Verify publication inputs and report child failures - #50
Merged
Merged
Conversation
why: A Go article hid foreign code while retaining other languages' headings, API descriptions and caveats. Exported Markdown disagreed with rendered pages, and nearby working trees could change source examples. what: - Select complete prose regions before rendering, linking and exports - Curate shared library articles and preserve native guide equivalents - Bind cached examples and native guides to their documented revisions - Check language isolation, root backlinks and executable Go examples
why: Curated port pages exposed nested API names and missing transport guide destinations. what: - Match qualified nested APIs and leave known ambiguous names plain - Correct source and testing-package references - Route transport guides to each native execution guide
Replace inherited tmuxp examples on seven command pages with native commands and pinned source links. Verify the documented commands and failure handling against all seven native CLIs on isolated sockets. Refresh the Go model to the documented CLI revision. Limit docs.json output checks to the selected port and fail on malformed build defaults. Validation: outer checks pass in 32.30s; 77 native commands and 28 negative checks pass. Full publication and broader workspace curation remain in progress.
why: The central dispatcher could report success while its final shell refresh was still queued or had failed. what: Wait for the shell run, surface child failure logs and linked summaries, limit waiting jobs, and execute success and failure cases against both workflow scripts.
why: Native workspace readers inherited tmuxp instructions and historical comparisons instead of instructions for the CLI they selected. what: Curate configuration, installation, automation and command pages per port; link reproducible source checkouts; exercise documented commands and real tmux configuration, including failure cases.
why: Permission and network failures must not initialize an empty port manifest, and the conditional write must use the ETag of the bytes read. what: - Read the manifest and ETag in one request; initialize only on absence - Preserve read failures and cover conditional writes and retries - Document the contract and correct the example release pin Verification: pnpm test passed in 41.33 seconds; executable manifest negative controls reject swallowed errors.
why: Markdown-like Scala calls were rewritten as links inside examples. what: - Rewrite parsed Markdown links without touching code spans or fences - Cover Scala generic calls, definitions, images, and relative links Verification: focused staging checks and the outer suite passed; the previous regex fails the code-preservation negative controls.
why: A port reader should search that language before broadening scope. what: - Scope modal and standalone search to the current port - Keep explicit scope through empty results and asynchronous queries - Reject non-port routes when deriving search links Verification: outer suite passed in 34.94 seconds; delayed inventory and result negative controls prevent stale requests from replacing UI.
why: Native references from older source revisions lacked the shared shell, theme preferences diverged, and Furo covered the port menu. what: - Apply the Sphinx shell adapter during assembly and scope search metadata - Share Astro and native theme preferences in both navigation directions - Keep the native menu above Furo content and search within its port - Exercise desktop, tablet, phone, keyboard, and theme behavior Verification: outer suite passed in 34.94 seconds; assembled output has 1571 passing tests and one stable-reference skip. All 15473 pages and 2724729 links passed assembly checks. Browser menu and theme negative controls reproduce the previous failures.
why: Astro replaces root attributes during client navigation without
rerunning the inline enhancement script. API links then exposed
the entire mobile tree while hiding both drawer controls.
what:
- Restore the API navigation flag when initializing the current page.
- Center the documentation disclosure row above its separator.
- Exercise real Lua API navigation and Back in the routine browser gate.
- Check closing controls, scroll restoration, and desktop resizing.
validation: pnpm test passes in 58.73s. Removing the restoration line
fails the new 688px check. Full latest assembly checks 15,473 pages and
2,724,729 links with zero broken links. Independent browser review
passes 33 cases across widths, themes, navigation, and no-JS fallback.
No generated reference data changed.
why: Python was excluded by repository owner, and its reviewed caller branch differs from its core source branch. what: - Catalogue workflow, caller ref and optional language for each port - Scope App tokens to one owner and repository with Actions permission - Keep arbitrary source refs separate from the reviewed caller - Use native version grammar for Python post-release aliases Verification: 27 focused tests, lint and type checks pass. Five deliberate defects fail their gates. A Python build-only dispatch passes with both publishers skipped. The outer gate stops at mentions freshness, also reproduced with the unmodified base generator and port catalog.
why: The native Python reference inserted its shared header after the article was visible. Cold loads shifted the content by 49 pixels on desktop and 177 pixels on phones. what: - Render the existing shell's header, footer and styles during assembly with the catalog-pinned Happy DOM dependency and no network requests. - Enhance the initial navigation without replacing it, preserving the insertion fallback for previously published native references. - Exercise delayed script loading, stable article geometry, version controls and no-JavaScript navigation in the routine browser gate. verification: Outer passes in 49.55 seconds. Independent cold, throttled and delayed-script loads report CLS 0 at 1440, 688 and 390 pixels. Removing the initial header or styles fails the new regression check. Regenerated native output passes controls and theme checks; the complete preview has 15,473 pages and 2,726,643 links with no broken targets.
why: A fresh local test run lacked the ignored Ruby and Lua guides, making the mention freshness check fail or encouraging regeneration that removed valid backlinks. what: - Stage integrated guides from each API model's exact local Git commit before medium and outer checks, preserving selected-source release builds and cached wrapper guides. - Report the required source checkout and revision when unavailable. - Verify newer branches and dirty working files cannot replace the integrated guide bytes, without fetching during routine checks. verification: Fresh missing-staging reconstruction restored all guides without changing committed mentions. Outer passes in 32.13 seconds; the regression fails when reads are changed to the working tree.
why: A published page did not identify its source and docs revisions, artifact, or workflow run. Artifact names alone also allowed the publisher to accept bytes unrelated to the selected build inputs. what: - Snapshot clean source and docs revisions before native generation, including Python's separate workspace and MCP repositories. - Record sorted content hashes in each version tree and link the record from its HTML pages. Keep upload and run identity outside those bytes. - Download the exact uploaded artifact, verify its ZIP digest, safely extract it, and check ownership, revisions and inventory before AWS. - Write publication receipts into port manifests while preserving the original receipt on identical immutable reruns. - Require port callers to supply provenance, reject malformed path and locale inputs, and accept existing GitHub SSH remote formats. - Document caller migration, central dispatch and IAM prerequisites. verification: 150 focused tests and the outer gate pass in 32.13 seconds. Independent review passes 114 focused tests, malformed environment input fixtures and the three actual Python checkout identities. Inventory, digest, dirty-input, empty-port and routing negative controls fail as intended. A local Go assembly verifies all 7,934 files and 2,950 HTML provenance links; it records dirty docs and cannot be published. Hosted publication at this revision, custom Ruby/Lua caller migration and shared-root provenance remain unverified. These records establish a publication trace, not a cryptographic builder attestation.
why: The native header gave its language list a zero flex basis. At intermediate widths, fixed controls squeezed thirteen links into a tall column above the article. what: - Reserve a useful flex basis so controls wrap before language links collapse, while retaining every port and existing phone layout. - Check visible, unobscured links and a compact language list before enhancement, including no-JavaScript navigation and 768px coverage. verification: Outer passes in 50.73 seconds. Independent light/dark and JavaScript/no-JavaScript checks pass sixteen browser cases. The header is 86px tall at 688px and 768px, with phone and desktop heights unchanged. Measured layout shift remains zero. Restoring the old flex basis fails the new regression check.
why: Kotlin and Scala share the Java repository, so their GitHub buttons opened the parent repository instead of the documented library. what: - Record each wrapper's source directory separately from its repository identity, preserving checkout and publishing ownership. - Use that directory for the library button and footer, preferring an explicit source revision, then a release tag or default branch. - Pass the homepage's selected version and source into its library links. verification: Outer passes in 54.27 seconds; assembled wrapper checks and browser checks pass at desktop and phone widths, including no-JS. Independent browser checks confirm both links and preserve Java URLs. Real tag and source-pinned alias builds resolve the expected directories. Removing the directory metadata makes both regression cases fail.
why: Publication checks must accept each wrapper library directory and reject links to unrelated trees. what: - Match wrapper footer links against their declared repository and path. - Keep repository-root links valid for core and companion products. - Exercise branch, tag, revision, wrong-directory, and wrong-owner cases.
why: A selected-ref publication retained committed MCP snapshots, so its tool schemas could describe a different source than its API pages. Cold Go compilation could also exhaust the protocol response deadline. what: - Require matching source, API model, runtime snapshot and registrations - Provision each selected native toolchain without executable caches - Compile Go before protocol capture and clean temporary binaries - Fail missing inputs and missing runtime schemas visibly Verification: combined outer passes in 42.11s; source mutation negatives fail. A local empty-cache Go build takes 11.17s and preserves all 45 tool contracts. Other native runtimes still need hosted execution.
why: Generated MCP reference pages were missing from docs.json and LLM exports, and Markdown conversion dropped their nested schemas. what: - Reuse rendered Markdown for each selected port's tools and catalog - Preserve input/output schemas and exact source metadata - Add the same contracts to docs.json, llms.txt and llms-full.txt - Keep wrapper and translation builds free of inherited MCP routes Verification: combined outer passes in 42.11s. An actual-source Go build checks all 45 contracts, nested schemas and matching Markdown twins; three deliberate export regressions fail their checks.
why: Ruby and Lua generate reference data with a separate checkout. Recording only their selected library source omits the exporter revision and nested checkouts make otherwise clean inputs appear dirty. what: - Record the owned native generator repository, SHA and dirty state - Recheck its HEAD when consuming the pre-generation input snapshot - Permit explicitly selected fork builds while rejecting publication - Reject missing, dirty or foreign native exporter records before AWS Verification: 67 helper tests, type checks and lint pass. The integrated outer passes in 37.53s. Clean native Ruby/Lua exports retain source and exporter identities across generation; hosted caller proof remains open.
why: Each pull request assembled every port twice, once for its audit and once for preview publication. The preview also ran independently of the source and output gates. what: - Build one preview tree in the required test job and audit its output - Render production locale roots for indexing and canonical checks - Publish the exact current-run artifact after the publisher dry run - Preserve fork isolation, digest failures and cleanup concurrency - Keep prompt links and sidebar checks within the preview prefix - Bound optional browser availability probes to three seconds Verification: combined outer passes in 35.08s. Cold rendering plus the complete output phase passes 1,650 tests; two absent native Sphinx page checks remain skipped. Independent output review passes 1,254 tests. Six workflow regressions and output corruption controls fail as expected. An unresponsive TCP fixture proves the probe deadline. The change removes one full port assembly; hosted net cost and preview latency measurements remain pending.
why: Ruby's MCP CLI borrows a running tmux server, so discovery failed before uploading docs when a clean runner had no server. what: - Start a config-free daemon inside the private discovery socket root - Always attempt explicit socket cleanup and scratch removal - Preserve capture and cleanup errors together when both fail - Cover daemon lifecycle failures and verify native Ruby discovery Verification: 29 focused tests, native eight-tool discovery and an independent control daemon, mutation negatives, fresh review, and the complete outer loop in 32.79 seconds.
why: Content curation and publication verification share guide staging, port metadata and machine-readable exports. what: - Preserve port-owned prose and source-bound publication inputs together - Stage other cached guides before regenerating the selected source - Reject explicitly cached selected inputs and keep final SHA checks - Retain both workflow routing and wrapper source-link metadata Verification: independent merge review, native staging CLI fixtures with removal negatives, and the full outer gate in 53.37 seconds. The first combined outer run reached its 60-second budget; the coordinated rerun passed with that budget and all checks unchanged.
why: Preview assemblies prepend pr-N to each page path. The footer check consequently mistook the locale for the port and rejected valid Kotlin and Scala source directories. what: - Strip the preview prefix before resolving the library - Check allowed and rejected targets in root and preview paths - Verify 11 focused cases and a failing removal control - Pass the outer gate in 48.51 seconds; hosted assembly remains pending
why: Source inclusions and wrapped snippet tests can hide the imports, setup, or entry point missing from a reader's copied program. what: - Require complete programs with visible dependencies and run commands - Verify the exact displayed bytes at their documented source revision - Put comments above code and wrap them at 80 columns - Keep long attribution links outside code blocks Reviewed the policy against the renderer and existing example checks.
why: Baseline cached staging compared old guide artifacts with the new publication source before that source had been exported. what: - Exclude the selected publication port from baseline cached staging - Retain strict source checks on the later fresh export - Reject explicit cached staging of the selected port - Exercise Ruby, Lua, and Kotlin through real CLI fixtures The three regression fixtures fail when the exclusion is removed.
why: Preview assemblies prepend pr-N to each page path. The footer check consequently mistook the locale for the port and rejected valid Kotlin and Scala source directories. what: - Strip the preview prefix before resolving the library - Check allowed and rejected targets in root and preview paths - Verify 11 focused cases and a failing removal control - Pass the outer gate in 48.51 seconds; hosted assembly remains pending
why: Extracted snippets omitted imports, entry points, and setup. Shared capture examples and their citations also obscured the tmux workflow. what: - Give the root capture page a complete shell program and compact links - Put eight complete native programs in their own port routes - Include imports, dependency files, run commands, and server cleanup - Complete the Java, .NET, and C++ workspace consumer programs - Protect executed source bytes through HTML and Markdown rendering - Enforce short capture comments and describe source checks accurately Native runs exercise exact displayed programs at their pinned revisions. Import/setup and runtime negatives fail as expected. The shell and C++/.NET/Swift capture programs pass on tmux 3.2a and 3.7c; the other capture programs run on 3.7c. All three workspace programs pass on both. Browser checks compare copied content and inspect desktop/phone layout. The combined outer gate passes in 49.41 seconds. Full publication remains separate.
why: Publication CI caught example project filenames misclassified as API references after the outer development gate had passed. what: - Run the existing API-link checker in medium and outer gates - Remove redundant filename mentions and retain the named code blocks - Regenerate the mention index without those local project references The full API-link check passes across 403 pages. The new gate uses the existing checked-in inputs and performs no fetch or site assembly.
why: Go and TypeScript session creation can start a daemon and then fail while fetching its snapshot. Registering cleanup after the call leaked that daemon and removed its socket directory. what: - Establish cleanup before session creation in the Go program - Check TypeScript's private socket even when creation throws - Preserve operation and cleanup errors together - Keep the endpoint reachable when stopping the daemon fails - Update the executed-program receipts without changing dependencies Real tmux 3.2a and 3.7c fault injection reproduces the old leaks and proves the corrected cleanup. Combined failures preserve both diagnostics and the endpoint; proof cleanup reaps only the recorded owned processes. Fresh independent reviews pass for both programs. The rendered HTML, clipboard content, Markdown, and full-text exports retain their bytes.
Keep root capture documentation about tmux and route complete programs to their owning ports. Include the verified workspace examples, partial startup cleanup, and routine API-link validation from the content branch. Retain the publisher's integrated-source guard during the staging merge; the resulting staging implementation is byte-identical to its parent. The combined outer gate passes in 47.42 seconds with no skipped browser checks. Hosted publication validation remains separate.
why: Complete Java consumer projects need a settings file. The assembled content audit mistook its Kotlin DSL for a foreign port example. what: - Accept settings.gradle.kts beside the existing build.gradle.kts rule - Keep the exemption limited to Java pages and Kotlin configuration validation: The assembled product content check and seven predicate cases pass. The outer loop passes in 45.99s. Hosted runs 36655549814 and 36655731965 exposed the missing settings filename; full CI reruns next.
why: Complete Java consumer projects need a settings file. The assembled content audit mistook its Kotlin DSL for a foreign port example. what: - Accept settings.gradle.kts beside the existing build.gradle.kts rule - Keep the exemption limited to Java pages and Kotlin configuration validation: The assembled product content check and seven predicate cases pass. The outer loop passes in 52.69s. Hosted runs 36655549814 and 36655731965 exposed the missing settings filename; full CI reruns next.
why: Workspace and MCP pages showed callable fragments or assumed an existing server. Readers need complete consumer projects they can run. what: - Publish full TypeScript and Swift workspace/MCP programs and setup - Provide a private Swift stdio launcher and correct .NET lifecycle guide - Preserve verified program and project bytes across HTML and Markdown - Retire the unused source include and refresh guide backlinks validation: Native cases cover tmux 3.2a and 3.7c, startup and cleanup failures, exact dependency resolution, and missing-import controls. Twenty-seven receipt checks and the outer loop pass (45.66s). Fresh Astro output matches nine native files through HTML, copying and text exports. Thirty-two browser cases and ten actual copy buttons pass. The combined local search index was rebuilt; three filtered queries see current pages. Historical-version execution and the broader publication audit remain separate from these checks.
why: Publication checks must exercise the same complete programs and project files as the reviewed site change. what: - Include reviewed TypeScript and Swift consumer examples and launcher - Keep the .NET lifecycle guide and generated backlinks in sync - Protect every native program and project file through both renderers validation: All twelve incoming paths equal the reviewed source tree. The combined outer loop passes in 48.99s, including types, lint and fresh browser checks. Native and copied-byte evidence belongs to the reviewed content commit; this merge does not rerun native toolchains.
tony
marked this pull request as ready for review
September 30, 2026 02:41
tony
added a commit
that referenced
this pull request
Sep 30, 2026
what: - Build native API and MCP contracts from the selected source - Verify source, docs, artifact, and destination before publication - Propagate dispatch and shell-refresh failures to the initiator - Publish the audited preview artifact without rebuilding it why: A successful dispatch must identify the exact bytes it published and report failures in every child job. Source-derived contracts and verified artifact reuse prevent stale or mismatched documentation from publishing.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A selected-ref publication now builds the port API and MCP contracts from the selected source, records the source and docs revisions, and verifies the uploaded bytes before requesting AWS credentials. Generated MCP schemas also appear in copied Markdown, docs.json and LLM exports.
The publisher validates the exact artifact ID and ZIP digest, clean inputs, repository ownership, destination and matching builder/publisher revisions. Published pages link to a deterministic build inventory; the manifest receipt identifies the artifact, run and destination. Identical immutable reruns retain their original receipt. Ruby and Lua additionally record the separate native exporter revision. Fork sources may build, but cannot pass publication validation.
Native MCP toolchains are provisioned without executable caches. Go compiles before its protocol response deadline. Missing checkouts, stale source identities and incomplete runtime schemas fail visibly. Routine checks stage integrated Ruby/Lua guides from pinned Git objects, preserving backlinks without reading newer or dirty content. A selected port skips the baseline cache stage and must then pass fresh source checks. Ruby MCP discovery starts and closes its own private server; capture and cleanup failures remain visible.
The central dispatcher selects a reviewed caller independently of the requested source ref, supports Python's separate owner, and scopes each App token to one repository. It waits for port publication and the final shell refresh, preserves child failures and exposes failed-step logs. Manifest updates read the document and ETag together; only a confirmed missing key initializes an empty manifest.
PR previews now publish the same artifact that passed the required source and output audit, identified by its immutable current-run ID and checked digest. Two production locale renders preserve indexing checks without rebuilding every port. A recording publisher dry run gates publication, fork PRs receive no publishing credentials, and preview cleanup retains its concurrency boundary. Optional browser probes have a three-second deadline.
Verification
Current combined development gate passes in 48.99 seconds, including types, lint and fresh browser checks. The prior combined hosted assembly found a preview-prefix bug in footer validation: 1,791 tests passed and one rejected valid Kotlin/Scala directory links. The correction passes 11 focused cases, and removing it fails the regression. The merged content also includes complete capture/workspace programs, real partial-startup cleanup controls, and API-link validation in routine gates. The subsequent hosted test and recording publisher check passed; the hosted Gradle-settings correction also passes. The current combined run passes the full publication audit, recording publisher check and preview publication with the complete TypeScript/Swift product examples. Earlier workflow mutations, corrupt-output controls, a nonresponding TCP fixture and recording-AWS failures verify the corresponding failure paths.
Completed preview reuse run compared with its preceding full baseline used 1,629 versus 1,801 runner-seconds. Preparation fell from 1,154 to 578 seconds; publisher time increased from 647 to 1,051 seconds. This single pair shows lower runner usage but slower preview completion, not a general speedup or billing estimate.
An empty-cache local Go compile takes 11.17 seconds. All 45 runtime tool contracts match the warm capture, and an assembled tree verifies the complete schemas, source metadata and Markdown/export agreement. Source/schema/export mutations fail their checks. Native Ruby/Lua exporters preserve separately captured source and generator identities; 67 provenance tests include fork-publication and malformed-generator failures.
Ordinary CI passes with a stale committed Rust registry. A real invalid Go dispatch fails at the initiator after its child rejects the source; a successful final refresh does not hide that failure.
The shell-wait script passes hosted success and injected failure controls. Eleven executable manifest cases cover read failures, absent keys and conditional-write races; swallowing errors breaks four controls.
Hosted publication proof at the approved 843278f5 revision: a clean Python build publishes, three controlled artifact violations fail before AWS, and an identical rerun skips sync and retains the receipt. Ordinary hosted GETs return HTTP 200, and all 7,699 S3 objects match their recorded bytes. Dispatch to first receipt takes 434 seconds. The run is deliberately red because its negative jobs fail. Durable evidence and completed cleanup preserve the checks.
Merged native callers publish successfully for Lua, TypeScript, and Ruby. Ordinary public guide and build-record responses match their uploaded ZIPs; every recorded file hash matches (3,685 Lua files, 4,162 TypeScript files and 3,677 Ruby files). Ruby also passes all 36 merged-source compatibility cells. Its preview cleanup logs only its 3,677 owned-prefix deletes, and the preview build record is no longer public. Manifest receipts identify the exact source, docs revision, artifact and run. These checks cover one public guide per port, not every public URL.
Hosted cold builds across every remaining native runtime, shared-root provenance, release-event/public-delivery latency and the final adoption assessment remain open. The build record is a publication trace, not cryptographic builder attestation.