Slack: explicit private-workspace setup, readiness doctor and runbook - #1024
Conversation
|
Independent audit is blocked on the supported runner/authentication boundary. PR #1024 remains draft at The trusted audit request succeeded, but https://github.com/codemower-ai/code-mower/actions/runs/35306082524 has no assigned reviewer runner. GitHub reports zero repository-level self-hosted runners; this account cannot inspect organization runners. The supported local fallback command Owner actions:
No live Slack/provider operation, credential change, deployment or cloud upload was performed. Existing validation runs may finish independently; their terminal state will be recorded where available. This unit stops at the owner boundary rather than configuring runners or credentials. |
|
Update: the earlier queued-run observation is superseded. An audit runner did pick up the first request, but the Claude audit step failed and no independent verdict was published. The audit workflow also reports The completed CI run found only the new CLI registry entry and two package extraction inventory omissions. Those are fixed in the same Codex-owned branch. New head: Revised owner actions:
The |
Claude audit unavailableHead SHA: |
Claude audit unavailableHead SHA: |
Codex delivery: #922Implemented and pushed one draft PR: #1024 (closes #922). Head: The reduced OSS scope includes explicit interactive/scripted hosted manifest preparation, separate redacted readiness checks, and the private start/status/answer/cancel plus install/upgrade/disable/rollback/uninstall runbook. Default Claude + Codex setup remains unchanged. Live readiness requires the explicitly configured trusted private host probe; offline snapshots cannot pass. Validation:
Remaining: independent audit and gate. The trusted Claude audit workflow failed without publishing a verdict; metadata commands reported a missing Owner actions:
Outcome: implementation delivered for review; owner action required for audit infrastructure. |
Final exact-head review evidenceExact head: The trusted self-hosted Claude audit completed with PASS and zero P0/P1/P2/P3 findings in source run https://github.com/codemower-ai/code-mower/actions/runs/35308536301. The reviewer seal completed successfully with digest Exact-head CI passed across Python 3.12/3.13/3.14 plus containment, Board qualification, package, privacy and install rehearsals: https://github.com/codemower-ai/code-mower/actions/runs/35306548110. The default-branch publisher still fails before writing a verdict reservation; the bounded diagnostic added in #1030 classifies the replay as |
Closes #922.
Adds explicit
code-mower slack setupfor the hosted single-workspace manifest,slack doctor/doctor --slack, and the v1.5.0 private start/status/answer/cancel runbook. Default Claude + Codex setup remains unchanged, with no Slack dependency, login, prompt or service.Doctor separates enablement, app/OAuth installation, immutable identity/repository/channel policy, registration, qualified supervisor reachability, hosted Devin transport and task/campaign/runtime/review caps. An explicitly selected trusted private host probe supplies fresh scoped observations under a five-second deadline, output bounds and a closed schema. Fixed diagnostics never echo private inputs. Offline snapshots cannot establish live readiness, and diagnostic success is never execution authority. The authenticated host adapter is an explicit operator prerequisite; this OSS PR does not deploy it.
The runbook covers installation, upgrade, stale/revoked/mismatched components, disable, rollback and uninstall. It distinguishes the existing OSS
/code-moweringress seam from hosted/codemoweroperations. Hosted UI changes, telemetry/Board links and paid canaries remain outside the reduced scope. Both wheel installation and standalone package extraction include the new modules, manifest and applicable documentation.Builder and sole source writer: Code Mower Codex (
builder:codex). Independent Claude review is requested withneeds-claude-audit; Claude supplied no source changes.Validation:
Independent audit remains blocked: the trusted workflow's Claude step failed without a published verdict and metadata commands reported a missing
code_mowermodule. Latest requested workflow: https://github.com/codemower-ai/code-mower/actions/runs/35306650945 . The local wrapper also lacks its required token input; no credentials or permission changes were attempted. Exact numbered owner actions are on this PR and #922. Keep the PR draft withneeds-owneruntil a qualified exact-head audit and authoritativecode-mower/gatepass.No live Slack/hosted Devin operation, deployment, credential change or Code Mower cloud upload was performed. Probe fixtures are synthetic; no raw local audit/test logs were uploaded. Cloud upload evidence is not claimed for this reduced scope.