Skip to content

Tag reviewed main in release workflow - #22

Merged
senamakel merged 3 commits into
tinyhumansai:mainfrom
senamakel:tinybrowser-protected-release
Sep 25, 2026
Merged

senamakel merged 3 commits into
tinyhumansai:mainfrom
senamakel:tinybrowser-protected-release

Conversation

@senamakel

@senamakel senamakel commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Summary

Fix release preparation for protected main. Release run 36087226790 passed formatting, Clippy, build, tests, docs, and 90% per-file Chrome coverage, then created local v0.2.2 commit b59fa1c. GitHub rejected its direct HEAD:main push with GH013 because the new commit had no required Rust status; the workflow never pushed a tag or produced assets.

The workflow now accepts the version already merged through a normal PR. After all release checks pass, it verifies its checkout equals current protected main and Cargo metadata matches the requested version. It then creates an annotated tag on that exact commit, or reuses a tag only if it already points there. The workflow no longer creates or pushes a commit to main. The existing module matrices and immutable release steps continue from the tag.

After the separate v0.2.2 version PR is merged, dispatch with:

gh workflow run release.yml --repo tinyhumansai/tinybrowser --ref main -f release_version=0.2.2

Related issue

Failed Release run 36087226790.

API or behavior changes

The manual release input changes from a semantic bump/current choice to the exact version already merged on main. No product API change.

Validation

  • cargo fmt --all -- --check
  • cargo clippy --locked --all-targets --all-features -- -D warnings
  • cargo build --locked --all-targets --all-features
  • cargo test --locked --all-features --quiet
  • .github/scripts/test-tag-reviewed-release.sh
  • actionlint, shellcheck, bash -n, git diff --check

The shell test uses a local bare Git remote to prove wrong version/branch, unreviewed local HEAD, and stale tag fail; tag creation pushes only refs/tags/v0.2.2; rerunning with the same tag is idempotent.

Tests

Added the protected-release tag script test and wired it into CI and release preparation. No live GitHub tag was created by this PR.

Documentation

Updated AGENTS.md and the release spec/plan for the reviewed version PR and tag-only workflow.

Checklist

  • The change is focused on one logical change
  • No new allow attributes, ignored tests, or relaxed lints
  • No secrets, tokens, or environment files in the diff or description

Summary by CodeRabbit

  • Release Process

    • Releases now use a version already merged to main through a reviewed pull request. The release workflow tags that commit and builds the release without creating a version-update commit.
    • Release runs can be resumed when the existing version tag points to the same commit.
  • Documentation

    • Updated release guidance and plans to reflect the revised versioning and release process.
  • Tests

    • Added checks for release-tag creation, reuse, and rejection of invalid release conditions.

@tinysweeper

tinysweeper Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Updates the release workflow to tag an already-merged version on protected main instead of computing and pushing a version bump commit. Adds a new tagging script with validation and a test suite. Updates documentation to reflect the new process.

State: Ready for maintainer review
Priority: medium
Reviewed head: ae4f4f8a8605
Updated: 1790306324 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 0 Active findings 4
Tests 1 Noted findings 0
Documentation 3 Resolved findings 13
Configuration 3 Pending checks/questions 0

Completeness: Complete
Test assessment: Test coverage is assessed from changed tests and lane evidence; execution is not claimed without trusted check data.

What changed

The release workflow now accepts a release_version input and runs a script that validates the checkout is on main, the version matches, the commit is the current main commit, and creates or reuses an annotated tag. The CI workflow now runs the tag script's test suite. Documentation is updated.

Features

  • Added — Protected release tagging script: Enables tagging only from the current protected main commit with version and tag type validation (.github/scripts/tag-reviewed-release.sh)
  • Modified — Release workflow input change: Replaces the bump input with a release_version input, removing automatic version bump and commit logic (.github/workflows/release.yml)
  • Modified — Release process documentation update: Documents the new process of merging a version bump PR then dispatching the release (AGENTS.md, docs/plans/tinybus-module-release.md, docs/specs/tinybus-module-release.md)

Tests

  • shell script test — Tests that the tagging script rejects version mismatch, non-main branch, unreviewed commit, lightweight tags, and stale tags; and that it creates an annotated tag on the current main commit and reuses existing correct tags.: Covers many scenarios but does not test the race condition where main is updated between verification and tag push, as noted in the security review. (.github/scripts/test-tag-reviewed-release.sh)

Findings

  • medium · critique · Exercise a concurrent main update during tag creation — This only advances `origin/main` before invoking the release script, so it verifies a normal stale checkout but never exercises an update occurring after the script's `ls-remote` c (\.github/scripts/test\-tag\-reviewed\-release\.sh:77)
  • medium · security · Atomically verify main before pushing the release tag — The script checks `origin/main` and then performs the tag creation and push later. If another reviewed commit lands on `main` between this check and `git push`, this run can still (\.github/scripts/tag\-reviewed\-release\.sh:36)
  • medium · security · Exercise the concurrent-main-update race — This only tests a sequentially stale checkout. It does not create or simulate a main update between the release script's main verification and its tag push, so the existing time-of (\.github/scripts/test\-tag\-reviewed\-release\.sh:82)
  • medium · description · Atomically verify main while pushing the release tag — The script verifies that HEAD equals the current `origin/main` at line 37 and then pushes the tag later (line 60). If another reviewed commit is merged after this check but before (\(pull request description\))

Resolved this pass

  • Match the protected-main error emitted by the script
  • Require an existing release tag to be annotated
  • Document lightweight-tag reuse accurately
  • Require an existing release tag to be annotated
  • Match the protected-main error emitted by the script
  • Require an existing release tag to be annotated
  • Document lightweight-tag reuse accurately
  • Match the protected-main error emitted by the script
  • Require an existing release tag to be annotated
  • Document lightweight-tag reuse accurately
  • Match the protected-main error emitted by the script
  • Require an existing release tag to be annotated
  • Document lightweight-tag reuse accurately

Before merge

None.

Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 2 files; 2 findings. (1 already reported on an earlier push) (1 earlier finding(s) still open) _2 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._
  • Evidence: \.github/scripts/test\-tag\-reviewed\-release\.sh — Exercise a concurrent main update during tag creation

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 2 files; 2 findings. (1 earlier finding(s) still open) _2 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._
  • Evidence: \.github/scripts/tag\-reviewed\-release\.sh — Atomically verify main before pushing the release tag
  • Evidence: \.github/scripts/test\-tag\-reviewed\-release\.sh — Exercise the concurrent-main-update race

tests

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No behavioural change: nothing outside documentation, configuration and tests.

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This change updates the release workflow to tag an already-merged version on protected main instead of computing and pushing a version bump commit. The tagging script validates the checkout, version, and tag type, and creates or reuses an annotated tag. However, a race condition remains between verifying main and pushing the tag; a concurrent merge could cause the tag to be placed on a stale commit. _2 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._
  • Evidence: \(pull request description\) — Atomically verify main while pushing the release tag

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No behavioural change: nothing outside documentation, configuration and tests.
Evidence and run details
  • Models: ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash
  • Spend: $0.010665
  • Tokens: 273795 input · 23575 output · 39216 cached · 591 embedding
Head State Pass summary
004b3f2f6c03 changes requested 4 active finding(s), 2 resolved finding(s) (at 1790305414)
ae4f4f8a8605 ready for maintainer review 4 active finding(s), 13 resolved finding(s) (at 1790306324)

tinysweeper 0.1.0

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

  • Run on-demand review

This review includes 7 billable files and costs up to $1.75.

Or wait 41 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 44b9bd85-b14e-4bf5-b254-e07b3ec31c07

📥 Commits

Reviewing files that changed from the base of the PR and between 004b3f2 and ae4f4f8.

📒 Files selected for processing (7)
  • .github/scripts/tag-reviewed-release.sh
  • .github/scripts/test-tag-reviewed-release.sh
  • .github/workflows/ci.yml
  • .github/workflows/release.yml
  • AGENTS.md
  • docs/plans/tinybus-module-release.md
  • docs/specs/tinybus-module-release.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 93f946f5-ec9e-4342-8b63-742584f8b62a

📥 Commits

Reviewing files that changed from the base of the PR and between 0e719ef and 004b3f2.

📒 Files selected for processing (7)
  • .github/scripts/tag-reviewed-release.sh
  • .github/scripts/test-tag-reviewed-release.sh
  • .github/workflows/ci.yml
  • .github/workflows/release.yml
  • AGENTS.md
  • docs/plans/tinybus-module-release.md
  • docs/specs/tinybus-module-release.md

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The release workflow now takes a version already merged to protected main. A script validates the checkout and version, then creates or reuses a tag on the current main commit. CI tests the script, and release instructions describe the updated process.

Changes

Reviewed release flow

Layer / File(s) Summary
Tag validation and verification
.github/scripts/tag-reviewed-release.sh, .github/scripts/test-tag-reviewed-release.sh
The script checks the requested version, branch, repository root, working tree, package version, and remote main commit. It creates or reuses a tag only when the tag targets that commit. The integration test covers validation failures, tag creation and reuse, and rejection after main advances.
Workflow and release instructions
.github/workflows/release.yml, .github/workflows/ci.yml, AGENTS.md, docs/plans/tinybus-module-release.md, docs/specs/tinybus-module-release.md
The release workflow accepts a version already merged to main and invokes the tagging script. CI runs the integration test. The release instructions and documentation describe version updates through a reviewed PR and tagging the checked main commit.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant ReleaseWorkflow
  participant TagScript
  participant OriginMain
  participant GitHubOutput
  ReleaseWorkflow->>TagScript: Pass EXPECTED_VERSION
  TagScript->>OriginMain: Compare HEAD with current main
  TagScript->>OriginMain: Create or verify version tag
  TagScript->>GitHubOutput: Write crate, version, and tag
Loading

Merge Risk: ⚪ Minimal · up to 004b3

The release flow is ready to merge after normal checks. Tagging stays tied to the reviewed main commit, and subsequent jobs use that tag.

Architecture Summary

Architecture risk: 🔵 Low · up to 004b3

The change affects 2 systems.

Changed systems: docs, AGENTS.md

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — docs (service) was modified; 2 changed files map to changed impact.
  • observed — AGENTS.md (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in AGENTS.md: Release instructions replace workflow-owned version bumps and commits with a reviewed version-and-lockfile PR, then a manual run using the merged version. The workflow verifies the current protected main commit, creates or reuses a tag on that exact commit, builds packages, and creates a release; reruns resume only if the tag still targets that commit. The workflow does not push a new commit to main.
  • observed — Modified behavior in docs/plans/tinybus-module-release.md: The release step now requires merging a version-bump PR through protected main and dispatching a release for that version; it no longer says to push main and trigger a patch release.
  • observed — Modified behavior in docs/specs/tinybus-module-release.md: The contract adds that version bumps update the workspace manifest and lockfile in a reviewed PR, and that releases tag the checked, protected main commit without pushing a version commit directly to main.
  • observed — Modified behavior in .github/scripts/tag-reviewed-release.sh: Adds a release-tagging script with required version and output variables and a default package name. It validates the version format, main branch, repository-root location, clean tracked files and index, package version, and equality of local HEAD with remote main, failing with an error for each unmet check. It reuses the version tag only if it points to that HEAD, fails if an existing tag points elsewhere, or creates and pushes an annotated tag if absent; successful runs write the crate name, version, and tag to the GitHub output file.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (5 skipped: 5 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: tagging the reviewed protected main commit in the release workflow.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (5 skipped: 5 unsupported.)


A rabbit checks the tag with care
Then finds the right commit is there
A reviewed version takes its place
The release notes record the case
And carrots mark the finished race

Comment @coderabbitai help to get the list of available commands.

@senamakel senamakel mentioned this pull request Sep 25, 2026
9 tasks done

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 1 lane(s) blocking, worst finding is high.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0169 · 505,743 in / 30,141 out · 33,293 cached (7%) · flash, ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash, deepseek-v4-flash · 588 embedded
critique:    $0.0096 · 302,552 in / 15,894 out · 26,003 cached (9%) · gpt-5.6-luna, deepseek/deepseek-v4-flash
security:    $0.0047 · 179,680 in / 4,118 out  · 7,290 cached (4%)  · gpt-5.6-luna
description: $0.0003 · 11,699 in  / 3,374 out  · 0 cached (0%)      · deepseek-v4-flash

Comment thread .github/scripts/test-tag-reviewed-release.sh
Comment thread .github/scripts/tag-reviewed-release.sh
Comment thread .github/scripts/tag-reviewed-release.sh
@senamakel
senamakel merged commit 6c344c2 into tinyhumansai:main Sep 25, 2026
6 checks passed

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-blocking findings are resolved. Clearing the changes request.

             $0.0107 · 273,795 in / 23,575 out · 39,216 cached (14%) · ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash · 591 embedded
critique:    $0.0055 · 152,558 in / 10,771 out · 17,814 cached (12%) · gpt-5.6-luna, deepseek/deepseek-v4-flash
security:    $0.0028 · 101,610 in / 4,792 out  · 9,114 cached (9%)   · gpt-5.6-luna
description: $0.0012 · 12,462 in  / 5,159 out  · 12,288 cached (99%) · deepseek/deepseek-v4-flash

Comment thread .github/scripts/test-tag-reviewed-release.sh
Comment thread .github/scripts/tag-reviewed-release.sh
Comment thread .github/scripts/test-tag-reviewed-release.sh
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant