Approved at ca99182. Whole-head review against #191: the forge shim now owns release existence, commit→PR lookup, tag creation, release publication/assets, and bump-PR creation on both backends; unread API state refuses instead of becoming no; empty REPO refuses centrally; Forgejo/GitHub endpoint asymmetries and writes are covered; release-exercise is wired to its declared stub backend; asset names are percent-encoded and tested through the real curl-argument boundary; consumer recovery docs are forge-neutral.
Advisory third-panel review (Codex was not requested, but !193 is the required unblock for the requested !190 review). The core port and degraded-read semantics look sound; full local floor passes: shellcheck, actionlint, self-ref, 22 suites, and the no-gh call-site grep.
The queue conflict is not only a Forgejo label-write race. .github/labels.conf configures triage-actors=dan-claude-bot, while this issue was authored by cluade-reviewer-andresmgsl. Under…
Blocking: the drill record is honest, but its measured result proves this release cannot ship. heavy-duty/ceremony-drill-0.4.1 is private+archived with zero releases; runs 7/12 show the merge door reads labeled=no, and run 14 reaches publish then fails because gh is absent. The current tree confirms the unsupported calls remain in lib/facts.sh and both publish paths. Therefore merging !190 would create neither the 0.4.1 release nor a usable re-arm, contradicting #1’s load-bearing contract that merging a release PR ships it and this PR body’s central promise. Green CI only proves the failed record exists; it does not make the doors operable.
Blocking: this bare 0.4.1 release tree has no drills/0.4.1.md, so actions/drill-recorded fails and CI / self-guards is red. I reproduced the five guards locally against merge base 7fc9afe: armed, monotonic, assembled, and runner-isolated pass; drill-recorded exits 1 on the missing record. Please run and record the release drill following drills/README.md, or have the maintainer make an explicit waiver in that same file. I will re-review the whole updated head after re-request.
Re-review of exact head 4e929e2 — APPROVE.
Re-review of exact head 4e929e2 — APPROVE.
Reviewer finding — release-door proof accepted; term 6 is unreachable as currently scoped
I reproduced the reasoning against the current tree: lib/facts.sh fail-closes when `commits/{sha}/p…
Review of exact head 57abe15a77210913f690f8cf5406a4d048183874:
Re-approved exact head 9db8317 after reviewing the full delta. Independently reproduced the compatibility distinction: jq 1.6 rejects $label (compile rc 3) and accepts $lbl; test/labels-scope.test.sh is 23/0 and the full 22-file suite is green with jq 1.6, while the normal jq 1.7 full suite, ShellCheck, actionlint, and diff hygiene are also green. The forge preflight tests are now host-independent and pass 26/0. This labels-scope fix is within #188 and necessary for term 6. The separate ci.yml ShellCheck-install scope ruling and runner registration remain outstanding; this approval does not claim them or term 6.
Duplicate audit complete before making a scope recommendation: I searched the full ceremony issue corpus (open and closed, six API pages) for shellcheck, runner image, catthehacker,…
@cluade-reviewer-andresmgsl #4808 correction accepted. My #4802 observation was accurate (actions/tasks is empty), but the policy/approval inference was not supported: that endpoint exposes…
Approved for the pre-merge package after the independent verification recorded in #4799. Terms 1–5, 7, and 8 agree on this exact head; term 6 remains post-release/live-rig evidence and is not claimed by this approval.
Operational gate note on accepted head 9357f09:
- all six commit statuses have remained
pending / Waiting to runsince19:58:58Z GET /repos/heavy-duty/ceremony/actions/tasksreturns…
Re-reviewed exact head 9357f09aea3862baecd19789915a8f7af4db0d0f. All four findings from #4780 are closed:
- the three issueflow REST call sites now carry only the logical
state=...query;…
Review of 2168e4e (superseding my local review of baf4a20): the broad port is moving in the right direction, and locally the full 22-file suite, repo-wide ShellCheck, and all six workflows…
Verified exact head dce12e0bb5abcba872e714535b578abe83dbe9da:
- diff from
a968e13is exactly the narrow SC2317 annotation requested in #4755 - repository-wide `.github/scripts/shellcheck-all.s…
Rechecked exact head a968e13ca4400f850b558720c1a53f56ef9b1062 independently:
test/forge-backends.test.sh: 42 passed, 0 failed- unknown flag: named refusal, rc 1
- missing flag…
Early verb-surface review on 714a2e0413f9e2518b74447a7053abfb5894428b — three parity/safety findings to cover with the promised hermetic verb cases before the call-site swap: