chore(release): prepare v0.36.0 beta-48 - #1739
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b1f0f04a62
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
b1f0f04 to
022b88e
Compare
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6f0f332b72
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ject in v0.36.0 notes Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f418ec67f1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… the schedulingctl audit file Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 457b7aff33
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…Scheduling to the upgrade order Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 71672a99e7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…g upgrade and rollback steps Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 40caf7754e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…the restored claim on rollback, and retire Scheduling Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Prepare Registry Stack v0.36.0 / beta-48. This commit carries:
v0.36.0 is the first breaking beta of the 1.0 push. It carries 19 BREAKING entries: BReg 9, Casework 7, Evidence 1, Scheduling 2. The notes give the migration step for each. Main points:
evidencectlresult envelope (feat(evidence)!: give evidencectl the shared ctl report and exit contract #1663).bregctlusage error no longer repeats a rejected argument value (fix(breg): keep rejected argument values out of bregctl usage errors #1736, closing bregctl usage errors repeat a rejected argument value, including --operator-reference #1699)./usr/local/bin/<name>ctl, and the manifest addsschedulingctl.Security review notes (advisory baselines, deployment defaults, release provenance):
Unchanged images. The runtime bases and every image's OCI process configuration are unchanged.
renew-advisory-baselineswould have refused either change, and it refused nothing.What the renewal moved. The subcommand moved, for all six images:
release/scripts/test_check_advisory_baselines.py.A second dry run reports no changes, the strict check passes for every image, and
test_check_advisory_baselinespasses.The 18 exceptions are re-reviewed and kept. They cover CVE-2026-5435 and CVE-2026-19499 on libc6, and CVE-2026-85091 on zlib1g.
expires_atstays 2026-10-06.The operator tools are reviewed too. They are new in these images this release, so the rehearsal records an exposure report for each (
exposure/<name>.<name>ctl.json).bregctl,caseworkctlorschedulingctlimports or contains the resolver-printing,strfmon, libz or gzip-write symbols the rationales name. I checked both the exposure reports and the exported bytes.bregctl's onereview_requiredentry is the same Wasmtime ittapidlsymprobe asbreg: it reaches the tool through registry-breg, registry-platform-script, wasmtime and ittapi.caseworkctlandschedulingctlhave none.files. Thewhole_image_fingerprint_equalsassertion already binds every ordered rootfs DiffID, including the application layer that holds the tool.Other
review_requiredentries are unchanged: SQLite's nonconstant extensiondlsymin evidence and relay, whereload_extensionis denied. Casework, discovery and scheduling have none.Documentation date. The documentation set is dated 2026-09-29, the intended publication date.
Review fixes. The upgrade steps name
--runtime-config FILEon every BReg, Casework and Schedulingplan,apply,verifyandstatuscall. The Evidence migration, in the notes and the docs changelog, keeps the documented--projectonsource import,source diff,source updateandtarget new. Because the changelog is archived, the v0.36.0 archive-lock entry was regenerated from the fixed tree. The upgrade order, in the notes and inupgrade-and-retire.mdx, now includes a Scheduling backup and activation step, and every BReg and Casework command in the runbook carries its required--runtime-config(and--package). A read-only review of the runbook against the code then completed it: the BReg rebuild namesbregctl testand--test-receipt, Casework addsidentity.databaseId, repins its BReg sources, and repointspackage.root, the earliercaseworkandevidenceprocesses are stopped before the new ones start,evidence checktakes--runtime-config, and "Roll back" covers returning BReg, Casework, and Scheduling to the previous release, and the Scheduling changelog names theschedulingctlsibling ofaudit.pathinstead of a literal file name. A further round namesBUILD/packageas the packagebregctl package --output BUILDwrites, repoints BRegpackage.expectedDigestwhen set, has a BReg rollback restore into a fresh database and adopt its instance claim with the v0.35.0bregctl instance-claim adoptbefore starting the previousbreg, and adds "Retire Scheduling" to "Retire a deployment".Validation:
registry-release validateon beta-48;registry-release prepare(ready);test_registry_release;test_check_advisory_baselines;cargo fmt --check;cargo check --locked --workspace --all-targets.Known follow-ups, not blockers:
rehearse-upgrade.pydoes not cover Scheduling or the Casework BReg-source repin (test(release): rehearse the Scheduling upgrade and the Casework BReg-source repin #1740).