docs(6.0): backfill the changelog for the release's back half, and say what the release lane has actually run - #731
Merged
Conversation
…y what the release lane has actually run The [Unreleased] section covered work through #627 and stopped. Every PR from #630 through #727 — 46 merges, ~52 issues — had no entry, including every defect an adopter reported against a release candidate. 46 entries, derived from each commit's diff and issue thread rather than its subject line. That produced seven recorded divergences, kept as HTML comments beside the entries they explain. Two matter most: #668's title claims it fixed tag reading, but its whole diff is a fetch-tags: true that is a no-op at fetch-depth: 0, and #669 fixed it 39 minutes later; #715's 'one canonical frontmatter reader' unified four strippers while two non-canonical readers survive on main. ci-confidence.md's tag-authority section reasoned about what the release lane enforces without ever saying which of it had run. It now records that resolve and validate executed for real, qualify executed for the first time on rc.8 and is failing on Windows, and promote has never executed — with what was proven about promote ahead of time, and what remains unproven, stated separately.
0xLeif
requested review from
0xGaspar,
Kyntrin and
tofu-ux
and removed request for
a team
August 27, 2026 21:15
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CHANGELOG.md
The
[Unreleased]section covered 6.0 work through PR #627 and then stopped. Every PR from #630 through #727 had no entry — 46 merges, ~52 issues, the entire back half of the release, including every defect an adopter reported against a release candidate.46 entries are added: 3 Added, 8 Changed, 3 Security, 32 Fixed. The existing
Removedentry (the Windows binary) stays first — it is the single most important thing an upgrader needs, and burying it under 1,700 lines of newer prose would be a regression in the document's job.Nothing existing was touched: verified mechanically that every line of the previous file survives (1,662 lines, all accounted for).
Entries were derived from diffs and issue threads, never from commit subjects
That is not ceremony. Three issues this release — #699, #706, #719 — were filed with diagnoses that were directionally right and specifically wrong, each caught only when an implementer re-derived from source. Writing 46 entries from commit titles would have laundered every one of those errors into the release's public record.
It found seven divergences, kept as HTML comments beside the entries they explain — invisible when rendered, available to anyone doing archaeology later. Two are worth naming here:
fetch-tags: trueonactions/checkout, which is a no-op on that code path: the action assignsfetchTagsonly inside itsfetchDepth > 0branch, so atfetch-depth: 0it is silently dropped. fix(release): a release candidate must be installable without release-grade provenance #669 established this 39 minutes later, removed the line, and replaced it with an explicitgit fetch --force. The entry credits fix(release): a release candidate must be installable without release-grade provenance #669.parse_frontmatterCRLF-tolerant, but two non-canonical readers survive onmain:registry.rs's line-wiseextract_module_nameandcommands/lifecycle.rs's unanchoredfind("---\n"). The commit body is honest about this; the subject is not.docs/ci-confidence.md
Its "Tag authority" section reasons carefully about what the release lane enforces and never says which of it has ever run. A new subsection records that:
resolveworkflow_dispatchdry run, first in the repository's historyvalidatequalifypromotepromotecannot be rehearsed here:final_tagderives from the candidate's ownCargo.toml, so any run against a real candidate mints the real tag. The proof and the release are the same event.What was proven ahead of time is recorded with its limits. The
Create final tagstep was transcribed verbatim against a local bare repository and all three branches exercised — a fresh create produces an annotated tag pointing atcandidate_shaand not HEAD; a re-run against the same candidate takes the idempotent path; a re-run against a different candidate refuses. And both rulesets were confirmed to carryupdateanddeletiononly, so tag creation is unrestricted and immutability cannot block the mint — the failure that would otherwise have appeared for the first time at the moment of release.What remains unproven is named rather than glossed: a local path remote never asks for a credential, so the rehearsal shows the credential helper's
git -csyntax does not break the invocation, not that it authenticates.Deliberately not done
Consolidating the pre-existing duplicate
### Fixedand### Changedheadings inside[Unreleased]. They were already there; fixing them means reordering ~700 lines of prose nobody is changing and would bury 46 new entries in an unreviewable diff. Recorded in the change'scontext.md.Findings that became their own issues
The backfill surfaced three defects too substantial to fix inside a docs change: #728 (a live requirement describing behaviour deleted by #665, invisible to
checkby construction), #729 (ADOPTING.mdleads with the pre-#689 squash cost), and #730 (the delta binding hashes raw bytes while the applier normalizes line endings).change checkexit 0 · 2395 unit + 407 integration · independent review recorded · finalized ·change audit --strictexit 0.🤖 Generated with Claude Code
https://claude.ai/code/session_01DgYAvsQM6P9fKxDotnDuzP