Skip to content

ci: bootstrap trusted release evaluators - #25

Draft
mfethe1 wants to merge 3 commits into
product/mainfrom
codex/buzz-evaluator-bootstrap
Draft

ci: bootstrap trusted release evaluators#25
mfethe1 wants to merge 3 commits into
product/mainfrom
codex/buzz-evaluator-bootstrap

Conversation

@mfethe1

@mfethe1 mfethe1 commented Sep 7, 2026

Copy link
Copy Markdown
Owner

Summary

Provide the standalone DCO and CI qualification evaluators that the follow-up release workflow must load from its trusted base. This five-file prerequisite adds the two evaluators, their standalone tests, and two regression steps in the existing CI changes job. It introduces no workflow trigger, aggregate qualification job, ruleset, or deployment change.

Base: adeec6eb5c4ff425aa03d8a744a295da4429f67f
Head: 0aee6a6ba5b4b80d04c76aec968f7ec9226114a7

Related issue

Prerequisite for #20.

Testing

  • Nine production qualification tests and ten standalone DCO tests passed. Seven evaluator guard mutations were caught. Syntax checks, actionlint, existing CI isolation checks, and the file-size policy passed.
  • The actual qualification CLI accepted successful lanes and rejected a required native lane marked skipped under a successful summary job. The DCO evaluator accepted PR feat(fleet): qualify scoped dispatch with durable Buzz receipts #19's signed-off commit and rejected PR [AGENT-HOMES-001 PR-3] Machine homes: record the machine an agent runs on #15's two commits lacking author sign-offs using live read-only GitHub metadata and Git's trailer parser. That local harness supplied a synthetic trusted-event context; it does not prove hosted trigger activation.
  • Independent review of the complete exact diff was clean and independently reran the 19 tests and positive/negative CLI cases.
  • Hosted evaluator regressions passed all 19 tests on merge 3af0dcebf2d904b2e66b9378b91f7c4b61d82f0b, whose verified parents are the base and head above (run 34149448152, job 101828421458). This covers the evaluator steps only; it does not establish DCO trigger activation, whole-CI success, or merge approval.
  • Full just ci failed at the final mobile step: 2,241 passed and eight golden comparisons failed. Earlier stages passed, including 6,583 desktop tests and 3,221 tests in the main native desktop test binary. All eight actual failure PNGs are byte-identical to the captured exact-base run. Expected images and tolerances were unchanged; this remains a CI failure.

This candidate does not activate Product DCO or Product Qualification. Trusted-base installation, the trusted default-branch trigger, hosted qualification, and protected review remain prerequisites for the later workflow change.

Signed-off-by: Michael Feth <mfethe1@gmail.com>
@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant