Skip to content

chore: Stable dispatcher releases now open the pin-stamp pull request automatically - #2473

Merged
hatayama merged 3 commits into
mainfrom
chore/hatayama/dispatcher-pin-auto-stamp-pr
Aug 31, 2026
Merged

hatayama merged 3 commits into
mainfrom
chore/hatayama/dispatcher-pin-auto-stamp-pr

Conversation

@hatayama

@hatayama hatayama commented Aug 31, 2026 •

Copy link
Copy Markdown
Owner

Part 1 of #2463.

Summary

  • Publishing a stable dispatcher release now opens the pin-stamp pull request automatically; reviewing and merging it is the only manual step left
  • Pre-releases are never stamped onto main, and minimumDispatcherVersion is never touched

User Impact

  • Before: after dispatcher-vX.Y.Z was published, someone had to remember to run stamp-dispatcher-pin, mirror the file to .uloop/, and open a PR. During the 3.0.0 release this was missed, so fresh install.sh runs kept installing a beta dispatcher until chore: update dispatcher pin to the 3.0.0 stable release #2461
  • After: the dispatcher-publish workflow's post-publish job opens chore: update dispatcher pin to the X.Y.Z stable release with the two-file diff, verified the same way the manual command verifies it. The stamp still goes through attestation verification before anything is written

Changes

  • cli/release-automation/cmd/open-dispatcher-pin-pr (new) backed by internal/automation/dispatcher_pin_pr.go: rejects pre-release tags up front; branches chore/dispatcher-pin-<tag> from the current main tip; runs StampDispatcherPin; mirrors Packages/src/project-runner-pin.json byte-identically to .uloop/project-runner-pin.json; re-verifies offline and against the published release subjects; exits 0 without a PR when the pin already records the tag; commits as github-actions[bot]; pushes (plain for a new branch, --force-with-lease pinned to the observed remote SHA otherwise); creates or updates the open PR for that head; then dispatches the required check workflows
  • internal/automation/pull_request_checks.go (new): DispatchPullRequestChecksForHead shared by the release-please check dispatcher and the new command, because a PR created with GITHUB_TOKEN never triggers pull_request workflows. The release-please path keeps its draft → watch → ready flow unchanged; the pin PR only dispatches and returns so post-publish does not wait on Unity CI
  • .github/workflows/dispatcher-publish.yml: build exposes release_prerelease; post-publish gains pull-requests: write and actions: write and a final step gated on should_publish == 'true' && release_prerelease != 'true' that runs gh auth setup-git (the checkout keeps no credentials) and the new command. No new uses: refs
  • docs/dispatcher-pin-release-order.md, docs/project-runner-pin.md: describe the automated flow and keep stamp-dispatcher-pin as the manual fallback

Not in this PR

Verification

  • cli/release-automation: gofmt -l . clean, go vet ./..., go test ./... pass; golangci-lint run with both .golangci.yml and .golangci-complexity.yml report 0 issues
  • scripts/check-go-cli.sh exit 0; go run ./cmd/check-release-triggers --base origin/main --head HEAD → "Release trigger guard passed."; go run ./cmd/check-file-length reports no file over 500 SLOC
  • actionlint .github/workflows/dispatcher-publish.yml exit 0
  • Branch ruleset scope confirmed as ~DEFAULT_BRANCH and v3-beta only, so the workflow token can push chore/dispatcher-pin-*
  • End-to-end behavior can only be observed on the next stable dispatcher release; the unit tests cover the stable, already-stamped, existing-branch, invalid-stamp, and pre-release paths with recorded git/gh invocations

https://claude.ai/code/session_01XbhSMKK4LFud57iAmowDz7

Review in cubic

…equests

The release-please check runner could only dispatch workflows for a pull
request it had found by the release-please head-ref naming convention, so no
other automated pull request could reuse it. A pull request created with
GITHUB_TOKEN never triggers pull_request workflows, and the upcoming dispatcher
pin pull request needs the same treatment.

Move the dispatch loop and the gh body-file helper behind an entry point that
takes an explicit head ref and a caller-supplied description, and let the
release-please path pass its own description so its log output is unchanged.

Claude-Session: https://claude.ai/code/session_01XbhSMKK4LFud57iAmowDz7
Fresh installs resolve the dispatcher named by the package pin, so a published
stable release does not reach new users until the pin records it. Both stable
stamps so far were hand-made pull requests, which is exactly the step that gets
forgotten while a stale release keeps being installed.

The command branches from the base tip, stamps the package pin with the
attestation-verified manifest, mirrors it byte-identically to the project pin,
re-verifies it offline and against the published release subjects, then commits
as the workflow bot, pushes, and opens or refreshes the review pull request.
A pre-release tag is refused up front so a pre-release can never become the pin
on a stable branch, and minimumDispatcherVersion is left untouched because
raising the floor would lock out working installs. A run with nothing to change
opens no pull request, so retries stay harmless.

Claude-Session: https://claude.ai/code/session_01XbhSMKK4LFud57iAmowDz7
The pin stamp was a manual step that nothing reminded anyone to perform, so a
published stable dispatcher could stay unreachable for fresh installs
indefinitely.

Run open-dispatcher-pin-pr from post-publish whenever a stable release was
published, exposing the resolver's prerelease flag as a build output so
pre-releases are skipped at the workflow level as well as inside the command.
The job now needs pull-requests: write to open the pull request and
actions: write to dispatch its required checks, and gh auth setup-git supplies
the push credential the credential-free checkout does not keep.

Claude-Session: https://claude.ai/code/session_01XbhSMKK4LFud57iAmowDz7
@coderabbitai

coderabbitai Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 18559815-5baa-4f54-b59a-533b2d66f55a

📥 Commits

Reviewing files that changed from the base of the PR and between e627bb1 and 541cc0f.

📒 Files selected for processing (10)
  • .github/workflows/dispatcher-publish.yml
  • cli/release-automation/cmd/open-dispatcher-pin-pr/main.go
  • cli/release-automation/internal/automation/dispatcher_pin_pr.go
  • cli/release-automation/internal/automation/dispatcher_pin_pr_test.go
  • cli/release-automation/internal/automation/pull_request_checks.go
  • cli/release-automation/internal/automation/pull_request_checks_test.go
  • cli/release-automation/internal/automation/release_pr_check_runs.go
  • cli/release-automation/internal/automation/release_pr_checks.go
  • docs/dispatcher-pin-release-order.md
  • docs/project-runner-pin.md
💤 Files with no reviewable changes (1)
  • cli/release-automation/internal/automation/release_pr_check_runs.go

Included review availability: Your plan provides up to 4 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The release workflow now invokes open-dispatcher-pin-pr for stable dispatcher releases. The command stamps and validates both pin files, pushes a branch, creates or updates a pull request, and dispatches required checks. Documentation describes the automated flow and manual fallback.

Changes

Dispatcher pin automation

Layer / File(s) Summary
Pin stamping flow
cli/release-automation/internal/automation/dispatcher_pin_pr.go, cli/release-automation/internal/automation/dispatcher_pin_pr_test.go
The command validates stable tags, checks out the base branch, stamps and mirrors both pin files, validates them, and skips unchanged pins. Tests cover prerelease rejection, idempotency, and invalid pins.
Pull request check dispatch
cli/release-automation/internal/automation/pull_request_checks.go, cli/release-automation/internal/automation/pull_request_checks_test.go, cli/release-automation/internal/automation/release_pr_checks.go
Configured pull request workflows now dispatch against a supplied head ref. Shared temporary body-file handling replaces the release-check-specific helper.
Branch push and pull request publication
cli/release-automation/internal/automation/dispatcher_pin_pr.go, cli/release-automation/internal/automation/dispatcher_pin_pr_test.go, cli/release-automation/cmd/open-dispatcher-pin-pr/main.go
The command commits pin changes, uses force-with-lease for existing remote branches, creates or edits the matching pull request, and dispatches checks. Tests cover stable releases and existing pull requests.
Release workflow integration
.github/workflows/dispatcher-publish.yml, docs/dispatcher-pin-release-order.md, docs/project-runner-pin.md
The workflow gates pin stamping on stable published releases and grants pull request and workflow permissions. Documentation describes the automated process and manual fallback.

Estimated code review effort: 4 (Complex) | ~45 minutes

Merge Risk: ⚪ Minimal · up to 541cc

This change automates creation of the stable dispatcher pin pull request without introducing an actionable merge-blocking risk at the current head.

Sequence Diagram(s)

sequenceDiagram
  participant DispatcherPublish
  participant OpenDispatcherPinPR
  participant GitHub
  DispatcherPublish->>OpenDispatcherPinPR: Invoke for a published stable tag
  OpenDispatcherPinPR->>OpenDispatcherPinPR: Stamp and validate pin files
  OpenDispatcherPinPR->>GitHub: Push pin branch
  OpenDispatcherPinPR->>GitHub: Create or edit pull request
  OpenDispatcherPinPR->>GitHub: Dispatch required check workflows
Loading
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 20.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 40 functions across 6 files. (3 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely summarizes the main change: stable dispatcher releases now automatically open the pin-stamp pull request.
Description check ✅ Passed The description directly explains the automated stable-release pin-stamp workflow, pre-release handling, permissions, tests, documentation, and excluded follow-up work.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 20.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 40 functions across 6 files. (3 skipped: 3 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/hatayama/dispatcher-pin-auto-stamp-pr

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hatayama
hatayama merged commit 517ad62 into main Aug 31, 2026
15 checks passed
@hatayama
hatayama deleted the chore/hatayama/dispatcher-pin-auto-stamp-pr branch August 31, 2026 14:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant