Repository navigation
Release: qualify and publish basic supervised Slack ingress in v1.5.0 #923
Description
Activity
v1.4.1 independent adoption feedback incorporated
The upgrade rehearsal confirmed the core install path, PyPI/tag/version alignment, doctor, lane status, session-lease guidance, and fresh Board startup. Follow-up is now mapped as follows:
- Board: manage persistent services and reject stale keepalive bindings during release restart #1001 (from Board: manage persistent services and reject stale keepalive bindings during release restart #961) already completed the observed Board process-loss problem with a managed persistent service lifecycle.
- Adoption polish: report effective review authority and superseded Devin bridge drift #955 already completed posture-scoped concise doctor output; warning count remains evidence, not a release target.
- Release integrity: reject transient publication text in final tags #1014 is the v1.5 release blocker that prevents final tags from retaining transient candidate/publication-pending text and removes the hard-coded prior release identity from publication.
- Adoption polish: explain drift direction and stabilize Board startup evidence #1015 owns the remaining adoption polish: explicit setup-drift operands/classification meaning, a bounded Board-startup visibility grace, concise install verification guidance, and extraction of detailed optional Devin setup from the universal prompt.
The published v1.4.1 tag remains immutable. Current main has corrected prose; #1014 prevents recurrence for v1.5.0 rather than rewriting history.
Provenance convergence update: stage 1 of #1020 merged through #1021 at 1888cd4740da76cd03f7e062ef23c62f74f3a41e with green CI, exact-head Codex PASS and the authoritative gate. Stage 2 is now #1022 and is active in the Code Mower Codex builder lane. #1020 remains open until same-owner local audits publish through the trusted workflow without a routine override.
Roadmap update: provenance stage 2 is complete. PR #1023 merged as a6b2e32804dcd16153fdcf4efe70c35e4fbe592e after exact-head Claude PASS, separate trust review PASS, green CI, and the one-time bootstrap owner override. The next #922 implementation PR is the live acceptance proof for workflow-attested local audits without routine owner identity override.
The narrowed v1.5.0 critical path is now: minimal #922 in parallel with #918 private admin readiness; immutable candidate artifacts; install/upgrade/rollback rehearsal; the two explicitly capped #920 canaries; exact-head release audit; publication; and independent reinstall verification.
Roadmap mapping update: #1027 is the single release-prep PR boundary for the immutable 1.5.0 candidate and its fresh-install, explicit Slack opt-in, v1.4.2 upgrade, disable/uninstall, rollback, package-inventory, and release-text rehearsals. It follows #1025/#1024, feeds #918 private acceptance and #920 capped canaries, and leaves tag/package publication to #923 after those gates pass.
Release dependency update: #1029 is required in the v1.5.0 candidate before the #1027 package/rehearsal PR freezes. It consumes the already-merged #1007 reader changes, adds readiness/query parity and actionable compatibility diagnostics, and must preserve usable bounded-partial query semantics. No private graph data or adoption evidence enters public artifacts.
v1.5.0 candidate and release-path reconciliation:
- Audit publication: verify repository-dispatch workflow identity correctly #1025 is complete and Slack: explicit private-workspace setup, readiness doctor and runbook #1024 merged; the provenance publication path and minimal opt-in Slack setup/readiness guidance are in the candidate.
- Release: build and rehearse the immutable v1.5.0 candidate #1027 completed through PR Release: prepare and rehearse the immutable v1.5.0 candidate #1033 at
d66e01db952e2528f0b5693508808cd068fbf718. Candidate workflow run35317161869produced immutable 1.5.0 artifacts; the wheel SHA-256 is08c8b44cdb4795e1bae939d190b2058b0c73084a856169734111898b9c868001and the sdist SHA-256 is91ab9b1407f6c482122338323f94ea7c66335e3dedded10b583bd44d33685313. - All ten offline candidate rehearsals passed, including default Slack-free install, explicit opt-in, v1.4.2 upgrade, disable/uninstall, rollback, package inventory, release-state integrity, and installed-wheel Graphify compatibility. The Fix Graphify inventory limits and frontend test discovery #1007/Graphify: validate query-reader compatibility before reporting search available #1029
doc_refquery-reader correction is therefore included in this candidate; it remains unreleased until v1.5.0 publication. - The authorized private OAuth relay correction is merged, the production application is deployed at its exact merge, and the relay is deployed in its disabled state. Exact-head CI and an independent Claude audit passed with zero P0/P1/P2/P3 findings.
The remaining serialized path is now: finish fresh provider telemetry inventory and synthetic OAuth preflight; run #918's isolated private admin lifecycle plus rollback; obtain the explicit 1-ACU-per-canary / 2-ACU-total / zero-recovery authorization and run #920's completion and confirmed-cancellation canaries; perform the final exact-head release audit; publish; independently reinstall; then close #918/#920/#923/#903/#900. No live Slack qualification or paid provider result is claimed by this update.
Candidate invalidated before live Slack mutation
Live #918 preflight found a contract mismatch in the retained candidate: its generated Slack manifest sends OAuth directly to the application callback, while the reviewed privacy boundary requires the dedicated query-scrubbing relay as Slack's sole redirect. The current candidate therefore cannot pass both manifest matching and the OAuth telemetry privacy gate.
Candidate run 35317161869 and its wheel/sdist remain immutable evidence, but they are invalid for publication and must not be tagged, uploaded, or used for #918/#920. No Slack app was created and no paid provider work was spent before this stop.
Corrective PR: #1035
The PR pins the relay redirect and separately pins the application command/interactivity routes in unit and installed-wheel rehearsal checks. After exact-head independent review, green CI, and the authoritative gate, merge it and build one new immutable candidate from that merge SHA. Resume #918 and the authorized two-canary campaign only against those replacement bytes.
Replacement immutable v1.5.0 candidate verified after the Slack OAuth relay correction.
- Source merge:
027a249115d77ba7ce576a854cc1e817b119d0f6(PR Slack: route OAuth through the privacy relay #1035) - Candidate run: 35330007032, first attempt, success
- Wheel SHA-256:
b76519639391cd2a8cac9828d08401f92c785b75334bd665f8ef73d1dcf871db - Sdist SHA-256:
0ed172c1950133bbca19c9a990dc3dc96933ca05de576d08f09818e3294d01fa - Manifest kind/version:
candidate/1.5.0, release PR1035 - Rehearsal: PASS for fresh install, explicit private Slack setup, offline disabled state, the three required Graphify checks, 1.4.2 upgrade, disposable rollback, and uninstall; synthetic state preserved.
The earlier candidate from d66e01db remains invalid and must not be published or installed. Private acceptance, live Slack lifecycle, paid canaries, and publication remain pending against this replacement candidate.
Candidate run 35330007032 is now invalidated and must not be published or installed for live acceptance.
The replacement candidate correctly fixed the Slack OAuth redirect, but release convergence exposed a separate release-critical defect: the trusted local-audit publication workflow cannot write its reservation/verdict comment on pull requests with its current read-only Pull requests permission. PR #1036 carries the narrow permission correction and a generated-workflow regression.
After #1036 passes an independent exact-head audit, CI and the authoritative gate, one new immutable candidate must be built from its merge SHA. No paid canary has run and no provider spend has occurred.
Replacement v1.5.0 immutable candidate verified
The prior candidate invalidations are superseded by a new immutable candidate built from merged PR #1036.
- Source commit:
59fe054498ec2db5a43b782b75f5070f44a51320 - Candidate run: https://github.com/codemower-ai/code-mower/actions/runs/35331968778
- Wheel SHA-256:
b8c1c0cec1fe33996df985beae53235f652ad069cc123f289d42ca148eb5888e - sdist SHA-256:
953ae03884d421e5dca3e315fcca4d69444b69a86162ebee61401be6554e2d65 - Rehearsal: PASS; 10/10 fresh install, setup, Graphify, upgrade, rollback, and uninstall checks passed with synthetic state preserved.
- Independent local verification: artifact manifest and digests match; hash-locked Python 3.12 installation from the canonically named retained wheel passed; the exact installed package passed the hosted-worker no-provider qualification with zero provider and GitHub calls.
This is the candidate to use for the remaining private-host qualification, Slack lifecycle, paid completion/cancellation canaries, and release audit. The earlier candidates remain invalidated.
Candidate invalidated by production privacy evidence
The candidate at 59fe054498ec2db5a43b782b75f5070f44a51320 is now invalidated before any live Slack or paid-provider request.
The deployed Cloudflare Worker had logs, traces, tails, Logpush, exports, bindings, previews, and workers.dev disabled, but the custom hostname remained inside customer-zone Security Analytics. Cloudflare documents that this sampled dataset covers all incoming zone traffic and retains it for up to seven days; its security log schema exposes request query strings. Slack OAuth sends code and state in that query, so the prior custom-domain boundary cannot support the release's suppression claim.
#1037 tracks the correction: pin the single production workers.dev route, disable previews, remove custom domains and zone routes, repeat the provider inventory and bounded marker probe, then build a new immutable candidate. No synthetic OAuth marker, real Slack authorization, or paid canary was run against the invalidated route.
Final v1.5.0 immutable candidate evidence
- Release preparation PR: Finalize v1.5.0 release identity and operator documentation #1039
- Reviewed merge SHA:
e5101a19626a16d5af17ebb2ea3a04318b76b91b - Candidate workflow: https://github.com/codemower-ai/code-mower/actions/runs/35420055466
- Workflow event/ref/attempt:
workflow_dispatch/main/ attempt 1 - Candidate result: PASS
- Wheel SHA-256:
621ae5fdaf9928b58384d88a3bc56772f0822cdb8fa4ad97886ffbe27d51709b - sdist SHA-256:
687dc3aeeb29e3b0daedd7a28eec82a7bb33a39c533880df12b0df08b3487cd3 - Artifact inventory verification: PASS
- Sanitized installed-wheel rehearsal: PASS
Required rehearsal checks passed:
- fresh default remains Slack-free with no network/service activation
- explicit Slack setup produces only the private manifest
- an all-green offline snapshot cannot claim live readiness
- offline disabled snapshot and local manifest removal
- Graphify excludes
doc_refwhile keeping the reader available - Graphify ambiguity alone returns a usable partial answer
- Graphify wrong-distribution input returns bounded
reader_incompatiblediagnostics without leakage - upgrade from 1.4.2 preserves synthetic state
- digest-verified disposable rollback to 1.4.2 preserves state
- uninstall preserves synthetic state
Candidate run 35416128989 from PR #1038 is superseded and invalid for publication because packaged source/documentation changed in #1039. All remaining #918, #920, and publication evidence must consume only run 35420055466 and the digest pair above.
Candidate supersession after pre-dispatch canary finding
The first completion-canary admission failed closed before any hosted builder/provider create. Durable evidence recorded one supervisor admission attempt, no maintained claim, no builder dispatch, no provider session, and no ACU spend. The original Slack task, campaign reservation, run binding, and zero-recovery-create rule remain in force; no replacement task or session was created.
The failure isolated a public release blocker: the supervisor's fixed codex exec --ignore-user-config invocation also discarded the isolated home's selected credential-store setting. Public #1041 fixed that boundary and merged at 3d3e1644dea8fa367ff58e0cc08d92d68160710d after a verified exact-head Claude PASS, full three-version CI, release-wheel rehearsal, Board qualification, and the authoritative gate.
Replacement immutable candidate:
- workflow run:
35437294635 - source:
3d3e1644dea8fa367ff58e0cc08d92d68160710d - wheel SHA-256:
d4e805c63788f7bce24545a52b19f0e226298b5b72b15d955bf5dbb441c378c8 - sdist SHA-256:
e01c9d912593eaa00736aef4643f6769498bf54719f772ecdac799070377ee50 - candidate/rehearsal status: PASS
The numeric authorization is unchanged: exactly two serialized tasks, 2 ACU per task, 4 ACU / USD 100 campaign cap, original expiry, and zero recovery creates. The same already reserved completion task will be owner-reconciled under its original binding after the private runtime lock is reviewed and deployed. Publication remains blocked until both required canaries pass.
Candidate supersession update: immutable candidate run 35439791442 now supersedes 35437294635 for the same authorized Slack completion/cancellation canary boundary. Source is 3ac849026023f909565934314aed9a05ed5cf16b; wheel SHA-256 is b4aa1b66cff94f205b84d079d12087c876f260715e7bc56429c2abb2ce60b0f8; sdist SHA-256 is ceaf89568589f332919ade4929f43e5fc51d3d6d2701fd268905fa60b10a38fe. Candidate build and disposable install/upgrade/rollback rehearsal passed.
This does not create a replacement Slack task, hosted binding, campaign reservation, or provider session. All failed admission attempts remain pre-dispatch with zero provider dispatch/message/cancel/collect operations; the existing 2 ACU task cap and 4 ACU aggregate cap are unchanged. The same durable task will resume only after the private host lock is advanced to this exact artifact.
Completion-canary reconciliation and bounded authorization update
The first paid completion canary dispatched exactly once and returned a verified implementation at PR #1044, exact head e8bfca41326622eb9984e5600606a03bc18a7d07. The head passed the full Python 3.12/3.13/3.14 matrix, Board and graph checks, release-wheel rehearsal, independent exact-head Claude and Codex audits, and the native code-mower/gate.
The canary is not counted as a passing end-to-end completion. The provider reported the structured result while its writer still reported running. At the maximum durable polling backoff, the private bridge's 60-second renewal window coincided with the 60-second poll delay; normal scheduling moved the next turn past claim expiry. The original task then held before it could request/record supervisor review completion. Every durable operation is recorded, there is no pending or uncertain mutation, and no replacement task or provider session was created. Owner recovery terminated only the original writer, and a fresh provider read confirmed actual exit. The held task and its reservation remain preserved.
The repository gate auto-merged #1044 after its audits despite the PR's unmerged-canary instruction, which also temporarily closed this issue. The issue is reopened. PR #1045 removes the resulting inaccurate unpackaged archive note; the immutable v1.5 candidate bytes and digests are unchanged.
A private bridge correction now renews early enough to cover the next bounded poll plus the configured supervisor decision timeout. Publication remains blocked until that correction is independently reviewed, deployed, and both live canaries pass.
The owner's existing USD 100 campaign authorization permits one replacement completion task after the confirmed exit and correction, followed by the original cancellation canary. Each remaining task stays capped at 2 ACU; the total reservation ceiling is therefore amended from 4 ACU to 6 ACU for at most three tasks including the preserved failed canary. Exactly one recovery create is allowed for this demonstrated bridge-timing defect; no further recovery creates are authorized. The original expiry and all clarification, fix, review, serialization, privacy, and uncertainty rules remain unchanged.
Final immutable candidate and bounded canary-equivalence evidence
The final reviewed release source is PR #1049, squash merge 197c0c6080afe2a7625d22b897f4027112cf4a01. Its exact head passed Codex and Claude merge-authority audits with zero P0/P1/P2 findings, full CI, and code-mower/gate before merge.
Final immutable candidate:
- workflow: https://github.com/codemower-ai/code-mower/actions/runs/35447905132
- event/ref/attempt:
workflow_dispatch/main/ attempt 1 - source / release PR:
197c0c6080afe2a7625d22b897f4027112cf4a01/ release: attest bounded v1.5 canary equivalence #1049 - wheel SHA-256:
4f2451a7801980a74c34908166cdba7f2e44e15f12a610733cef37bc8f483e06 - sdist SHA-256:
6d52d398237a5096fa23fbd496c9816f44a8f97b28de6f8c6ea43b948f5c7a19 - candidate/inventory verification: PASS
- installed-wheel rehearsal: PASS for all ten required install, Slack opt-in/disabled, Graphify, upgrade, rollback and uninstall checks
Run 35447075808 is superseded because #1049 changed packaged qualification text and the comparison tool. It remains immutable evidence and must not be tagged or published.
The machine-readable code_mower.canary_candidate_equivalence.v1 comparison from the retained paid-canary candidate (run 35439791442, source 3ac849026023f909565934314aed9a05ed5cf16b, wheel b4aa1b66cff94f205b84d079d12087c876f260715e7bc56429c2abb2ce60b0f8) to the final candidate passed:
- ancestry: PASS
- wheel member inventory: identical
- package metadata headers: identical
- required Slack, Graphify and supervisor members: byte-identical
- unchanged wheel members: 335
- changed wheel members, complete list:
code_mower-1.5.0.data/data/share/code-mower/docs/graphify-setup.mdcode_mower-1.5.0.data/data/share/code-mower/docs/v150-qualification.mdcode_mower-1.5.0.data/data/share/code-mower/docs/v150-release-notes.mdcode_mower-1.5.0.data/data/share/code-mower/docs/v150-release-runbook.mdcode_mower-1.5.0.dist-info/METADATA(description body only; headers identical)code_mower-1.5.0.dist-info/RECORDcode_mower/audit_publication.pycode_mower/release_readiness.pycode_mower/templates/workflows/local-audit-publication.yml.j2code_mower/templates/workflows/trailer-comment-labeler.yml.j2
Every other wheel member, including provider/session adapters, Slack setup/readiness/manifest, supervisor contracts, CLI/bootstrap, durable state/persistence, package dependencies and entry points, is byte-identical. No unknown or added member was accepted.
The changed audit-publication path was independently replayed at completion-canary PR #1047 head ddd85bf2e62761cd90df1da3af1fd29dfdbfab3f: the immutable Claude receipt and Codex receipt launched the default-branch receivers, restored both labels, and produced a green gate. PR #1047 remains intentionally closed and unmerged.
No provider session was created for this closeout or comparison. Publication remains blocked until the exact final wheel completes the private no-provider installation/administration lifecycle, after which the owner decision, tag, no-publish verification, PyPI publication, GitHub Release, canonical reinstall and temporary-variable cleanup remain.
Owner release decision — APPROVED
The v1.5.0 publication gate is satisfied:
- final reviewed source: PR release: attest bounded v1.5 canary equivalence #1049 /
197c0c6080afe2a7625d22b897f4027112cf4a01 - exact-head Codex and Claude audits: PASS with zero P0/P1/P2 findings
- full CI and authoritative gate: PASS
- immutable candidate run
35447905132: first-attempt PASS - wheel / sdist SHA-256:
4f2451a7801980a74c34908166cdba7f2e44e15f12a610733cef37bc8f483e06/6d52d398237a5096fa23fbd496c9816f44a8f97b28de6f8c6ea43b948f5c7a19 - all ten installed-wheel rehearsals: PASS
- CodeMower.com: single-workspace Slack OAuth installation and explicit policy binding #918 exact-final-wheel private administration: PASS
- Slack: Devin dispatch, clarification, completion, and cancellation bridge #920 accepted completion and confirmed-cancellation outcomes: PASS, count-preserved
- bounded candidate equivalence and exact-head audit-receipt replay: PASS
- no unresolved provider mutation or exit uncertainty; no further provider create authorized or required
- repository-scoped PyPI/TestPyPI release-event switches: explicitly
false v1.5.0tag, GitHub Release and production PyPI version: absent before publication
The owner’s standing instruction is to drive v1.5.0 through release. Record this as the explicit decision to tag this exact source and publish only candidate run 35447905132, following the no-publish verification, production PyPI publication, canonical reinstall, GitHub Release asset comparison and release-event verification in the reviewed runbook. TestPyPI is optional and is not selected.
v1.5.0 publication closeout — COMPLETE
Code Mower v1.5.0 is fully published and independently verified.
- Git tag:
v1.5.0→197c0c6080afe2a7625d22b897f4027112cf4a01 - GitHub Release: https://github.com/codemower-ai/code-mower/releases/tag/v1.5.0
- Production PyPI: https://pypi.org/project/code-mower/1.5.0/
- Final reviewed source: PR release: attest bounded v1.5 canary equivalence #1049
- Immutable candidate: run 35447905132
- Wheel SHA-256:
4f2451a7801980a74c34908166cdba7f2e44e15f12a610733cef37bc8f483e06 - Sdist SHA-256:
6d52d398237a5096fa23fbd496c9816f44a8f97b28de6f8c6ea43b948f5c7a19 - No-publish verification: run 35449469067, both publication jobs skipped
- Production PyPI publication: run 35449515374, PyPI passed and TestPyPI skipped
- GitHub Release-event verification: run 35449662780, candidate/distribution verification passed and both publication jobs skipped
- Exact-final-wheel private acceptance: CodeMower.com: single-workspace Slack OAuth installation and explicit policy binding #918 PASS
- Count-preserved completion/cancellation canaries: Slack: Devin dispatch, clarification, completion, and cancellation bridge #920 PASS
- Bounded candidate equivalence and audit-receipt replay: PASS
Canonical PyPI independently exposed both files with the retained candidate digests. A fresh Python 3.12 environment installed code-mower==1.5.0 from canonical PyPI; both CLI entrypoints reported 1.5.0 and pip check passed. The canonical wheel passed all ten offline default install, Slack opt-in/disabled, Graphify, 1.4.2 upgrade, rollback, uninstall and synthetic-state-preservation checks.
The GitHub Release assets are byte-identical to both the retained candidate and canonical PyPI files. The release is public, non-prerelease and selected by the latest-release endpoint. The temporary candidate-run variable is removed. Repository-scoped PyPI and TestPyPI release-event switches remain explicitly false.
No unresolved provider mutation or exit uncertainty remains. Unknown settlement is preserved rather than rewritten. No private credentials, identities, mappings, logs, task prose or provider output were published.
Closed after tag, production PyPI, GitHub Release, release-event verification, asset comparison, canonical reinstall and temporary-variable cleanup all passed.
Canonical basic-Slack v1.5.0 release gate — owner-approved, reconciled 2026-09-17
This section supersedes older dependency and acceptance text below where it conflicts.
Final publication follows candidate canaries; the final published package is not a canary prerequisite. #921/#978, rich Slack UX, Slack Connect, public channels, broad provider selection and optional #951 are v1.5.1.
Part of #903 and roadmap #900.
v1.5.0 release and qualification
Dependencies
Final acceptance
Paid completion/cancellation canaries require explicit campaign-wide caps. Provider exit, implementation completion, reviewed head, authorized/settled spend, stored receipt and fresh aggregate visibility remain separate evidence.
Owner-approved basic Slack release gate (2026-09-17)
Required dependencies
#951, #921, and #978 are v1.5.1 work and do not block v1.5.0.
Final acceptance