Skip to content

ci(ci): move mutation to a release gate on main - #35

Merged
kiro-systemf[bot] merged 9 commits into
mainfrom
lake1/release-gate
Oct 7, 2026
Merged

kiro-systemf[bot] merged 9 commits into
mainfrom
lake1/release-gate

Conversation

@systemfsoftware-maker

@systemfsoftware-maker systemfsoftware-maker commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Lake 1, U3 (Evaluator) — stacked on #33.

Operator approval: Kiro, 2026-10-05 (GATE1).

  • pnpm check:ci no longer runs pnpm mutation; mutation never runs in the PR gate (R66).
  • New .github/workflows/release-gate.yml on push to main only (no manual dispatch), concurrency queued and never cancelled:
    • plan (fleet small) runs scripts/mutation-shards.ts, which lists every workspace package whose package.json declares a mutation script and fails on an empty set.
    • mutation (fleet large, one job per package, fail-fast: false, 75 min) restores the package's reports/stryker-incremental.json from the Actions cache and runs turbo run mutation --filter=<pkg> at break: 100, uploading the reports.
  • packages/starter/stryker.config.ts drops prioritizePerformanceOverAccuracy (removed in stryker-js 15, optional in 13) ahead of U4.

#51 adds the production deploy job to this workflow.

QA

$ deno check --config=scripts/deno.json scripts/mutation-shards.ts
Check scripts/mutation-shards.ts
$ ./scripts/mutation-shards.ts
mutation-shards: packages=["@TODO/starter"]
packages=["@TODO/starter"]
exit=0
$ ./scripts/mutation-shards.ts --root <tmp workspace whose only package has no mutation script>
mutation-shards: no workspace package declares a `mutation` script; the release gate refuses an empty set
exit=1
$ nix run nixpkgs#actionlint -- .github/workflows/*.yml
actionlint exit=0
$ pnpm check:ci        # now excludes mutation by definition
exit=0

Stryker was not run locally. The first release-gate run on main after merge is the proof of the shard job.

Review fixes (Kiro rulings, Lake 1 bottom review)

No decisions to mutate (Kiro ruling, 2026-10-06, GATE1)

$ deno test scripts/mutation-shards.test.ts
ok | 6 passed | 0 failed        # 2 new cases: no decisions → no shards and no refusal; decisions without a mutation script → refused
# sabotage, restored: drop the no-decisions return → "a workspace without a single *.workflow.ts file …" FAILED (5 passed, 1 failed)
# sabotage, restored: count *.decision.ts instead → 5 of 6 FAILED
$ ./scripts/mutation-shards.ts          # this layer's tree: no *.workflow.ts; packages/starter declares mutation
::notice title=Release gate::No decisions to mutate: no workspace package has a *.workflow.ts file.
packages=[]                             # exit 0
$ ./scripts/mutation-shards.ts          # #63's tree as of cycle 35 (9d4a3a4)
mutation-shards: packages=["@endgame/site"]
$ ./scripts/mutation-shards.ts          # #63's tree before cycle 35, plus one untracked apps/site/src/probe.workflow.ts
mutation-shards: 1 *.workflow.ts file(s) but no workspace package declares a `mutation` script; the release gate refuses an empty set
                                        # exit 1
$ actionlint                            # release-gate.yml as it stands at #35…#49, #52…#50 and #51…#63
exit=0
$ pnpm check:ci                         # at #63, after the restack
checkci=1                               # only check:sfs-sources (#52's blocker); 8/8 turbo tasks incl. test:scripts, build, sandbox proofs pass

Not exercised: a release-gate run on GitHub. The workflow runs only on push to main.

Cycle 35 (Kiro rulings on starter-verify's review)

  • F10 (6b3c059): release-gate.yml drops workflow_dispatch:. Mutation runs on push to main only.
  • F13 (6b3c059): the README describes what the code has. It no longer claims Cell workflows, a single Cell.provide at the root, tenant-bound store ports or compile-time phase markers, and no longer tells readers to run pnpm mutation locally; the FAQ says mutation runs only in the release gate on main.
  • Gate at 6b3c059, clean worktree: pnpm check:ci exit 0.

Linux only (Kiro, cycle 52)

Ryan's standing rule: no macOS anywhere in our repos.

  • 95bbb06 merges main with chore: drop macOS from CI (hosted larger-runner quota) #67, which dropped the macOS CI leg.
  • 29d1b80: the flake builds x86_64-linux and aarch64-linux only; nix/dprint.nix pins only the two Linux release archives; the comment-checker sandbox loses its sandbox-exec branch and keeps bubblewrap; AGENTS.md says every job runs on ubuntu-latest and CI is Linux only.

Gate at 29d1b80, clean worktree, Linux:

$ pnpm install --frozen-lockfile    # exit 0
$ pnpm check:ci                     # exit 0: 6/6 turbo tasks, dist 1/1

CI run 37573302092 on 29d1b80: all 5 jobs pass (format, lint, typecheck, test, dist).

@systemfsoftware-maker
systemfsoftware-maker added this pull request to stack #34 October 5, 2026 19:34
Base automatically changed from lake1/fleet to main October 6, 2026 01:46
systemfsoftware-maker added a commit that referenced this pull request Oct 6, 2026
… and QA evidence

Findings for #35-#38 and #41 from ce-code-review (8 lenses, validator), the verifier's terminal probes of the confirmed findings, and the real-browser and real-CLI QA. Nothing applied; each finding waits for a ruling
@systemfsoftware-maker
systemfsoftware-maker removed this pull request from stack #34 October 6, 2026 16:04
@systemfsoftware-maker
systemfsoftware-maker added this pull request to stack #54 October 6, 2026 19:52
@systemfsoftware-maker
systemfsoftware-maker removed this pull request from stack #54 October 6, 2026 21:56
@systemfsoftware-maker
systemfsoftware-maker added this pull request to stack #59 October 6, 2026 21:57
@systemfsoftware-maker
systemfsoftware-maker removed this pull request from stack #59 October 6, 2026 22:13
@systemfsoftware-maker
systemfsoftware-maker added this pull request to stack #61 October 6, 2026 22:13
check:ci no longer runs stryker. The release gate on push to main plans one
shard per workspace package that declares a mutation script, refuses an
empty set, and runs each shard at break 100 on the fleet with its
incremental report cached. The checker drops
prioritizePerformanceOverAccuracy, which stryker-js 15 removes. Operator
approval: Kiro, 2026-10-05 (GATE1)
The plan and per-package mutation jobs move from the self-hosted fleet,
which admits only private repositories, to ubuntu-latest. Mutation stays
one parallel job per package.

Operator approval: Kiro, 2026-10-05 (GATE1)
A package with a mutation script whose mutate globs match nothing
reports zero mutants and passes a break-100 threshold vacuously
(review finding #9). Each package now declares its globs once, as
stryker.mutate in package.json; its Stryker config reads them and the
release gate's shard planner expands them. The planner fails red at
plan time naming the package, its directory and its globs when they
match no file, including a package with no declared globs. Its Deno
tests are ordinary tests: a turbo root task, test:scripts, runs them
through the dev shell's deno, and both pnpm test and check:ci run it,
so a local check:ci covers the planner exactly as CI does
…ns to mutate

A decision is a *.workflow.ts file. When no workspace package has one, the planner emits an empty shard list and a 'No decisions to mutate' notice, and the mutation job is skipped. When decisions exist and no package declares a mutation script, it still refuses the empty set, naming how many decisions went unmutated. Kiro ruling, 2026-10-06
starter-verify F10 and F13 (Kiro ruling, cycle 35): drop workflow_dispatch so mutation runs on push to main only; the README no longer claims Cell workflows, Cell.provide, tenant-bound store ports or compile-time phase markers, and no longer tells readers to run pnpm mutation locally
Ryan's standing rule via Kiro (cycle 52): no macOS anywhere. The flake builds x86_64-linux and aarch64-linux only; dprint pins only Linux archives; the comment-checker sandbox loses its sandbox-exec branch; AGENTS.md says CI is Linux only

@kiro-systemf kiro-systemf Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Conductor verdict: 7/7 checks green on b23a8e2, 0 unresolved threads, no unchecked boxes, two starter-verify reviews with no findings on this layer, hunt grep clean.

@kiro-systemf
kiro-systemf Bot merged commit 583c747 into main Oct 7, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant