Repository navigation
fix: track the channel checker, and test the two paths only a release could prove - #39
Merged
Merged
Conversation
… could prove Two findings from a final review round, both correct. **The documented recovery monitor did not exist.** `release.yml` and the changelog pointed at `tmp/check-channels.mjs`; `tmp/` is gitignored, so nobody but me ever had it — and it was the thing meant to stop three disabled channel variables sitting off indefinitely. It is now `scripts/check-channels.sh`, tracked, and `npm run channels:check`. **The two highest-risk fixes had no regression coverage.** Both were changes that ordinary CI could not exercise: - The publication guard was fifteen lines of shell inside the workflow, and it had been wrong twice — once because a boolean input arrives as the *string* "false" and is truthy in a GitHub expression, once because every manual dispatch was forced to a dry run, which made the binary bypass unusable. It is now `scripts/release-guard.mjs`, a pure function with eleven tests, and the workflow calls it. - The swap-error path in `installBinary` now has fault injection: the directory is made unwritable so replacing the file genuinely fails after the daemon has been stopped, proving the daemon is started again. Skipped when running as root, which bypasses directory permissions; CI runs unprivileged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
It is a scratch tool for one person, not a project script — no npm entry, no tests, nothing referencing it. The original finding stands though: the workflow and changelog must not point at a file the repository does not contain, so those references are gone rather than redirected. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This was referenced Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Final review round — two findings, both correct.
1. The documented recovery monitor did not exist
release.ymland the changelog both pointed attmp/check-channels.mjs.tmp/is gitignored, so nobody but me ever had that file — and it was the thing meant to stop three disabled channel variables sitting off indefinitely.Now
scripts/check-channels.sh, tracked, wired asnpm run channels:check.2. The two highest-risk fixes had no regression coverage
Both were changes ordinary CI could not exercise.
The publication guard was fifteen lines of shell inside the workflow — the single decision separating "built and verified" from "published to seven registries" — and it had been wrong twice:
"false", which is truthy in a GitHub expression, inverting the guardskip_binariesbypass unusableNow
scripts/release-guard.mjs: a pureresolveGuard()with 11 tests covering both of those, plus the bypass being refused offmainwhile still recording operator intent.The swap-error path now has fault injection — the directory is made unwritable so replacing the file genuinely fails after the daemon is stopped, proving it gets started again. Skipped under root (which bypasses directory permissions); CI runs unprivileged, so it executes there.
Assessed and not changed
New package:withArchitecture: x64.PUBLISH_WINGETstays off for 0.5.3. #417273 is in review for 0.5.2 and the package does not exist upstream yet; submitting a second "New package" PR would put two competing submissions in Microsoft's queue. Enable it once that merges.Full suite: 3300 passed, 3 skipped.
🤖 Generated with Claude Code