Skip to content

feat(workflows): select exact workflow catalog releases - #4788

Merged
mnriem merged 4 commits into
github:mainfrom
mnriem:mnriem-feat/4719-workflow-catalog-releases
Sep 29, 2026
Merged

mnriem merged 4 commits into
github:mainfrom
mnriem:mnriem-feat/4719-workflow-catalog-releases

Conversation

@mnriem

@mnriem mnriem commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator

Description

This is the workflow-catalog slice of #4719. A workflow catalog entry continues to advertise its current release in the existing top-level version, url, and optional sha256/requires fields. Customer-authored catalogs can also advertise historical releases in an optional releases map keyed by version, where each release has its own URL and SHA-256 digest and can declare its own requirements. Malformed, inconsistent, and duplicate histories raise workflow catalog validation errors.

WorkflowCatalog.get_workflow_info(id, version=None) returns the current or a selected exact release from the winning catalog source, and get_workflow_versions(id) lists its advertised versions. specify workflow add <id> --version <version> installs the selected release; specify workflow info <id> --versions displays the available versions. A missing historical release never falls through to a lower-priority catalog or substitutes current, and discovery-only catalogs stay non-installable. Installs validate the selected URL and redirects, downloaded SHA-256 (archive or YAML), workflow ID and version, and any declared release requirements before committing. Unqualified search/info/add/update and direct --from retain their established behavior. Workflow steps and bundle pin resolution are separate #4719 slices.

Testing

  • Tested locally with .venv/bin/specify workflow add --help and .venv/bin/specify workflow info --help (both new options present).
  • Ran focused tests from this worktree's .venv: 915 passed after rebasing onto current main (workflow catalog, command add/info/update, workflow regression suite, existing bundle delegation). Scoped Ruff and diff checks passed.
  • Tested with a separate sample project; catalog-backed install is exercised in CLI integration tests with a mocked download and a real workflow archive/YAML.

An earlier full-suite run on this worktree finished with 8,549 passed, 17 skipped, 64 failed. All 64 failures were in PowerShell tests with a runtime System.IO.FileLoadException; a representative failed test passed when rerun alone. The full suite was not rerun after the rebase; no PowerShell or integration code was changed by this PR.

AI Disclosure

  • I did not use AI assistance for this contribution
  • I did use AI assistance (fill in the disclosure below)

AI disclosure: GitHub Copilot (GPT-6 Sol, autonomous mode, session-default reasoning settings not exposed) generated the workflow-catalog implementation, tests, documentation, this PR description, and performed the checks listed above. This is agent-authored work; no human line-by-line review or testing is claimed.

Keep current workflow metadata at the top level while validating and selecting optional historical releases from the winning catalog. Verify the selected digest, requirements, ID, and version before installation, and expose available versions in workflow info.

Assisted-by: GitHub Copilot (model: GPT-6 Sol, autonomous)

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Advertised-version validation conflicts with workflow version rules, and discovery-only versions are not clearly identified.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds exact workflow catalog release selection while preserving current-version defaults.

Changes:

  • Adds historical release validation and lookup.
  • Adds workflow add --version and workflow info --versions.
  • Verifies selected artifacts and documents versioned catalogs.
File Description
tests/​specify_cli/​workflows/​test_catalog_versions.py Covers lookup, validation, precedence, and installation.
src/​specify_cli/​workflows/​command_info.py Adds catalog version display.
src/​specify_cli/​workflows/​command_add.py Adds exact-version selection.
src/​specify_cli/​workflows/​catalog/​_versions.py Validates and selects releases.
src/​specify_cli/​workflows/​catalog/​_domain.py Exposes version-aware catalog APIs.
src/​specify_cli/​workflows/​_commands.py Verifies and installs selected releases.
docs/​reference/​workflows.md Documents versioned catalogs and CLI options.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/specify_cli/workflows/catalog/_versions.py
Comment thread src/specify_cli/workflows/command_info.py
@mnriem mnriem added the triage-can-wait Verdict: valid and in-scope but deprioritized; held behind the evidence gate label Sep 29, 2026
Reject advertised versions that workflow definitions cannot declare, enforce exact artifact spelling for selected releases, and mark discovery-only versions as non-installable in workflow info.

Assisted-by: GitHub Copilot (model: GPT-6 Sol, autonomous)

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 29, 2026 13:07
@mnriem

mnriem commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator Author

Review-round update at commit 8e83845f:

  • Catalog entries with releases now validate their advertised current version and each historical key against the same X.Y.Z rule as workflow definitions. PEP 440-equivalent spelling remains accepted for the requested version, while the downloaded workflow must declare the advertised spelling for both YAML and archive installs.
  • workflow info <id> --versions now prints the winning catalog’s install policy, explicitly marking discovery-only versions as not installable. The policy and versions are read together from one winning catalog entry.
  • New regression tests failed before the fixes; the focused workflow and bundle-delegation suites now pass (925 tests). Scoped lint and diff checks pass. The earlier full-suite PowerShell runtime failures noted in the PR body were not rerun here.

Posted on behalf of @mnriem by GitHub Copilot (GPT-6 Sol, autonomous mode, session-default reasoning settings not exposed). Copilot generated this review-round code, tests, documentation, and comment, and ran the listed checks. Review conversations remain for reviewers to resolve.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused implementation preserves existing defaults and includes comprehensive positive and negative coverage.

Review effort: Balanced
Findings: None

Resolved since last review (2)

Reproduce narrow Windows Rich console output and compare the validation message after normalizing whitespace, without weakening the exit or rollback assertions.

Assisted-by: GitHub Copilot (model: GPT-6 Sol, autonomous)

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 29, 2026 13:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

New YAML requirement validation and several catalog-only option rejection branches lack required negative test coverage.

Review effort: Balanced
Findings: None

Previously missed (2)

In code that hasn't changed since last review

Low severity Add negative test for mismatched YAML requires

src/​specify_cli/​workflows/​_commands.py:1367

Add a negative YAML-install test for this branch. The existing requirements-mismatch case downloads an archive and exercises expected_requires in _install_workflow_package, while the new standalone-YAML comparison here is never entered. A .yml historical release whose catalog requires differs from the downloaded definition should assert exit 1 and no registry/file commit, as required by the repository's positive-and-negative coverage rule.

Low severity Test --version rejection for all invalid source forms

src/​specify_cli/​workflows/​command_add.py:54

Please cover each newly rejected source form here. The only invalid-scope test uses --from; there is no --version test for a bare URL, an existing local path, or --dev, even though these are separate branches and the documentation now promises that all are rejected. A parametrized CLI test would prevent one route from accidentally bypassing catalog-only selection.

@mnriem

mnriem commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator Author

CI follow-up at commit 92f719b0: the prior Windows 3.13 pytest failure was a test assertion against Rich output wrapping between “requested” and “workflow ID,” not an install failure. The test now forces a narrow console and checks the same error after whitespace normalization, retaining the exit-status and no-install assertions. It failed locally before the fix and passes afterward; 925 focused tests and scoped Ruff checks pass locally. The new CI run is green across Windows, macOS, and Ubuntu (Python 3.13/3.14), Ruff, markdownlint, shellcheck, CodeQL, and the remaining applicable checks.

Posted on behalf of @mnriem by GitHub Copilot (GPT-6 Sol, autonomous mode; session-default reasoning settings not exposed). Copilot investigated the CI logs, generated the test change and this comment, and ran the listed validation.

Exercise mismatched requirements in standalone YAML releases and reject exact-version selection for URL, local-file, local-directory, and dev sources before download or install.

Assisted-by: GitHub Copilot (model: GPT-6 Sol, autonomous)

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 29, 2026 13:46
@mnriem

mnriem commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator Author

Follow-up for review 5353318310 at 7644fbcc: both previously missed Low coverage requests are now addressed. The new standalone .yml historical-release test supplies valid downloaded bytes with a mismatched catalog requires and verifies exit 1, no registry entry, and no installed file. A parametrized CLI test covers --version rejection for a bare URL, an existing YAML file, an existing directory, and --dev, asserting no download or install. This is test-only; production behavior was already present. The focused workflow and bundle-delegation suites pass (930 tests), and Ruff check/format pass. Replacement CI is running.

Posted on behalf of @mnriem by GitHub Copilot (GPT-6 Sol, autonomous mode; session-default reasoning settings not exposed). Copilot added these tests, ran validation, and generated this comment.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation matches the stated workflow-catalog contract and includes comprehensive positive and negative coverage.

Review effort: Balanced
Findings: None

@mnriem
mnriem merged commit 2c0a57a into github:main Sep 29, 2026
15 checks passed
@mnriem
mnriem deleted the mnriem-feat/4719-workflow-catalog-releases branch September 29, 2026 16:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

triage-can-wait Verdict: valid and in-scope but deprioritized; held behind the evidence gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants