Skip to content

fix(delivery): review the whole candidate before every push - #71

Merged
clairernovotny merged 1 commit into
mainfrom
codex/whole-change-review-gate
Sep 30, 2026
Merged

clairernovotny merged 1 commit into
mainfrom
codex/whole-change-review-gate

Conversation

@clairernovotny

@clairernovotny clairernovotny commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Delivery could publish a repair or release after reviewing only the latest delta. Require paired adversarial reviews and Codex review of the complete candidate before every push, including repair, rebase, and release pushes. Bind findings and validation to the published tree while keeping CE responsible for online review settlement and merge.

The startup charter, delivery skills, and published guides use the same rule. Record escaped findings, external repair rounds, and time to settlement; preserve unknown historical values instead of inventing a catch rate. Both plugin manifests advance to 0.12.7.

Validation: all 22 cumulative files passed independent correctness/security, maintainability, and Codex reviews. The required native suite passed 554 tests; the 42 affected tests and all site checks passed again after the final changes. The site builds 76 pages. Four restricted process-inspection failures reproduce on the unchanged base and pass in the native suite.

Summary by CodeRabbit

  • Documentation
    • Updated delivery guidance to require a review of the complete cumulative change and affected lifecycle before every push, including repair and release pushes.
    • Clarified that standalone, narrower reviews do not satisfy the publication gate. Review evidence must match the candidate being pushed, and unchanged evidence may be reused when its inputs and coverage still match.
    • Added guidance for recording candidate coverage, findings, and delivery outcomes. Documentation-only changes remain exempt from release machinery, but still require publication review.
  • Release
    • Updated the Railyard plugin version to 0.12.7.

Copilot AI balanced review requested due to automatic review settings September 30, 2026 00:43

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T00:46:00.343202Z 962a5e1 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: d170231b-155d-4caa-9379-24814507feda

📥 Commits

Reviewing files that changed from the base of the PR and between c525b5d and 962a5e1.

📒 Files selected for processing (22)
  • AGENTS.md
  • docs/agents/release-coupling.md
  • docs/whole-candidate-review-baseline.md
  • plugins/railyard/.claude-plugin/plugin.json
  • plugins/railyard/.codex-plugin/plugin.json
  • plugins/railyard/hooks/routing-charter.js
  • plugins/railyard/hooks/routing-charter.test.mjs
  • plugins/railyard/references/whole-candidate-review.md
  • plugins/railyard/skills/deliver/SKILL.md
  • plugins/railyard/skills/deliver/references/ce-call-adapter.md
  • plugins/railyard/skills/orchestrate/SKILL.md
  • plugins/railyard/skills/orchestrate/scripts/delivery-contracts.test.mjs
  • plugins/railyard/skills/thermo-nuclear-review/SKILL.md
  • plugins/railyard/skills/thermos/SKILL.md
  • site/src/content/pages/delivery/gates.md
  • site/src/content/pages/delivery/lifecycle.md
  • site/src/content/pages/faq/index.md
  • site/src/content/pages/skills/deliver.md
  • site/src/content/pages/skills/thermos.md
  • site/src/content/pages/start/first-delivery.md
  • site/src/content/pages/start/index.md
  • site/src/content/pages/what-it-does/ship-a-change.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The changes make whole-candidate review mandatory before every push. They define review scope, evidence receipts, and publishing checks, then update delivery workflows, reviewer guidance, and related documentation.

Changes

Whole-candidate publication gate

Layer / File(s) Summary
Define the gate, receipt, and ledger
AGENTS.md, docs/agents/release-coupling.md, docs/whole-candidate-review-baseline.md, plugins/railyard/references/whole-candidate-review.md, plugins/railyard/skills/orchestrate/scripts/delivery-contracts.test.mjs
The shared gate defines cumulative-candidate review, proof reuse, receipt contents, publication blocks, publisher checks, and delivery metrics. Project and documentation-exemption instructions also require the gate. Tests check gate, receipt, and ledger requirements.
Wire the gate into publishing handoffs
plugins/railyard/.claude-plugin/plugin.json, plugins/railyard/.codex-plugin/plugin.json, plugins/railyard/hooks/routing-charter.js, plugins/railyard/hooks/routing-charter.test.mjs, plugins/railyard/skills/deliver/SKILL.md, plugins/railyard/skills/deliver/references/ce-call-adapter.md, plugins/railyard/skills/orchestrate/SKILL.md
Delivery, orchestration, and direct publishing instructions require a matching whole-candidate receipt before pushes. Routing guidance and tests reference the shared gate. The plugin manifests update to version 0.12.7.
Define reviewer scope and reports
plugins/railyard/skills/thermo-nuclear-review/SKILL.md, plugins/railyard/skills/thermos/SKILL.md
Reviewer guidance specifies complete-candidate and lifecycle coverage, receipt evidence, and how to record intentional breakage. Reportable defects remain limited to those introduced or exposed by the change.
Update delivery and review instructions
site/src/content/pages/delivery/*, site/src/content/pages/faq/index.md, site/src/content/pages/skills/*, site/src/content/pages/start/*, site/src/content/pages/what-it-does/ship-a-change.md
Site guidance now describes pre-push review, Thermos and Codex coverage, exact-candidate receipts, evidence reuse, repair-push revalidation, and CE settlement responsibilities.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 962a5

No concrete merge-blocking issue is established by the supplied evidence. Proceed with normal repository checks.

Architecture Summary

Architecture risk: 🔵 Low · up to 962a5

The change affects 4 systems.

Changed systems: plugins, site, docs, AGENTS.md

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — plugins (service) was modified; 11 changed files map to changed impact.
  • observed — site (ui) was modified; 8 changed files map to changed impact.
  • observed — docs (service) was modified; 2 changed files map to changed impact.
  • observed — AGENTS.md (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in AGENTS.md: Adds a project publishing requirement to satisfy the whole-candidate review gate before every push, including repair and release pushes; for CE, delta review or a test pass alone does not satisfy it.
  • observed — Modified behavior in docs/agents/release-coupling.md: The exemption now requires the whole-candidate review gate before every push and clarifies that it removes release machinery, not publication review; the prior instruction to commit and push documentation changes directly was removed.
  • observed — Modified behavior in docs/whole-candidate-review-baseline.md: Adds the PR18 review baseline, source-comment links, unknown metric caveats, and instructions for recording and comparing measurements in subsequent deliveries.
  • observed — Modified behavior in plugins/railyard/.claude-plugin/plugin.json: Updated the plugin manifest version from 0.12.6 to 0.12.7.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the main change: requiring whole-candidate review before every push.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 3…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@clairernovotny
clairernovotny merged commit e45779a into main Sep 30, 2026
6 checks passed
@clairernovotny
clairernovotny deleted the codex/whole-change-review-gate branch September 30, 2026 00:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants