Skip to content

refactor(release): simplify desktop distribution channels#10163

Merged
Git-on-my-level merged 18 commits into
mainfrom
codex/simplify-release-channels
Jul 21, 2026
Merged

refactor(release): simplify desktop distribution channels#10163
Git-on-my-level merged 18 commits into
mainfrom
codex/simplify-release-channels

Conversation

@Git-on-my-level

@Git-on-my-level Git-on-my-level commented Jul 20, 2026

Copy link
Copy Markdown
Collaborator

Summary

Simplifies Omi release distribution while closing the executable draft-PR blockers. The branch is rebased onto current origin/main and now includes the independently reviewed memory chronology fix that was blocking the broad backend CI lane.

Beta and Stable remain two desktop distribution pointers over one immutable qualified manifest. The generalized release-record/ring system, Beta backend fleet/routing, nomination, emergency promotion, holds/receipts, and qualification-claim state are not restored.

Trust, deployment, and routing changes

  • Qualification records exact Stable/Beta URLs, hashes, and Sparkle signatures for all four files; Beta and Stable promotion bind a successful trusted candidate-tag qualification run at the exact release-source SHA, never rebuild, and reject mutable release drift before pointer movement.
  • Evidence labels are explicit: T2/fault coverage is source-built named-bundle evidence at the frozen tag, while exact signed ZIP/DMG smoke is signing/notarization/package/storage proof. Required operational evidence remains signed .89 upgrade, .70 side-by-side, core journeys, soak, and same-manifest Stable promotion.
  • Stable controls are pinned to main, use actual access-token expansion, retain exact lost-response pointer idempotency, accept retained qualified repoints, and verify exactly one identity=stable XML item with immutable version/build/enclosure/signature facts.
  • environment=prod, deploy_targets=all rejects before checkout, cloud authentication, image publication, or mutation because transactional GKE/config rollback parity does not exist.
  • environment=prod, deploy_targets=cloud-run-only is intentionally narrow: exact no-traffic tag, VPC Cloud Run Job known-audio gate with Cloud Run IAM plus Firebase auth, traffic snapshot/restore, and unconditional cleanup of the tag, Job, temporary invoker grant, and temporary service account. It performs no GKE mutation.
  • Source-admitted direct GKE workflows (gcp_backend_listen_helm.yml, pusher, llm-gateway, agent-proxy) remain their respective production paths and report checked-out HEAD identity with fresh-origin/main ancestry diagnostics.
  • Production-family Codemagic workflows pin https://api.omi.me/; the startup function called by main.dart validates the production API and agent WSS authority. It rejects old Beta/dev/staging/arbitrary overrides while development remains configurable.
  • Node-20 artifact-action majors are replaced with repository-approved Node-24 majors. Resolver cache fixtures cover validated primary and LKG records under the expanded immutable Beta manifest contract.
  • Required-memory processing no longer owns or extends short-term TTL. The authoritative apply owner preserves persisted capture/corroboration expiry and keeps updated_at monotonic under clock skew; receipt chronology cannot predate capture or grant freshness.

Product invariants affected

  • INV-AUTH-1
  • INV-INT-1
  • INV-MEM-1

Failure-Class: FC-nonrecoverable-promotion

Verification

  • Combined rebased exact head: deterministic local PR preflight passed all 49 selected checks.
  • Combined backend selection: memory lifecycle 28 passed, authoritative memory apply store 7 passed, and test_sync_v2.py 163 passed.
  • Focused desktop release/update/probe/vector suite: 62 passed.
  • Memory lifecycle exact file also passed three consecutive times before folding; adjacent apply/lifecycle/model suites: 100 passed.
  • Deployment concurrency, direct-writer and mobile-routing mutation contracts: passed.
  • actionlint for changed release/deploy workflows and git diff --check: passed.
  • Flutter environment tests: 7 passed; targeted analysis had only the existing non-blocking library_private_types_in_public_api information message.
  • Swift debug build and APIClientRoutingTests: 60 passed.

Qualification boundary

Source-built named-bundle T2/fault evidence and exact signed-artifact evidence are separate layers. Signed production binaries do not expose a local automation/fault interface. Before Stable promotion, the exact signed Beta artifact still requires .89 upgrade, .70 side-by-side operation, real core journeys, recovery checks, and soak. Stable advances the same immutable qualified manifest without rebuilding.

Non-executed live operations

No cloud resources, releases, pointers, production app bundles, secrets, deployments, or workflows were changed or dispatched.

@mintlify

mintlify Bot commented Jul 20, 2026

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
omi 🟢 Ready View Preview Jul 20, 2026, 11:45 PM

💡 Tip: Enable Workflows to automatically generate PRs for you.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 79742669d0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread backend/scripts/probe-transcription-candidate-from-cloud-run.sh Outdated
Comment thread backend/scripts/run_vpc_transcription_candidate_probe.py Outdated
Comment thread .github/schemas/desktop-release-manifest-v1.schema.json Outdated
@Git-on-my-level
Git-on-my-level marked this pull request as draft July 21, 2026 03:27
@Git-on-my-level
Git-on-my-level marked this pull request as ready for review July 21, 2026 03:29

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1502c04a65

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/scripts/prepare-desktop-beta-promotion.py Outdated
Comment thread .github/workflows/desktop_promote_beta.yml
@Git-on-my-level
Git-on-my-level marked this pull request as draft July 21, 2026 03:47
@Git-on-my-level
Git-on-my-level marked this pull request as ready for review July 21, 2026 04:34
@Git-on-my-level
Git-on-my-level marked this pull request as draft July 21, 2026 04:35
Failure-Class: FC-nonrecoverable-promotion
Failure-Class: FC-nonrecoverable-promotion
Failure-Class: FC-nonrecoverable-promotion
The canonical apply owner now stamps updates at the maximum of its UTC wall clock and the persisted captured_at and updated_at chronology anchors. This preserves strict MemoryItem validity when an apply host clock lags a persisted item, while retaining the persisted short-term TTL and existing retry/revision behavior.

RED: BACKEND_UNIT_TEST_FILE_LIST=/tmp/omi-memory-apply-red.* bash backend/test.sh (1 failed, 6 passed; strict MemoryItem chronology validation failed with an earlier apply clock).

GREEN: focused persisted apply regression (7 passed); tests/unit/test_ws_b_short_term_lifecycle.py via backend/test.sh 3x (28 passed each); 11 adjacent apply/lifecycle/model suites (all passed).

Verification: black --line-length 120 --skip-string-normalization; scripts/pr-preflight --suggest; failure-class explain/validate; relevant no-service pre-push gates; git diff --check.

Failure-Class: FC-split-mutation-authority
Failure-Class: FC-nonrecoverable-promotion
Failure-Class: FC-split-mutation-authority
Failure-Class: FC-nonrecoverable-promotion

Reviewed-Findings: bound ephemeral Cloud Run IDs, separate Beta artifact schema names, route retained manifests under admin policy, and keep verifier fixtures stdlib-only.
Failure-Class: FC-nonrecoverable-promotion

Policy: require trusted retained manifest fetch, exact beta/stable precondition, pointer-before-bridge ordering, and external appcast verification.
Failure-Class: FC-deployment-proof-gap

Regression: request the tagged candidate URL while minting the IAM identity token for the canonical service audience.
Failure-Class: FC-nonrecoverable-promotion

Review: retain doctor-compatible evidence identity and publish the beta-identity DMG on every static beta redirect surface.
Failure-Class: FC-nonrecoverable-promotion
Failure-Class: FC-deployment-proof-gap

Regression: require all-traffic egress plus pre-creation Private Google Access validation for the production candidate probe.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cf154451b4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines 151 to +154
gh workflow run desktop_promote_beta.yml --repo "$REPO" \
-f release_tag="$RELEASE_TAG" \
-f automatic=true
-f automatic=true \
-f qualification_run_id="$GITHUB_RUN_ID"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Wait for qualification completion before dispatching beta promotion

When automatic qualification succeeds, this last step dispatches desktop_promote_beta.yml with the current run's $GITHUB_RUN_ID before the current workflow has actually completed. The promotion workflow immediately queries that run and requires .conclusion == success (.github/workflows/desktop_promote_beta.yml), but GitHub only reports a success conclusion after the source run is completed; gh workflow run only creates a workflow_dispatch event, so the promoted workflow can start while this run is still in_progress and fail the gate despite valid evidence. This leaves automatic beta promotion flaky/blocked whenever the dispatched workflow is scheduled before the qualifier run is finalized.

Useful? React with 👍 / 👎.


- name: Preflight Omi Bot repository access
- name: Validate trusted qualification run for initial promotion
if: ${{ inputs.operation == 'promote' }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Validate the stable confirmation for repoints too

Because the only step that checks CONFIRM == promote-stable is skipped when inputs.operation == 'repoint', a manual stable repoint can mutate the Stable pointer without satisfying the required typed confirmation. This matters for the new retained-manifest repoint path: even with CAS inputs, an operator who selects repoint accidentally or leaves the confirmation wrong still reaches Advance explicit stable pointer, bypassing the workflow's stated safety prompt.

Useful? React with 👍 / 👎.

@Git-on-my-level
Git-on-my-level force-pushed the codex/simplify-release-channels branch from cf15445 to 914bdd3 Compare July 21, 2026 04:48
@Git-on-my-level
Git-on-my-level marked this pull request as ready for review July 21, 2026 04:51

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 914bdd3e41

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread codemagic.yaml
Comment on lines 2927 to +2928
if gh workflow run desktop_qualify_beta.yml --repo "$GITHUB_REPO" \
-f release_tag="$CM_TAG" -f dispatch_key="$dispatch_key"; then
-f release_tag="$CM_TAG"; then

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bind the qualification dispatch to the release tag SHA

When main advances while Codemagic is building/smoking a candidate, this unqualified gh workflow run dispatch runs the qualification workflow at the repository default branch, not at $CM_TAG (the GitHub CLI manual's no---ref example runs at the remote default branch). The beta promotion gate then compares that run's .head_sha to the release tag SHA, so a valid candidate whose tag is no longer the current main tip fails promotion after qualification evidence is produced. Pass a ref that matches the tag/SHA or change the promotion trust check to validate the evidence/tag rather than the dispatch run's default-branch SHA.

Useful? React with 👍 / 👎.

@Git-on-my-level
Git-on-my-level marked this pull request as draft July 21, 2026 05:18
@Git-on-my-level
Git-on-my-level marked this pull request as ready for review July 21, 2026 05:23
@Git-on-my-level
Git-on-my-level merged commit cdec7b8 into main Jul 21, 2026
45 checks passed
@Git-on-my-level
Git-on-my-level deleted the codex/simplify-release-channels branch July 21, 2026 05:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant