Skip to content

fix: finish QA contracts and production redeployment - #112

Merged
Kitkitkittt merged 5 commits into
mainfrom
codex/98-price-unit-workspace-release
Oct 9, 2026
Merged

Kitkitkittt merged 5 commits into
mainfrom
codex/98-price-unit-workspace-release

Conversation

@Kitkitkittt

@Kitkitkittt Kitkitkittt commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Refs #98, #100, #101, #102, #103, #104, #105, #106, #107, #108, #109, #110, #111.

Summary

Complete QA contracts for price certification, financial units/periods, observation freshness, news coverage and workspace navigation/layout. Final improvements retain explicit unavailable TTM envelopes for empty/invalid quarterly source data or ordinary calculation failures and remove TLS bypass from Oracle release smoke scripts. Requested identity, null metrics and cancellation remain intact.

User authorized finishing improvements, committing and redeploying. Provider corpus repair, security-policy changes, paid calls and unrelated glossary/Matrix work are excluded.

Verification

  • Initial hosted CI https://github.com/Kohnnn/vnibb/actions/runs/37929068610 passed all four jobs: secret scan, uninterrupted CI gate, PostgreSQL migration/contracts and Chromium release smoke.
  • Final local gate passed all nine steps in 377.6s: 157 frontend suites/1,044 tests; 1,610 backend tests with four skips. TypeScript, production build, generated changelog and changed-line Ruff passed. ESLint zero errors/79 baseline warnings; two NumPy correlation warnings.
  • TTM before/after service smoke failed/passed; 29 financial-service tests passed. Actual router HTTP smoke returned 200 with missing_quarterly_source_data and null revenue/source.
  • Certificate-validating public runtime/smoke passed health/readiness, dashboard, profile/quote, screener, microstructure, CORS and WebSocket. Invalid trust bundle rejected with curl exit 77.
  • Prior runtime: 40/40 navigation checks; warm reload zero pending; stable authored geometry; same-request TTM reasons and certified below-fold canvas paint. Local/runtime evidence is separate from provider truth.
  • Standards and Spec release reviews have zero actionable findings. Final hosted CI for 3394fff must pass before merge/deploy. Historical test failures/timeouts remain in docs rather than relabelled passes.

Release and recovery

API/MCP/scheduler use one immutable GHCR digest; preserve runtime mount, database/cache/Auth/Caddy containers and current env. No new schema migration. Capture actual current image/config before replacement. Canonical Vercel project is vnibb-web; rollback deployment dpl_4xCqECMTtM59zXXvAMbnqEQg8cz4. Baseline API revision is 2c57654277ef5546662afc3cc7ed4a4e355e441e.

Live revision/health and affected browser acceptance are required after deployment. Issues remain open; do not merge by bypassing failing gates.

Hosted gate correction

Hosted runs 37931495455 and 37932317291 failed frontend typechecking and were not bypassed. A controlled isolated frozen install reproduced the exact error when React Query resolved React 18 types from pnpm hidden hoisting while the frontend used React 19. Commit 5bf3f99 declares the missing optional @types/react peer through pnpm packageExtensions; lock contexts now bind the provider to its consumer. The forced React 18 hoist then passed non-incremental frontend typecheck; 23 retry/cancellation tests and focused ESLint passed. Standards and Spec reviews both found zero issues. Hosted CI https://github.com/Kohnnn/vnibb/actions/runs/37935358289 passed all four jobs, including 157 frontend suites/1044 tests and 1610 backend passes/4 skips.

OCI replacement still needs renewed Tailscale SSH approval. Existing image publication workflow has no OCI deploy job. No access-policy change or bypass is authorized.

Late consumer regression

The earlier zero-finding Spec review was superseded by a concrete P1: new source-less TTM unavailable envelopes suppressed certified stored fallback rows. The controlled before smoke returned stored revenue40 but merged null; after the guarded merge repair revenue40 is preserved. Existing real-DB income endpoint test covers empty provider, missing source and calculation failure and returns revenue520/net104. All156 financial-service/endpoint tests passed; py_compile and changed-line Ruff passed. Rejected/source-bearing/unknown-unit rows remain withheld. Standards and Spec reviews both returned zero findings after the repair. Commit 2274758; final hosted CI https://github.com/Kohnnn/vnibb/actions/runs/37938294844 passed all four jobs: 157 frontend suites/1044 tests and 1621 backend passes/4 skips, nine root steps in518.0s.

Publication

Merged as 0e5dfdd87a75bf755794727efd2470e52f24b0d2. Main CI https://github.com/Kohnnn/vnibb/actions/runs/37939636005 is running. Canonical Vercel production build for that exact Git SHA: https://vnibb-mg4dricuu-vphk2001-gmailcoms-projects.vercel.app (building). OCI access check expired again without human approval; API remains old revision until authorized SSH replacement. Frontend and backend deployment acceptance are separate.

Refs #98, #100, #101, #102, #103, #104, #105, #106, #107, #108, #109, #110, #111. Preserve unrelated glossary and Matrix work; record local verification and deployment limits.
@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
vnibb-web Ready Ready Preview Oct 9, 2026 1:41pm UTC

Refs #101 and #111. Preserve requested TTM identity and null metrics for missing quarterly data or ordinary calculation failures. Keep cancellation semantics; verify HTTPS trust in deployment smoke. Full release gate: 157 frontend suites/1044 tests, 1610 backend passes and 4 skips.
@Kitkitkittt
Kitkitkittt marked this pull request as ready for review October 9, 2026 12:41
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T12:47:28.048171Z 3394fff Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3394fff0c8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +124 to +133
function rowsAreIdentical<T extends { period?: string | null }>(left: T, right: T): boolean {
const serialize = (value: T): string | null => {
try {
return JSON.stringify(value)
} catch {
return null
}
}
const leftText = serialize(left)
return leftText !== null && leftText === serialize(right)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Ignore volatile metadata when collapsing duplicate periods

When an annual provider response contains duplicate rows with identical financial values, each row receives its own updated_at timestamp in VnstockFinancialsFetcher.transform_data and may also carry different raw provenance. Serializing the entire object therefore classifies these harmless repeats as ambiguous-basis; canonicalPeriodRows then removes the period from every statement widget. Compare the financial fields and actual reporting-basis metadata while excluding transport fields such as updated_at and raw_data, so duplicate provider rows do not make an otherwise valid fiscal period disappear.

Useful? React with 👍 / 👎.

@Kitkitkittt
Kitkitkittt merged commit 0e5dfdd into main Oct 9, 2026
6 checks passed
@Kitkitkittt

Copy link
Copy Markdown
Owner Author

PR #112 merged as 0e5dfdd87a75bf755794727efd2470e52f24b0d2.

ghcr.io/kohnnn/vnibb-api@sha256:b1ec3141fce79a7077ba6e13c2099cd0eaf2d45f06f52f4e08b80866eaebd68e

Backend rollout blocked: API remains 2c57654277ef5546662afc3cc7ed4a4e355e441e; two Tailscale additional-check sessions expired without human approval. No SSH policy/host-key/TLS bypass. Existing workflow publishes but does not deploy OCI. API/MCP/scheduler replacement and new-backend financial acceptance remain incomplete. Provider repair, security-policy changes, paid calls and issue closure were not performed. Unrelated glossary/Matrix changes remain excluded.

This branch was successfully deployed

1 active deployment
Preview — 22747589 Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant