Skip to content

Gate future releases and smoke-test installed packages - #169

Merged
JeremyKuhne merged 3 commits into
mainfrom
prepare-v0-10-release
Sep 30, 2026
Merged

JeremyKuhne merged 3 commits into
mainfrom
prepare-v0-10-release

Conversation

@JeremyKuhne

@JeremyKuhne JeremyKuhne commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

Finish the release-validation infrastructure shelved while v0.10.0 shipped. This applies to future releases; it does not alter the published tag or publish another package.

  • Gate publication on a clean merged-main candidate whose tree matches the exact reviewed PR head with successful agent-files, Linux ARM64, Windows and aggregate ci checks. Missing, failed, skipped, pending, ambiguous or incomplete evidence fails closed.
  • Inspect and install the exact CLI/MCP packages from an isolated local feed, validating package/tool/server versions and real installed CLI/MCP behavior before NuGet login.
  • Reuse the existing MCP protocol check for installed servers, preserving its built-binary defaults while bounding output, waits and owned-process cleanup.
  • Exercise provenance and fake package/process failure contracts plus real package smoke in Linux PR CI; document the operational contract in one focused guide.

No product analyzer changes, new dependencies, raw-capture regeneration, repository settings, tag changes, or package publication.

Validation

  • Zero-warning Release build; full Windows Release suite: 1,955 passed and one expected elevated-host skip.
  • CLI help, MCP schema/stdout/call, docs/package-isolation, pinned agent files/links, and all 31 deterministic trace tasks passed.
  • Provenance positive/negative query and exact-tree/CI tests passed.
  • Fake package metadata, native results, MCP stream/version/timeout/failure/cleanup, and missing-SDK tests passed.
  • Real local 0.10.0 pack/install smoke passed on Windows: CLI info/rank on copied speedscope, EventPipe and ETL, unknown-command rejection, exact MCP tool list and real initialize/list/call; owned work removed.
  • Executed the same CI pack/MinVer version-discovery/installed-smoke sequence without a version override; packed filenames and installed versions matched.
  • Bounded read-only pre-PR review found one MinVer static-property lookup error, corrected and verified by the no-override end-to-end smoke.
  • First Linux package smoke exposed multiple native application matches being joined into one path; SDK/git/gh lookup now selects the first ApplicationInfo, with actual-assignment regression witnesses for duplicate matches.
  • Review identified a post-response MCP shutdown hang reported as success; a respond-then-hang fake reproduced it, now fails with a shutdown diagnostic and confirmed child cleanup. Real built and installed servers still pass.
  • Both release provenance and package smoke now use the same semantic-version validator; regression cases cover hyphen prerelease identifiers and reject numeric leading zeros/build metadata.

Scope

The existing v0.10.0 release remains unchanged. Post-merge, only read-only release-provenance verification is planned; no publish workflow will be dispatched.

Finish the post-release validation infrastructure without changing the published v0.10.0 tag or product analyzer.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The MCP check currently accepts a server that responds successfully but hangs during shutdown.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Adds fail-closed release provenance checks and installed-package smoke validation for future releases.

Changes:

  • Verifies merged-main, reviewed-tree, and CI evidence.
  • Tests exact CLI/MCP packages in isolated environments.
  • Integrates release checks into CI, publishing, and documentation.
File Description
tools/​Test-ReleaseReadiness.ps1 Tests release provenance rejection paths.
tools/​Test-ReleasePackagesContract.ps1 Tests package and MCP failure contracts.
tools/​Test-ReleasePackages.ps1 Smoke-tests installed release packages.
tools/​Test-McpServer.ps1 Supports bounded installed-server validation.
tools/​ReleaseReadiness.psm1 Implements release evidence validation.
tools/​Assert-ReleaseReady.ps1 Provides the release-readiness entry point.
docs/​roadmap.md Records post-release validation status.
docs/​release-validation.md Documents the release-validation contract.
docs/​README.md Links the new guide.
AGENTS.md Documents new repository gates.
.github/​workflows/​publish.yml Gates publishing and smoke-tests packages.
.github/​workflows/​ci.yml Runs release contracts and package smoke tests.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tools/Test-McpServer.ps1
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The package-smoke version validator disagrees with the provenance gate’s semantic-version grammar.

Review effort: Balanced
Findings: None

Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Align semantic-version prerelease validation across release stages

tools/​Test-ReleasePackages.ps1:53

ExpectedVersion uses a different semantic-version grammar from Get-ReleaseVersion: it rejects a version that readiness accepts (1.2.3--) while accepting a leading-zero numeric prerelease (1.2.3-01) that readiness rejects. A tag can therefore clear the provenance gate and then fail package smoke solely because the two release stages disagree. Use the same prerelease-identifier grammar in both validators.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@JeremyKuhne

Copy link
Copy Markdown
Owner Author

Addressed the previously missed version-grammar note in the latest review: package smoke now calls the same Get-ReleaseVersion validator as provenance, rather than maintaining a separate regex. Actual validation-call regression cases include 1.2.3--, numeric leading-zero prerelease rejection, and build-metadata rejection. Both deterministic contracts and real installed 0.10.0 smoke pass. No further manual review requested for this narrow validator reuse; no release/tag changes.

@JeremyKuhne
JeremyKuhne merged commit 3ef0687 into main Sep 30, 2026
4 checks passed
@JeremyKuhne
JeremyKuhne deleted the prepare-v0-10-release branch September 30, 2026 23:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants