the Slack OAuth redirect, but release convergence exposed a separate release-critical defect: the trusted local-audit publication workflow cannot write its reservation/verdict comment on pull requests with its current read-only Pull requests permission. PR #1036 carries the narrow permission correction and a generated-workflow regression.

After #1036 passes an independent exact-head audit, CI and the authoritative gate, one new immutable candidate must be built from its merge SHA. No paid canary has run and no provider spend has occurred.

jeffhuber commented on Sep 18, 2026

@jeffhuber
ContributorAuthor

Replacement v1.5.0 immutable candidate verified

The prior candidate invalidations are superseded by a new immutable candidate built from merged PR #1036.

  • Source commit: 59fe054498ec2db5a43b782b75f5070f44a51320
  • Candidate run: https://github.com/codemower-ai/code-mower/actions/runs/35331968778
  • Wheel SHA-256: b8c1c0cec1fe33996df985beae53235f652ad069cc123f289d42ca148eb5888e
  • sdist SHA-256: 953ae03884d421e5dca3e315fcca4d69444b69a86162ebee61401be6554e2d65
  • Rehearsal: PASS; 10/10 fresh install, setup, Graphify, upgrade, rollback, and uninstall checks passed with synthetic state preserved.
  • Independent local verification: artifact manifest and digests match; hash-locked Python 3.12 installation from the canonically named retained wheel passed; the exact installed package passed the hosted-worker no-provider qualification with zero provider and GitHub calls.

This is the candidate to use for the remaining private-host qualification, Slack lifecycle, paid completion/cancellation canaries, and release audit. The earlier candidates remain invalidated.

jeffhuber commented on Sep 18, 2026

@jeffhuber
ContributorAuthor

Candidate invalidated by production privacy evidence

The candidate at 59fe054498ec2db5a43b782b75f5070f44a51320 is now invalidated before any live Slack or paid-provider request.

The deployed Cloudflare Worker had logs, traces, tails, Logpush, exports, bindings, previews, and workers.dev disabled, but the custom hostname remained inside customer-zone Security Analytics. Cloudflare documents that this sampled dataset covers all incoming zone traffic and retains it for up to seven days; its security log schema exposes request query strings. Slack OAuth sends code and state in that query, so the prior custom-domain boundary cannot support the release's suppression claim.

#1037 tracks the correction: pin the single production workers.dev route, disable previews, remove custom domains and zone routes, repeat the provider inventory and bounded marker probe, then build a new immutable candidate. No synthetic OAuth marker, real Slack authorization, or paid canary was run against the invalidated route.

jeffhuber commented on Sep 19, 2026

@jeffhuber
ContributorAuthor

Final v1.5.0 immutable candidate evidence

Required rehearsal checks passed:

  1. fresh default remains Slack-free with no network/service activation
  2. explicit Slack setup produces only the private manifest
  3. an all-green offline snapshot cannot claim live readiness
  4. offline disabled snapshot and local manifest removal
  5. Graphify excludes doc_ref while keeping the reader available
  6. Graphify ambiguity alone returns a usable partial answer
  7. Graphify wrong-distribution input returns bounded reader_incompatible diagnostics without leakage
  8. upgrade from 1.4.2 preserves synthetic state
  9. digest-verified disposable rollback to 1.4.2 preserves state
  10. uninstall preserves synthetic state

Candidate run 35416128989 from PR #1038 is superseded and invalid for publication because packaged source/documentation changed in #1039. All remaining #918, #920, and publication evidence must consume only run 35420055466 and the digest pair above.

jeffhuber commented on Sep 19, 2026

@jeffhuber
ContributorAuthor

Candidate supersession after pre-dispatch canary finding

The first completion-canary admission failed closed before any hosted builder/provider create. Durable evidence recorded one supervisor admission attempt, no maintained claim, no builder dispatch, no provider session, and no ACU spend. The original Slack task, campaign reservation, run binding, and zero-recovery-create rule remain in force; no replacement task or session was created.

The failure isolated a public release blocker: the supervisor's fixed codex exec --ignore-user-config invocation also discarded the isolated home's selected credential-store setting. Public #1041 fixed that boundary and merged at 3d3e1644dea8fa367ff58e0cc08d92d68160710d after a verified exact-head Claude PASS, full three-version CI, release-wheel rehearsal, Board qualification, and the authoritative gate.

Replacement immutable candidate:

  • workflow run: 35437294635
  • source: 3d3e1644dea8fa367ff58e0cc08d92d68160710d
  • wheel SHA-256: d4e805c63788f7bce24545a52b19f0e226298b5b72b15d955bf5dbb441c378c8
  • sdist SHA-256: e01c9d912593eaa00736aef4643f6769498bf54719f772ecdac799070377ee50
  • candidate/rehearsal status: PASS

The numeric authorization is unchanged: exactly two serialized tasks, 2 ACU per task, 4 ACU / USD 100 campaign cap, original expiry, and zero recovery creates. The same already reserved completion task will be owner-reconciled under its original binding after the private runtime lock is reviewed and deployed. Publication remains blocked until both required canaries pass.

jeffhuber commented on Sep 19, 2026

@jeffhuber
ContributorAuthor

Candidate supersession update: immutable candidate run 35439791442 now supersedes 35437294635 for the same authorized Slack completion/cancellation canary boundary. Source is 3ac849026023f909565934314aed9a05ed5cf16b; wheel SHA-256 is b4aa1b66cff94f205b84d079d12087c876f260715e7bc56429c2abb2ce60b0f8; sdist SHA-256 is ceaf89568589f332919ade4929f43e5fc51d3d6d2701fd268905fa60b10a38fe. Candidate build and disposable install/upgrade/rollback rehearsal passed.

This does not create a replacement Slack task, hosted binding, campaign reservation, or provider session. All failed admission attempts remain pre-dispatch with zero provider dispatch/message/cancel/collect operations; the existing 2 ACU task cap and 4 ACU aggregate cap are unchanged. The same durable task will resume only after the private host lock is advanced to this exact artifact.

jeffhuber commented on Sep 19, 2026

@jeffhuber
ContributorAuthor

Completion-canary reconciliation and bounded authorization update

The first paid completion canary dispatched exactly once and returned a verified implementation at PR #1044, exact head e8bfca41326622eb9984e5600606a03bc18a7d07. The head passed the full Python 3.12/3.13/3.14 matrix, Board and graph checks, release-wheel rehearsal, independent exact-head Claude and Codex audits, and the native code-mower/gate.

The canary is not counted as a passing end-to-end completion. The provider reported the structured result while its writer still reported running. At the maximum durable polling backoff, the private bridge's 60-second renewal window coincided with the 60-second poll delay; normal scheduling moved the next turn past claim expiry. The original task then held before it could request/record supervisor review completion. Every durable operation is recorded, there is no pending or uncertain mutation, and no replacement task or provider session was created. Owner recovery terminated only the original writer, and a fresh provider read confirmed actual exit. The held task and its reservation remain preserved.

The repository gate auto-merged #1044 after its audits despite the PR's unmerged-canary instruction, which also temporarily closed this issue. The issue is reopened. PR #1045 removes the resulting inaccurate unpackaged archive note; the immutable v1.5 candidate bytes and digests are unchanged.

A private bridge correction now renews early enough to cover the next bounded poll plus the configured supervisor decision timeout. Publication remains blocked until that correction is independently reviewed, deployed, and both live canaries pass.

The owner's existing USD 100 campaign authorization permits one replacement completion task after the confirmed exit and correction, followed by the original cancellation canary. Each remaining task stays capped at 2 ACU; the total reservation ceiling is therefore amended from 4 ACU to 6 ACU for at most three tasks including the preserved failed canary. Exactly one recovery create is allowed for this demonstrated bridge-timing defect; no further recovery creates are authorized. The original expiry and all clarification, fix, review, serialization, privacy, and uncertainty rules remain unchanged.

jeffhuber commented on Sep 19, 2026

@jeffhuber
ContributorAuthor

Final immutable candidate and bounded canary-equivalence evidence

The final reviewed release source is PR #1049, squash merge 197c0c6080afe2a7625d22b897f4027112cf4a01. Its exact head passed Codex and Claude merge-authority audits with zero P0/P1/P2 findings, full CI, and code-mower/gate before merge.

Final immutable candidate:

Run 35447075808 is superseded because #1049 changed packaged qualification text and the comparison tool. It remains immutable evidence and must not be tagged or published.

The machine-readable code_mower.canary_candidate_equivalence.v1 comparison from the retained paid-canary candidate (run 35439791442, source 3ac849026023f909565934314aed9a05ed5cf16b, wheel b4aa1b66cff94f205b84d079d12087c876f260715e7bc56429c2abb2ce60b0f8) to the final candidate passed:

  • ancestry: PASS
  • wheel member inventory: identical
  • package metadata headers: identical
  • required Slack, Graphify and supervisor members: byte-identical
  • unchanged wheel members: 335
  • changed wheel members, complete list:
    1. code_mower-1.5.0.data/data/share/code-mower/docs/graphify-setup.md
    2. code_mower-1.5.0.data/data/share/code-mower/docs/v150-qualification.md
    3. code_mower-1.5.0.data/data/share/code-mower/docs/v150-release-notes.md
    4. code_mower-1.5.0.data/data/share/code-mower/docs/v150-release-runbook.md
    5. code_mower-1.5.0.dist-info/METADATA (description body only; headers identical)
    6. code_mower-1.5.0.dist-info/RECORD
    7. code_mower/audit_publication.py
    8. code_mower/release_readiness.py
    9. code_mower/templates/workflows/local-audit-publication.yml.j2
    10. code_mower/templates/workflows/trailer-comment-labeler.yml.j2

Every other wheel member, including provider/session adapters, Slack setup/readiness/manifest, supervisor contracts, CLI/bootstrap, durable state/persistence, package dependencies and entry points, is byte-identical. No unknown or added member was accepted.

The changed audit-publication path was independently replayed at completion-canary PR #1047 head ddd85bf2e62761cd90df1da3af1fd29dfdbfab3f: the immutable Claude receipt and Codex receipt launched the default-branch receivers, restored both labels, and produced a green gate. PR #1047 remains intentionally closed and unmerged.

No provider session was created for this closeout or comparison. Publication remains blocked until the exact final wheel completes the private no-provider installation/administration lifecycle, after which the owner decision, tag, no-publish verification, PyPI publication, GitHub Release, canonical reinstall and temporary-variable cleanup remain.

jeffhuber commented on Sep 19, 2026

@jeffhuber
ContributorAuthor

Owner release decision — APPROVED

The v1.5.0 publication gate is satisfied:

The owner’s standing instruction is to drive v1.5.0 through release. Record this as the explicit decision to tag this exact source and publish only candidate run 35447905132, following the no-publish verification, production PyPI publication, canonical reinstall, GitHub Release asset comparison and release-event verification in the reviewed runbook. TestPyPI is optional and is not selected.

jeffhuber commented on Sep 19, 2026

@jeffhuber
ContributorAuthor

v1.5.0 publication closeout — COMPLETE

Code Mower v1.5.0 is fully published and independently verified.

Canonical PyPI independently exposed both files with the retained candidate digests. A fresh Python 3.12 environment installed code-mower==1.5.0 from canonical PyPI; both CLI entrypoints reported 1.5.0 and pip check passed. The canonical wheel passed all ten offline default install, Slack opt-in/disabled, Graphify, 1.4.2 upgrade, rollback, uninstall and synthetic-state-preservation checks.

The GitHub Release assets are byte-identical to both the retained candidate and canonical PyPI files. The release is public, non-prerelease and selected by the latest-release endpoint. The temporary candidate-run variable is removed. Repository-scoped PyPI and TestPyPI release-event switches remain explicitly false.

No unresolved provider mutation or exit uncertainty remains. Unknown settlement is preserved rather than rewritten. No private credentials, identities, mappings, logs, task prose or provider output were published.

jeffhuber commented on Sep 19, 2026

@jeffhuber
ContributorAuthor

Closed after tag, production PyPI, GitHub Release, release-event verification, asset comparison, canonical reinstall and temporary-variable cleanup all passed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestserial-releaseSerialize because it changes release, gate, or final adoption posture

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions