Conversation
Run documentation browser certification independently of source freshness, while preserving the canonical fail-closed release rollup. Compare watched paths in pinned Git trees rather than timestamp-filtered moving refs. Add 83 dependency-free CLI and workflow regressions. Refs #89; this does not advance the source lock or close the outstanding public-source review.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Exact-head hosted verification receiptRun 34814168620 exercised head
Downloaded and independently checked both artifact ZIP SHA-256 digests:
This supersedes the initial PR body's pending hosted-verification status, not its source-review limit. The topology repair now has real browser execution evidence and real fail-closed rollup evidence. #89 still needs substantive review of those four source paths against affected public pages, followed by a truthful lock update and fresh successful canonical CI. Do not merge this PR by ignoring that remaining gate. |
There was a problem hiding this comment.
🔵 Needs a closer look
Full frozen-install, browser, and live drift gates were not run in this sandbox.
Pull request overview
This PR repairs documentation CI evidence and source-freshness detection while preserving a strict release gate.
Changes:
- Separates freshness and browser verification jobs.
- Pins drift checks to immutable Git tree identities.
- Adds regression coverage and documents evidence semantics.
File summaries
| File | Summary |
|---|---|
scripts/docs-release-gate.test.mjs |
Tests release-gate outcomes and workflow wiring. |
scripts/docs-release-gate.mjs |
Requires both verification jobs to succeed. |
scripts/check-source-drift.test.mjs |
Adds source-drift regression coverage. |
scripts/check-source-drift.mjs |
Implements pinned, fail-closed tree comparison. |
scripts/check-automation-syntax.mjs |
Runs automation regression tests. |
docs/e2e-source-freshness.md |
Documents evidence and freshness semantics. |
.github/workflows/docs.yml |
Adds independent verification jobs and canonical rollup. |
Review details
- Files reviewed: 7/7 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Integrate main 49c7a7d into #95 without rewriting history. Preserve current dependencies, installation docs and pnpm action v6. Document the current interpreter/prompt-prefix refusal contract, safe migration and build boundary. Require those claims in the existing harness-doc check. The scoped checker reproduced the missing-contract failure and passed after the page repair, including 14 rejecting mutations. All 83 existing detector/ rollup regressions passed locally. Full hosted verification remains required. Refs #89. Source-lock timestamps and revisions remain unchanged: this is the bounded harness slice, not complete upstream contract or deployed acceptance.
An ancestor obstruction identifies the ancestor, not the watched leaf. Reject watches unresolved in both snapshots instead of treating equal obstructions as unchanged content. Preserve valid removal/replacement drift. Five new subprocess regressions failed before this fix; all 88 detector and release-rollup tests pass locally on Node 22.16.0. No source-lock revision/timestamp, workflow authority, or publication gate is changed. Fresh exact-head hosted verification remains required. Refs #89, #95. Signed-off-by: Val Alexander <val@opencoven.ai>
Exact-head hosted receipt for the final detector follow-upRun 35671468692 completed for head
Downloaded source artifact Browser artifact This supersedes the PR body's pending-new-head hosted status. It does not complete #89's remaining source-to-page review, authorize a source-lock advance, or make the whole workflow green. No merge, publication, source-lock timestamp/revision change, or gate bypass occurred. Keep the current browser/detector repair evidence; finish the substantive contract review before seeking a green canonical release check. |
Correct the project-root rejection example to invalid_request; the proposed project_root_violation code remains reserved. Document negotiated 409 policy refusals without unrestricted fallback, capability availability without grants, and the Rust client's peer-bound renegotiation/no-automatic-mutation-replay. Source reviewed: Coven 801e9f219b1d50336ad4111ca92ce2a3a1eafa3c, docs/API-CONTRACT.md blob ccdc69acb5662959ffb88d02c721a795de1fa660. Add ten documentation regressions and wire them into check:automation. The original page fails the three positive contract checks; corrected page passes all ten, including seven negative mutations. Combined local detector, rollup and page suite: 98 pass, zero failures/skips. Hosted site verification remains required. These are docs checks, not new runtime E2E acceptance. Refs #89, #95. Source-lock boundaries, dependencies, workflows and publishing controls remain unchanged; this bounded review does not complete all #89 work. Signed-off-by: Val Alexander <val@opencoven.ai>
Current scope and disposition — 2026-09-26
Refs #89; closes no issue. Browser/build verification passes; the canonical release check remains blocked by unfinished source-to-page review. Do not merge by bypassing it.
Head:
571e3e7ac32387379c93dd3fef36a0c1dad5769e.Base main:
49c7a7df8890f80dcb3d2ee82d619a1c60d70770.Hosted merge tree:
976ce7f397024a5f26ff13113837cc81bfc6fe4f.Implemented in this branch
successresults. Missing, skipped, cancelled and failed results are not acceptance.8a0c7f445cc3c8ad499d8970a06ffd204ea9f021and harness blob63eace3993959ba6b8350d391af29163498cf923.project_root_violationto emittedinvalid_request; document negotiated policy-refusal handling without unrestricted fallback, availability versus authorization, and Rust peer-bound renegotiation without automatic mutation replay. Ten page regressions are wired throughcheck:automationand therefore fullpnpm verify.Latest API facts were reviewed against immutable Coven
801e9f219b1d50336ad4111ca92ce2a3a1eafa3c,docs/API-CONTRACT.mdblobccdc69acb5662959ffb88d02c721a795de1fa660(reusable client, structured errors and stable error codes). The source contract, not the new documentation tests, establishes runtime behavior.Verification actually performed
Local latest-slice proof
The old API page was reconstructed with exact blob
243f1a355b547de0f33d5b5c4972e44750e3379c. Its three positive page checks failed before the repair. The full initial ten-case run had three passes and seven failures; four failures were mutation setup against the uncorrected page, not seven separate runtime bugs. After correction, all ten cases passed, including seven negative mutations.node --test scripts/check-source-drift.test.mjs scripts/docs-release-gate.test.mjs scripts/api-reference-contract.test.mjs: 98 passed, zero failed/skipped/cancelled on Node 22.16.0. Syntax and whitespace checks passed. All three GitHub blob identities match the locally tested bytes. The local workspace is a sparse inspection copy, not a full dependency-installed checkout; no local full-site or native-runtime acceptance is claimed.Exact-head hosted proof
Run 36249152337 completed:
108423806443: success, including frozen dependency installation, Chrome installation, completepnpm verify, clean-generated-tree check and evidence upload.108423806536: failure after successful regression and source-lock validation steps; six real watched paths differ.108424131698: failure, correctly refusing release despite browser success.Downloaded and independently verified both ZIP SHA-256 values:
docs-certification-3624915233710907973447e8501ef4e513d5d3889966091f9565e46dc926931aad58fcbd8358ddb279ce8ddocs-source-drift-3624915233710908293813c095adb53f2965e7d99a1747209e718184a1bd0b7aa6e6b3fc47617d9b14e621The browser report binds merge tree
976ce7f...and returnsok:true: 12 HTTP-200 routes, including the changed/docs/reference/apipage with its canonical URL and one H1/main, four journey categories, three 390px no-overflow checks and five retained screenshots. This is CI-localhost site evidence, not a production deployment.Remaining #89 work
The authenticated freshness report binds reviewed upstream
9c7615a75c0a84dc9ef6f323bc542f30633189f0to target801e9f219b1d50336ad4111ca92ce2a3a1eafa3c. Differences remain in CLImain.rs,api.rs,harness.rs,setup/mod.rs,setup/process.rs, anddocs/API-CONTRACT.md.The custom-adapter and API-page corrections are bounded reviewed slices, not completion of the entire six-file/source-section review.
docs/source-lock.json,verifiedCommit, andverifiedAtremain unchanged. Finish the remaining source-to-public-page and any generated OpenAPI reconciliation, then truthfully advance the lock and require fresh successful canonical verification.No runtime authority, dependency, publishing control or workflow was changed by the latest three-file commit. No release, deployment or human acceptance is inferred. Earlier raw red/green and hosted receipts remain in the PR comments and commit history, including run 35671468692 and comment 5769508439; they are historical evidence, not substitutes for the new head above.