Skip to content

skills(sage-saint): align runbook prose with corrected gotchas - #135

Open
DJRHails wants to merge 1 commit into
mainfrom
sage-saint-runbook-consistency
Open

skills(sage-saint): align runbook prose with corrected gotchas#135
DJRHails wants to merge 1 commit into
mainfrom
sage-saint-runbook-consistency

Conversation

@DJRHails

Copy link
Copy Markdown
Owner

Post-merge review follow-up to #134. That PR corrected the gotchas section, which left two adjacent spots of the same file stale:

  • The upgrade runbook still described a release-pipeline failure as expected/cosmetic; the corrected gotchas record it as fixed (2026-08-24), so treating a new failure as noise would now mask a real regression. Reworded to keep the non-blocking fact but flag a fresh failure as a signal.
  • A stack-map row named only one of the two sandbox-container naming vintages that skills(sage-saint): correct gotchas after repair pass #134 itself documents; the row now lists both.

Details inside the encrypted file. Verified: glassine check, check-crypt-patterns, gitleaks, trufflehog, and all local behaviour suites pass (full pre-commit ran on the commit).

via gantry

Follow-up to #134's post-merge review: a step in the upgrade runbook
still described a release-pipeline failure as expected/cosmetic that
the corrected gotchas record as fixed, and a stack-map row named only
one of the two container-naming vintages the same PR documents.
Details inside the encrypted file.

Verified: glassine check, check-crypt-patterns, gitleaks (staged),
trufflehog (filesystem), and the four local behaviour suites all pass.
@DJRHails

Copy link
Copy Markdown
Owner Author

Review Summary

Direct single-pass review (docs-only delta: 1 encrypted skill file, ~8 plaintext lines changed) — no agent fan-out needed.

Findings

None (P1–P4). Both edits were verified for accuracy, not just consistency:

  • Runbook step 2 rewording — checked against DJRHails/openclaw-patched: verify-attestations has needs: [create-manifest] with if: needs.create-manifest.result == 'success', so a failure there genuinely cannot block the publish; and commit 0c2123e9 ("fork: unblock releases — lowercase attestation refs, non-fatal runtime smoke") landed 2026-08-24, matching the new prose and the corrected gotcha. Flagging a fresh failure as a regression rather than noise is the right posture now that the chronic cause is fixed.
  • Stack-map row — now names both sandbox-container naming vintages, matching the prose at the "Sandbox containers may be named…" paragraph and the refresh_sandbox_proxy_bindings gotcha that depends on the sbx-workspace-* variant existing.

Note: the --stat on this PR reads 11+/11− because it counts ciphertext lines; the smudged plaintext delta is 5+/3−.

Verification

  • Hooks: full prek run on the changed file — gitleaks, TruffleHog, check-crypt-patterns, glassine-check, and all six local behaviour suites pass
  • Encryption: committed blob is ciphertext; glassine rules match tracked files
  • External claims: verified against openclaw-patched workflow definition and commit history (see above)

Commit

No fix commit needed — branch approved as-is at 5cdb2d7.

Verdict: approve

via gantry

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant