rig/CHANGELOG.md
dan-claude-bot 77a9a1ad76 feat: CI refuses a release PR with no drill record
CONTRIBUTING has always required a real-hardware drill on a release, and
nothing enforced it — so no release in this family has ever carried one.
Every other ceremony step is checked by a script; the one that costs an
afternoon was checked by a reviewer remembering. A reviewer bot finally
blocked on it.

- drill/RUNS.md: rig's own run log, starting EMPTY of records. rig has no
  drill harness of its own yet; the harness lives in box's drill/ and this
  file is the record, not the instrument.
- .github/scripts/drill-recorded.sh: a -dev tree asserts nothing; a bare
  VERSION requires a non-empty '## Release drill — X.Y.Z' section, version
  matched WHOLE so an -rc1 record is not evidence for the final.
- Per-repo on purpose. A cross-repo lookup into box fails on a token, a fork
  checkout or a network blip, and all of those degrade to 'pass' on precisely
  the tree that ships — the UNREADABLE-vs-NONE shape #90 fixed.
- It asks for a RECORD, not a RESULT, so a maintainer waiver stays possible
  but has to be written down under that version.
- Fixtures carry their own VERSION and RUNS.md (heavy-duty/box#146: fixtures
  reading the repo's real VERSION exercised only the -dev branch and went red
  first while cutting a release).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 15:24:42 +00:00

2.6 KiB

Changelog

History before 0.1.0 lives in git — rig grew its version surface (VERSION, rig --version, the side-by-side versions/<v> install layout; #35/#36) on the way to cutting its first release, and this file starts there.

Unreleased

Fixed

  • Deleting a shipped release heading from CHANGELOG.md is caught on every PR (#98, heavy-duty/box#122)
  • The heading-uniqueness check no longer sits behind git conditions it does not need (#98, heavy-duty/box#143)
  • An unreadable check rollup no longer reads as "nothing is failing" (#90)
  • CI runs test/labels-reconcile.sh, which it had never run (#90)
  • state:needs-human no longer appears on PRs a human cannot merge (#87, heavy-duty/box#136)
  • A missing /run/sshd no longer reads as a broken sshd config (#92)
  • CI's shellcheck sweep reaches .github/scripts/ (#70)
  • Ctrl-D at the rig uninstall confirm aborts out loud (#68)
  • users apply tells "revoke everyone" apart from a truncated users file (#65)

Added

  • CI refuses a release PR with no drill record in drill/RUNS.md
  • rig platform — what this machine is, computed at run time, stored nowhere (#64)
  • /etc/rig/manifest records which rig converged a machine, and when (#61)

Changed

  • state:needs-human is set at handoff, not by the cron (#96)
  • PR labels split into two axes: state:* (whose ball) and blocker:* (what is in the way) (heavy-duty/box#137)
  • BREAKING: --class human|server is now --root-door closed|open; old markers still resolve (#77)
  • BREAKING: the box tenant roles carry a -box suffix (#76)
  • BREAKING: machine roles carry a -server suffix, and staging-server is back (#76)
  • Changelog entries are one line each, and the whole file now follows the rule (#100)

0.2.0 — 2026-07-19

Added

  • users apply grants the box tier, not just its socket (#49)

Changed

  • BREAKING: rig bootstrap takes the users file, and requires it (#51)

Fixed

  • A release no longer disarms the changelog under the PRs still in flight (#67)
  • A host=no box with an incus group no longer hands out the bare socket (#58)
  • Dropping the box role revokes through box, not behind its back (#50)
  • rig bootstrap refuses a users file that names no users (#57)

0.1.0 — 2026-07-19

Fixed

  • The release suite accepts the ceremony's own tree (#44)
  • The installer survives an environment with no $HOME (#39, #41)
  • Headless credential prompts refuse loudly instead of dying silently (#42)

Added

  • Merging a release-labeled PR IS the release, and the release re-arms main (#47)
  • Tagged releases, and an installer that installs them (#32)