Skip to content

Slack: explicit private-workspace setup, readiness doctor and runbook - #1024

Merged
jeffhuber merged 2 commits into
mainfrom
codex/922-slack-operator-setup
Sep 18, 2026
Merged

jeffhuber merged 2 commits into
mainfrom
codex/922-slack-operator-setup

Conversation

@jeffhuber

@jeffhuber jeffhuber commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Closes #922.

Adds explicit code-mower slack setup for the hosted single-workspace manifest, slack doctor / doctor --slack, and the v1.5.0 private start/status/answer/cancel runbook. Default Claude + Codex setup remains unchanged, with no Slack dependency, login, prompt or service.

Doctor separates enablement, app/OAuth installation, immutable identity/repository/channel policy, registration, qualified supervisor reachability, hosted Devin transport and task/campaign/runtime/review caps. An explicitly selected trusted private host probe supplies fresh scoped observations under a five-second deadline, output bounds and a closed schema. Fixed diagnostics never echo private inputs. Offline snapshots cannot establish live readiness, and diagnostic success is never execution authority. The authenticated host adapter is an explicit operator prerequisite; this OSS PR does not deploy it.

The runbook covers installation, upgrade, stale/revoked/mismatched components, disable, rollback and uninstall. It distinguishes the existing OSS /code-mower ingress seam from hosted /codemower operations. Hosted UI changes, telemetry/Board links and paid canaries remain outside the reduced scope. Both wheel installation and standalone package extraction include the new modules, manifest and applicable documentation.

Builder and sole source writer: Code Mower Codex (builder:codex). Independent Claude review is requested with needs-claude-audit; Claude supplied no source changes.

Validation:

  • 45 focused Slack tests and 221 doctor regression tests passed.
  • Six package extraction, registry and inventory regressions passed after correcting the first CI run's integration omissions.
  • Repository Ruff, privacy scan, workflow-template guard, compile checks and all 22 release-readiness checks passed.
  • Final-head wheel/sdist build and Twine passed. Installed-wheel easy-mode smoke and extracted-package Slack setup/doctor/resource verification passed.
  • Current-head full CI passed: https://github.com/codemower-ai/code-mower/actions/runs/35306548110 . Python 3.12/3.13/3.14, Linux/macOS containment, Board qualification and installation rehearsals all passed; the Python 3.14 suite ran 4,795 tests with 12 skips.
  • The attempted local full suite was not green: its initial missing dependencies and sandbox private-store restrictions prevented a valid full run. The CI matrix is the full-suite validation authority for this head.

Independent audit remains blocked: the trusted workflow's Claude step failed without a published verdict and metadata commands reported a missing code_mower module. Latest requested workflow: https://github.com/codemower-ai/code-mower/actions/runs/35306650945 . The local wrapper also lacks its required token input; no credentials or permission changes were attempted. Exact numbered owner actions are on this PR and #922. Keep the PR draft with needs-owner until a qualified exact-head audit and authoritative code-mower/gate pass.

No live Slack/hosted Devin operation, deployment, credential change or Code Mower cloud upload was performed. Probe fixtures are synthetic; no raw local audit/test logs were uploaded. Cloud upload evidence is not claimed for this reduced scope.

@jeffhuber

Copy link
Copy Markdown
Contributor Author

Independent audit is blocked on the supported runner/authentication boundary. PR #1024 remains draft at 1dd92ace0c64ebb9c12aa2513a188c5aaa75fc67, with Code Mower Codex as sole source writer and needs-claude-audit retained.

The trusted audit request succeeded, but https://github.com/codemower-ai/code-mower/actions/runs/35306082524 has no assigned reviewer runner. GitHub reports zero repository-level self-hosted runners; this account cannot inspect organization runners. The supported local fallback command tools/run_claude_audit_pr.sh --repo codemower-ai/code-mower --pr 1024 --repo-paths OWNER/REPO:SEPARATE_CHECKOUT --dry-run --publication workflow --timeout 900 --max-budget-usd 2 --no-spend-capture stopped before any provider invocation because its required GITHUB_TOKEN input is unavailable. No authentication material was searched for or read, and no permission/scope change was attempted.

Owner actions:

  1. Restore an authorized self-hosted audit runner available to this repository with labels self-hosted, macOS, and code-mower-audit, using the existing reviewer authentication and short-lived workflow-token setup in docs/local-audit-runner.md.
  2. Let the queued trusted workflow audit the exact PR head above, or re-request needs-claude-audit if that queue expires. Do not substitute an unsealed local verdict for the workflow publication.
  3. Return any P0/P1/P2 findings to the Codex branch owner for a same-branch fix round and fresh exact-head review. Keep the PR draft until independent review, normal CI and authoritative code-mower/gate pass.

No live Slack/provider operation, credential change, deployment or cloud upload was performed. Existing validation runs may finish independently; their terminal state will be recorded where available. This unit stops at the owner boundary rather than configuring runners or credentials.

@jeffhuber

Copy link
Copy Markdown
Contributor Author

Update: the earlier queued-run observation is superseded. An audit runner did pick up the first request, but the Claude audit step failed and no independent verdict was published. The audit workflow also reports ModuleNotFoundError: No module named 'code_mower' in its metadata commands. See https://github.com/codemower-ai/code-mower/actions/runs/35306082524 . Raw audit output remains private; no provider verdict is inferred from the job exit.

The completed CI run found only the new CLI registry entry and two package extraction inventory omissions. Those are fixed in the same Codex-owned branch. New head: 942f1b37d7e1d3f1b404af792e7c41e3ace361f2. Six targeted registry/extraction/inventory regressions, Ruff, privacy and release-readiness checks now pass. New full CI: https://github.com/codemower-ai/code-mower/actions/runs/35306548110 . needs-claude-audit was re-requested for the new head.

Revised owner actions:

  1. Repair the trusted audit runner/workflow's Python package/import setup and inspect its private wrapper failure locally. Keep raw provider output and authentication material out of issue comments; no authentication material was sought by this builder.
  2. Complete the trusted Claude audit/publication for PR Slack: explicit private-workspace setup, readiness doctor and runbook #1024 at the new head above. The local fallback cannot publish a sealed workflow verdict and its required token input is unavailable here.
  3. Return any P0/P1/P2 findings to Codex for same-branch fixes and fresh review. Keep the PR draft until independent review, normal CI and authoritative code-mower/gate pass.

The needs-owner boundary remains limited to independent audit infrastructure/authentication. No runner, credential or permission configuration is changed by this unit.

@github-actions

Copy link
Copy Markdown

Claude audit unavailable

Head SHA: 942f1b37d7e1d3f1b404af792e7c41e3ace361f2
Verdict: UNKNOWN
No merge-authority verdict was published. The local artifact was quarantined, stale, or inconclusive. Check the local runner and requeue this audit.

@github-actions

Copy link
Copy Markdown

Claude audit unavailable

Head SHA: 942f1b37d7e1d3f1b404af792e7c41e3ace361f2
Verdict: UNKNOWN
No merge-authority verdict was published. The local artifact was quarantined, stale, or inconclusive. Check the local runner and requeue this audit.

@jeffhuber

Copy link
Copy Markdown
Contributor Author

Codex delivery: #922

Implemented and pushed one draft PR: #1024 (closes #922).

Head: 942f1b37d7e1d3f1b404af792e7c41e3ace361f2. Named builder and sole source writer: Code Mower Codex, branch codex/922-slack-operator-setup.

The reduced OSS scope includes explicit interactive/scripted hosted manifest preparation, separate redacted readiness checks, and the private start/status/answer/cancel plus install/upgrade/disable/rollback/uninstall runbook. Default Claude + Codex setup remains unchanged. Live readiness requires the explicitly configured trusted private host probe; offline snapshots cannot pass.

Validation:

  • Exact-head CI passed: Python 3.12/3.13/3.14, Linux/macOS containment, Board qualification, package validation and installation rehearsals. Python 3.14 ran 4,795 tests with 12 skips.
  • Locally, 45 focused Slack tests, 221 doctor regressions, and six extraction/registry/inventory regressions passed. Ruff, privacy, workflow guard, compile, all 22 release-readiness checks, final wheel/sdist build, Twine, installed-wheel smoke and extracted-package Slack/resource verification passed.
  • The attempted local full suite was not green because initial dependency gaps and sandbox private-store restrictions invalidated that run. CI provides the clean full-suite result. The first CI run's registry/inventory omissions were corrected on this same branch.

Remaining: independent audit and gate. The trusted Claude audit workflow failed without publishing a verdict; metadata commands reported a missing code_mower module. The local wrapper also lacks its required token input. needs-claude-audit was re-requested after pushing; needs-owner remains on the PR and issue, and code-mower/gate is pending.

Owner actions:

  1. Repair the trusted audit runner/workflow Python/import setup and inspect its private wrapper failure locally.
  2. Complete qualified Claude review and verified publication against the exact head above.
  3. Return any P0/P1/P2 findings to Codex for same-branch fixes and fresh review; keep the PR draft until review and the authoritative gate pass.

Outcome: implementation delivered for review; owner action required for audit infrastructure. .code-mower/lane-outcome.json records owner_action. No merge, release, deployment, credential change, live Slack/hosted Devin canary or Code Mower cloud upload was performed. Upload evidence is not claimed for the reduced scope; only safe public PR/head, validation and workflow-status metadata is recorded here. Live acceptance remains #923 work.

@jeffhuber

Copy link
Copy Markdown
Contributor Author

Final exact-head review evidence

Exact head: 942f1b37d7e1d3f1b404af792e7c41e3ace361f2

The trusted self-hosted Claude audit completed with PASS and zero P0/P1/P2/P3 findings in source run https://github.com/codemower-ai/code-mower/actions/runs/35308536301. The reviewer seal completed successfully with digest 5b7327b698fd9fb3ee707695537436a67aa5cd12fc497baa8ebe9b0947847a87.

Exact-head CI passed across Python 3.12/3.13/3.14 plus containment, Board qualification, package, privacy and install rehearsals: https://github.com/codemower-ai/code-mower/actions/runs/35306548110.

The default-branch publisher still fails before writing a verdict reservation; the bounded diagnostic added in #1030 classifies the replay as INTERNAL_ERROR, so this is an API/runtime exception rather than a failed publication trust check. This product PR therefore uses the documented owner gate override with the immutable source-run/seal evidence above. The deeper publisher exception diagnosis is no longer a v1.5.0 product blocker.

@jeffhuber jeffhuber added gate:override Code Mower generated label and removed needs-owner Needs owner decision or approval labels Sep 18, 2026
@jeffhuber
jeffhuber marked this pull request as ready for review September 18, 2026 05:17
@jeffhuber
jeffhuber merged commit 4c2cd62 into main Sep 18, 2026
42 checks passed
@jeffhuber
jeffhuber deleted the codex/922-slack-operator-setup branch September 18, 2026 05:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

builder:codex Code Mower generated label gate:override Code Mower generated label needs-claude-audit

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Slack: minimal opt-in setup, doctor, and runbook for v1.5.0

1 participant