Skip to content

docs: record v6.5.11 publication and retrospective - #146

Merged
flyingrobots merged 1 commit into
mainfrom
docs/6.5.11-publication
Oct 2, 2026
Merged

flyingrobots merged 1 commit into
mainfrom
docs/6.5.11-publication

Conversation

@flyingrobots

Copy link
Copy Markdown
Member

Outcome

Replace candidate/current-release drift with verified v6.5.11 publication evidence. Record the signed tag, source commit, registry integrity/provenance, merged-main release gates and independent Docker registry-consumer checks, plus the required cycle retrospective. Historical candidate and older publication receipts remain intact.

Fixes #145. Follows #131 and PR #132. No runtime change, publication, artifact replacement or version bump.

Validation

COPY-based Docker: 77 documentation checks passed; full Node unit run passed2,206 with two existing skips; lint passed. The documentation run caught relative links to unpackaged planning evidence; public Markdown now uses durable GitHub links, and v6.5.11 joins the package-documentation inventory. The historical v6.5.10 guard now checks its retained artifact posture rather than wrongly requiring it to remain the latest release.

The published artifact is immutable. These repository documentation corrections take effect on main; they do not rewrite the already-published npm tarball. Git-warp #923 retains downstream adoption/GC acceptance responsibility; public attachment capability remains separate.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 2b34e29a-1723-4fba-b7f6-543a305b0a3a

📥 Commits

Reviewing files that changed from the base of the PR and between 1bcd631 and 0d17361.

📒 Files selected for processing (10)
  • BEARING.md
  • README.md
  • STATUS.md
  • docs/design/0062-mktree-transport-recovery/mktree-transport-recovery.md
  • docs/design/0062-mktree-transport-recovery/witness/publication.json
  • docs/design/0062-mktree-transport-recovery/witness/release-publication.md
  • docs/method/retro/0062-mktree-transport-recovery/mktree-transport-recovery.md
  • docs/releases/v6.5.11.md
  • test/unit/docs/package-docs.test.js
  • test/unit/docs/release-state.test.js
 _____________________________________
< ICBM: Intercontinental Bug Missile. >
 -------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Member Author

Full independent feedback below. Clarification to informational finding146-01: the corrected GitHub link applies to the repository and future packages; the existing6.5.11 tarball retains its original candidate documentation, as the PR explicitly states. No immutable artifact is rewritten.

The independent binding adversarial CodeLawyer review and evaluation plan for git-stunts/git-cas PR #146 has been compiled and saved to the plan artifact:

Implementation Plan Artifact: [codelawyer_pr146_review_plan.md](/codelawyer_pr146_review_plan.md)

Key Assessment Highlights & Decisions

  • Immutability of Published Package: Published @git-stunts/git-cas@6.5.11 is immutable in the public npm registry. Documentation corrections (such as absolute GitHub links for preparatory evidence to eliminate unpackaged relative links) take effect on main and in future package artifacts without modifying the released npm tarball or bumping versions.
  • Evidence Cross-Verification: All cryptographic digests (releaseVerification.rawLogSha256, publicConsumer.rawLogSha256), signed tag object a77ebbdff9b5e2bbce73f90e8d51a5d0cd71b98d, npm gitHead (1bcd6311e93ca9782e2f4a25af106af0651813fb), exact mathematical observation counts ($2,204 + 2,204 + 2,195 + 207 + 207 + 207 = 7,224$), and consumer verification numbers match raw logs and registry metadata.
  • Test Variance Accounted For: The variance between the 14-stage verifier (2,204 pass, 3 skip) and the persistent validation container (2,206 pass, 2 skip) is verified down to the exact test cases: 1 added doc test in test/unit/docs/release-state.test.js and 1 unskipped link check in test/unit/docs/markdown-links.test.js.
  • Downstream Boundaries Preserved: Distinctions between the CAS mktree transport fix (git-warp #923), bounded streams (git-warp #818), and public attachment APIs (git-warp #901) are explicitly preserved.
  • Final Verdict: APPROVE

Please review the detailed plan and verification checklist in the artifact and indicate if you would like to proceed.

Independent Binding Adversarial CodeLawyer Review

Repository: git-stunts/git-cas
Pull Request: #146 (docs: record v6.5.11 publication and release retrospective)
Head Commit: 0d1736112bcb34ff93fb8f05a927154b19f025e7 (docs/6.5.11-publication)
Base Target: 1bcd6311e93ca9782e2f4a25af106af0651813fb (origin/main, tag v6.5.11)
Tracking Issue: Fixes #145, follows #131 and PR #132
Discovery Data: [<temporary-evidence>/git-cas-lawyer-146-discovery.json](/git-cas-lawyer-146-discovery.json)
Registry Truth: [<temporary-evidence>/git-cas-6.5.11-registry.json](/git-cas-6.5.11-registry.json)
Mode: Read-only adversarial review (zero runtime code changed, no host tests, no merges, no subagents, no external network posts).


1. Findings (P0–P5)

No functional regressions, broken contracts, data integrity risks, or untruthful claims were discovered across the 10-file diff.

Finding 146-01: Packaged Release Notes Reference GitHub PR URL for Publication Witness

Finding 146-02: Honest Disclosure of Upstream ESLint 9 Deprecation in Deno


2. Mandatory Verification Checklist

Code Path Tracing (file:line to file:line)

Merge Audit (SHAs and Integration Invariants)

Constants and Claims Against Raw Evidence

  • DEFAULT_MAX_BLOB_SIZE = 10 * 1024 * 1024 (10 MiB, cited in BEARING.md:27, defined in GitPersistenceAdapter.js:22).
  • DEFAULT_POLICY = Policy.timeout(30_000) (30 seconds, GitPersistenceAdapter.js:21).
  • DEFAULT_SESSION_IDLE_TIMEOUT_MS = 1_000 (1 second, GitPersistenceAdapter.js:25).
  • Bounded 1-retry limit on transport failure: verified by GitPersistenceAdapter.mktree-recovery.test.js:73-81 where openings() equals 2 before throwing GitProtocolError.
  • Consumer fixture payload: 512,000 bytes, 2 chunks stored and restored with exact byte match ([<temporary-evidence>/git-cas-6511-public-consumer.log:22, 28, 46-48](/git-cas-6511-public-consumer.log#L22-L48)).
  • Npm verified signatures and attestations: 63 signatures and 31 attestations ([<temporary-evidence>/git-cas-6511-public-consumer.log:3, 5](/git-cas-6511-public-consumer.log#L3-L5), matching publication.json:29-30).
  • Tag object: a77ebbdff9b5e2bbce73f90e8d51a5d0cd71b98d peels to 1bcd6311e93ca9782e2f4a25af106af0651813fb (verified via git cat-file -p v6.5.11).
  • Registry gitHead: 1bcd6311e93ca9782e2f4a25af106af0651813fb ([<temporary-evidence>/git-cas-6.5.11-registry.json:53](/git-cas-6.5.11-registry.json#L53)).
  • Registry integrity: sha512-C6coWmKmOeRZ+X5nP5Ek7spwYpA5q6mgif09u9dDO0ISQQ+Hz4KVxAXrOPRRhNJzLEP74Ndbra55fxX5Cms5gw== ([<temporary-evidence>/git-cas-6.5.11-registry.json:12](/git-cas-6.5.11-registry.json#L12)).
  • Registry shasum: 184c18fce40629afd28a897cbf3672cb4cc0d43e ([<temporary-evidence>/git-cas-6.5.11-registry.json:9](/git-cas-6.5.11-registry.json#L9)).
  • Release workflow run: 37008258240.
  • Cache 404 resolution: Documented in release-publication.md:7 that fresh registry metadata resolved visibility before consumer execution.

Numeric Claims Checked by Explicit Math

  • 7,224 observations: Verified across [<temporary-evidence>/git-cas-merged-main-release-verify.log:3475-3490](/git-cas-merged-main-release-verify.log#L3475-L3490):
    $$\text{Unit Node (2204)} + \text{Unit Bun (2204)} + \text{Unit Deno (2195)} + \text{Integration Node (207)} + \text{Integration Bun (207)} + \text{Integration Deno (207)} = 7,224$$
    Exact mathematical equality holds.
  • 77 documentation checks: Verified in [<temporary-evidence>/git-cas-6511-publication-docs-green.log:28](/git-cas-6511-publication-docs-green.log#L28) (14 files passed, 77 passed).
  • Node unit suite variance:
    • Compose 14-stage release verifier ([<temporary-evidence>/git-cas-merged-main-release-verify.log:353-354](/git-cas-merged-main-release-verify.log#L353-L354)): 2,204 passed, 3 skipped (total 2,207). Skips: GitPersistenceAdapter.writeBlob.test.js (1), CasService.kdf.test.js (1), markdown-links.test.js (1, skipped because .git is not mounted in Compose containers).
    • Validation container run ([<temporary-evidence>/git-cas-6511-publication-unit.log:265-266](/git-cas-6511-publication-unit.log#L265-L266)): 2,206 passed, 2 skipped (total 2,208). Variance explained: +1 new test in release-state.test.js, and markdown-links.test.js executed (unskipped) due to presence of .git. Net: $+2$ passed, $-1$ skipped.

Raw Evidence Digests

  • releaseVerification.rawLogSha256: cdefc3ed121de8e861b984c31cf5ee48d73aea05eca0632d1de3972864e71e09 (matches shasum -a 256 <temporary-evidence>/git-cas-merged-main-release-verify.log).
  • publicConsumer.rawLogSha256: 42d7195c11774f9c2cc0aff0b55d72372383f30a24e98774548acb732c3c81c2 (matches shasum -a 256 <temporary-evidence>/git-cas-6511-public-consumer.log).
  • publication-docs-green.log: b8f493cf7433ef61ec6ac4bd4c89ba1afed4f4c9847a14b166ed974aaccfd8a5.
  • publication-unit.log: 93f3ae4f104c57330bfeef04fd264902f456962cfe902b9f253a424583fbd1a0.

3. State of Checks

  • Executed:
    • shasum -a 256 digest calculation for all raw log files in /tmp.
    • git rev-parse and git cat-file -p verification for tag v6.5.11 and commit 1bcd631.
    • git rev-parse and git merge-base inspection for PR Adopt Plumbing mktree recovery for git-cas 6.5.11 #132 parentage.
    • git diff comparison between 1bcd631 and PR Adopt Plumbing mktree recovery for git-cas 6.5.11 #132 branch head 243592c.
    • git diff comparison across all 10 modified files between 1bcd631 and 0d17361.
    • JSON attribute cross-validation between publication.json, <temporary-evidence>/git-cas-6.5.11-registry.json, and <temporary-evidence>/git-cas-lawyer-146-discovery.json.
  • Inspected Only:
    • <temporary-evidence>/git-cas-merged-main-release-verify.log (3,491 lines, 14 release gates).
    • <temporary-evidence>/git-cas-6511-public-consumer.log (77 lines, consumer fixture run).
    • <temporary-evidence>/git-cas-6511-publication-docs-green.log (35 lines, 77 passed doc tests).
    • <temporary-evidence>/git-cas-6511-publication-unit.log (269 lines, 2,206 passed unit tests).
  • Skipped:
    • Re-execution of the 7,224 multi-runtime test suite (explicitly prohibited in read-only review mandate without unresolved reason).
    • Host execution of tests (prohibited by repository test runtime policy in test/CONVENTIONS.md:71).
  • Unavailable:
    • Live external network calls to GitHub and npm registry (audited against local authoritative registry dump <temporary-evidence>/git-cas-6.5.11-registry.json and discovery file <temporary-evidence>/git-cas-lawyer-146-discovery.json).

4. Final Verdict

APPROVE

@flyingrobots

Copy link
Copy Markdown
Member Author

Code Lawyer activity summary

Exact head0d1736112bcb34ff93fb8f05a927154b19f025e7 independently approved with the complete checklist. No actionable review findings remain. Registry/tag/source identities and raw-log digests were rechecked. Informational observations about package links and the disclosed ESLint9 warning require no further code change.

Docker validation:77 documentation checks pass, full Node suite2,206 pass/two existing skips, lint passes. Hosted lint and all three runtime jobs are green. Historical evidence stays pinned, current-release markers match the published6.5.11 receipt, and no runtime or immutable artifact changed. The published tarball's candidate wording is not retroactively corrected.

Merge gate open for this documentation/retrospective scope. Merge already authorized; no bypass requested.

@flyingrobots
flyingrobots marked this pull request as ready for review October 2, 2026 13:11
@flyingrobots
flyingrobots merged commit da9d38b into main Oct 2, 2026
6 checks passed
@flyingrobots
flyingrobots deleted the docs/6.5.11-publication branch October 2, 2026 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Record v6.5.11 publication and post-release drift check

1 participant