Harden release sync ancestry checks and conflict recovery - #1687
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
🔵 Needs a closer look
It changes production release-branch merge and push automation, so final human validation is warranted.
Pull request overview
Hardens release-branch synchronization by extracting merge policy into a pinned Bash helper and adding ancestry regression tests.
Changes:
- Adds conflict classification, recovery summaries, failure propagation, and merge-parent validation.
- Adds disposable Git fixtures to the required CI gate.
- Runs the helper from the pinned
maincommit before pushing.
File summaries
| File | Description |
|---|---|
.github/workflows/update-release-branch.yml |
Uses the pinned merge helper and pushes validated merges. |
.github/workflows/ci.yml |
Adds release-sync tests to the CI gate. |
.github/scripts/merge-main-into-release.sh |
Implements merge policy and ancestry safeguards. |
.github/scripts/test-merge-main-into-release.sh |
Covers merge, conflict, recovery, and ancestry scenarios. |
Review details
- Files reviewed: 4/4 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Frontend HTML artifact readyThe latest frontend build uploaded the This comment updates automatically when a new frontend build artifact is uploaded. |
Keep the generated Floci entry and reject duplicate package IDs in structured-data validation. The stale manually appended row prevented the release catalog from consuming main's mirrored data. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
James Newton-King (JamesNK)
left a comment
There was a problem hiding this comment.
Reviewed the release-sync helper, workflow invocation, Git failure handling, ancestry safeguards, generated-data correction, and regression fixtures. No actionable issues found.
Reconcile navigation, Mermaid rendering, deployment guards, and Live status diagnostics while retaining Dev Hub, release docs, and official blog updates. Combine Vite redirect definitions with the StaticHost proxy and cover both proxy states. Preserve pinned dependencies and exactly mirror the seven approved generated paths. Validation: 208 Live tests and 273 frontend tests pass; pinned pnpm frozen-lockfile install and 366 E2E test discovery pass. PENDING DATA VALIDATION: pinned main contains duplicate Floci integration rows rejected by the release catalog. Keep strict validation; do not publish or land until corrected canonical main is merged and catalog tests pass. Safeguards PR microsoft#1687 must land first. MUST MERGE; DO NOT SQUASH OR REBASE. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Merge main 1885cc4 after safeguards PR microsoft#1687 landed. Include canonical Floci uniqueness correction and security fixes; preserve intervening release/13.6 commit 732f999 and the original de85064 merge without rewriting history. Validation: 355 focused frontend tests, 36 structured-data tests, 235 Live tests, 7 release-sync fixture scenarios, and 25 OG preview tests pass. Strict catalog validation and seven-path generated parity pass. Previously frozen-validated package manifest and lockfile are unchanged. No local site build. MERGE COMMIT REQUIRED; DO NOT SQUASH OR REBASE. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Summary
The release sync failed run reports 22 code/config/test conflicts outside the existing auto-resolution policy. Previous release repair PRs #1668 and #1680 landed as single-parent commits, copying main content without preserving main ancestry; the common ancestor remains September 2.
This is the main-based safeguards and prerequisite data-correction PR, not the one-time release repair. The separate repair must target
release/13.6and land with Create a merge commit, never squash/rebase. This safeguards PR may use the normal main-branch squash policy.Third-party links and affiliations
None. The deleted duplicate URL remains on the retained Floci entry.
Validation
actionlint -shellcheck= .github/workflows/update-release-branch.yml .github/workflows/ci.ymlpassed.communitytoolkit.aspire.hosting.flocibefore data correction.pnpm --dir ./src/frontend test:unit:structured-data: 2 files / 35 tests passed after correction.git diff --checkpassed.