Skip to content

chore(harness): pin fleet images to the v0.44.0-rc.2 release builds - #1570

Merged
waynesun09 merged 1 commit into
mainfrom
repin-images-0.44.0
Oct 2, 2026
Merged

waynesun09 merged 1 commit into
mainfrom
repin-images-0.44.0

Conversation

@waynesun09

Copy link
Copy Markdown
Member

Summary

Pins the 7 fleet harness images to the release builds published by fullsend v0.44.0-rc.2, so that the v0.44.0 agents tag (cut from agents main by fullsend's release workflow) ships with current sandbox images. The harnesses still pinned the v0.42.0 images, because v0.43.0 was never repinned (fullsend#6607 tracks automating this).

Image Harnesses From (0.42.0) To (0.44.0-rc.2)
fullsend-sandbox prioritize, retro, scribe, triage sha256:259605fe…995a sha256:61787695…1276
fullsend-code code, fix, review sha256:623fc745…d0b sha256:d681249e…8103

Both digests were verified against the registry's 0.44.0-rc.2 tags. They come from the release run that passed validate-agents (all 5 functional-test suites) for v0.44.0-rc.2. examples/link-check keeps the digest fullsend agent new emits.

What changes for the fleet with the newer images (pi 0.85 → 0.99.2, Claude Code 2.1.263 → 2.1.286, Codex 0.157 → 0.159.3):

  • pi ≥ 0.86 sends strict tool definitions. With the current Vertex org policy, sonnet-5 / sonnet-4-6 / opus-4-8 / opus-4-6 accept them. For models the policy still excludes, the bundled pi-anthropic-vertex falls back to non-strict after one refused request.

Test plan

  • pre-commit and make lint pass
  • make test passes except post-code-test.sh, a known macOS BSD-sed limitation (CI runs Linux)
  • CI (script-test, test, commit-lint, skillsaw, functional and behaviour tests) on this PR
  • After merge: tag fullsend v0.44.0; agents gets tagged at a main that includes this

The fleet harnesses still pinned the v0.42.0 images (v0.43.0 was never
repinned). Pin them to the images published by fullsend v0.44.0-rc.2,
which passed the release gate (validate-agents), so the v0.44.0 agents
tag ships with current sandbox images:

- fullsend-sandbox (prioritize, retro, scribe, triage):
  sha256:61787695ada71876324447979ac26a16bc64dc7139b819151cda817937be1276
- fullsend-code (code, fix, review):
  sha256:d681249e95e6a26e31cf4f5192ee7ed7c9ed050d03bb4d80b40a3bf252238103

examples/link-check keeps the digest `agent new` emits.

Assisted-by: Claude
Signed-off-by: Wayne Sun <gsun@redhat.com>
@waynesun09
waynesun09 requested a review from a team as a code owner October 2, 2026 00:01
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Pin fleet harness images to v0.44.0-rc.2 release builds

⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Repins all seven fleet harnesses from v0.42.0 images to verified v0.44.0-rc.2 release builds.
• Keeps code and workflow harnesses on their respective immutable image digests.
Diagram

graph TD
  Release["v0.44.0-rc.2"] --> CodeImage["fullsend-code digest"] --> CodeHarness["Code, fix, review"] --> Runtime["Agent sandbox"]
  Release --> FleetImage["fullsend-sandbox digest"] --> FleetHarness["Prioritize, retro, scribe, triage"] --> Runtime
Loading
High-Level Assessment

Pinning the verified release builds by digest preserves reproducibility while bringing the fleet up to date. Automating future repins is worthwhile but separate from this release-specific change.

Files changed (7) +7 / -7

Other (7) +7 / -7
code.yamlRepin code harness image +1/-1

Repin code harness image

• Changes the code harness to the v0.44.0-rc.2 fullsend-code digest.

harness/code.yaml

fix.yamlRepin fix harness image +1/-1

Repin fix harness image

• Changes the fix harness to the v0.44.0-rc.2 fullsend-code digest.

harness/fix.yaml

prioritize.yamlRepin prioritize harness image +1/-1

Repin prioritize harness image

• Changes the prioritize harness to the v0.44.0-rc.2 fullsend-sandbox digest.

harness/prioritize.yaml

retro.yamlRepin retro harness image +1/-1

Repin retro harness image

• Changes the retro harness to the v0.44.0-rc.2 fullsend-sandbox digest.

harness/retro.yaml

review.yamlRepin review harness image +1/-1

Repin review harness image

• Changes the review harness to the v0.44.0-rc.2 fullsend-code digest.

harness/review.yaml

scribe.yamlRepin scribe harness image +1/-1

Repin scribe harness image

• Changes the scribe harness to the v0.44.0-rc.2 fullsend-sandbox digest.

harness/scribe.yaml

triage.yamlRepin triage harness image +1/-1

Repin triage harness image

• Changes the triage harness to the v0.44.0-rc.2 fullsend-sandbox digest.

harness/triage.yaml

@qodo-code-review

qodo-code-review Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (1)

Grey Divider


Action required

1. Fleet image changes require human approval 📜 Skill insight § Compliance
Description
The PR modifies seven files under the protected harness/ infrastructure path by replacing pinned
container digests. The release-image repin rationale is documented in the PR description, but this
protected-path change still requires explicit human review rather than automated approval.
Code

harness/code.yaml[21]

+image: ghcr.io/fullsend-ai/fullsend-code@sha256:d681249e95e6a26e31cf4f5192ee7ed7c9ed050d03bb4d80b40a3bf252238103
Relevance

●●● Strong

Protected harness changes trigger explicit human-review requirements; release rationale does not
waive governance controls.

PR-#631
PR-#1502

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The checklist requires a finding whenever protected governance or infrastructure paths are modified,
including harness/, and states that such PRs must never be auto-approved. The changed harness file
and the six sibling harness files are all under that protected path; the PR description supplies a
release-repin justification but does not remove the human-review requirement.

harness/code.yaml[21-21]
harness/fix.yaml[21-21]
Skill: pr-review

Dismiss ↗ | View ↗


Grey Divider

Context sources
✅ Compliance rules (platform): 58 rules
✅ Skills: 4 invoked
  code-review
  code-implementation
  pr-review
  docs-review
✅ Cross-repo context — repo relationships
  Explored: repo: fullsend-ai/scribe (sha: 0f3eb528) — View relationship
  Explored: repo: fullsend-ai/.fullsend (sha: 7c163cad) — View relationship
  Explored: repo: fullsend-ai/pi-anthropic-vertex (sha: 960eff35) — View relationship
  Explored: repo: fullsend-ai/pi-xai-vertex (sha: 8f50bdda) — View relationship
  Explored: repo: fullsend-ai/fullsend (sha: 19329e3b) — View relationship
Review mode: 🚀 Fast: The PR only replaces pinned container image digests across seven harness YAML files, with no code or structural logic changes; review can be confidently limited to verifying the intended images and consistency.

Grey Divider

Tip of the day
💡 Did you know, you can show, collapse, or hide each part of a finding: code, evidence, and all

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread harness/code.yaml
# when the model: above moves to a generation with a different default.
effort: high
image: ghcr.io/fullsend-ai/fullsend-code@sha256:623fc74588876062f12f40690ee759c6134ba516fabdd36e6dcfc4eeb9cd1d0b
image: ghcr.io/fullsend-ai/fullsend-code@sha256:d681249e95e6a26e31cf4f5192ee7ed7c9ed050d03bb4d80b40a3bf252238103

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

1. Fleet image changes require human approval 📜 Skill insight § Compliance

The PR modifies seven files under the protected harness/ infrastructure path by replacing pinned
container digests. The release-image repin rationale is documented in the PR description, but this
protected-path change still requires explicit human review rather than automated approval.

Dismiss ↗ | View ↗

@fullsend-ai-review

fullsend-ai-review Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 12:03 AM UTC · Completed 12:12 AM UTC

Commit: 464978a · View workflow run →

Runtime: pi · Model: openai/gpt-6.1-sol → gpt-6.1-sol · Effort: high · Cost: $1.47

@waynesun09
waynesun09 merged commit 719866f into main Oct 2, 2026
35 of 36 checks passed
@waynesun09
waynesun09 deleted the repin-images-0.44.0 branch October 2, 2026 00:10
@fullsend-ai-review

Copy link
Copy Markdown

Review skipped — this PR is already merged.

The /fs-review command only reviews open PRs/MRs.

Posted by fullsend post-review check

yvonnedevlinrh pushed a commit to yvonnedevlinrh/fullsend that referenced this pull request Oct 2, 2026
…flow

skills/cutting-releases documented a single tag push per release,
but tag-agents tags agents main in that same run before anyone can
repin fullsend-ai/agents/harness/*.yaml to the images that release
just built. Released CLIs fetch agents@tags/vX.Y.Z, so every release
shipped the previous release's fleet images (the one-release lag
from fullsend-ai#6607). v0.44.0 was cut with an RC -> repin -> final flow that
removed the lag end to end; this change makes that the documented
default.

SKILL.md: every release now starts as vX.Y.Z-rc.N at a commit X.
After the RC gate is green, agents is repinned (new step 8, using
fullsend-ai/agents#1570 as the template), and only then is vX.Y.Z
tagged at X (or a later commit Y, gated on a git log check over
images/sandbox, images/code, and sandbox-images.yml -- a non-empty
result means cut rc.N+1 instead of reusing the RC). Added a hold
window note against merging image-affecting PRs between the RC and
the repin merge. Notes section documents two behaviors this flow
depends on: tag-agents runs for prereleases too (unlike the v0
move), and sandbox-images.yml builds on every v* tag regardless of
whether the publish gate passes, and is not reproducible.

pre-flight.md: new step A3 compares the functional-tests.yml@sha
pin in release.yml against agents main's copy of that file, since
PR CI never exercises the pinned workflow and a stale pin only
surfaces as a tag-time gate failure (as it did for v0.44.0-rc.1).

post-flight.md: extended B2 to verify the agents tag lands on the
repin PR's merge commit and that v0 moved on both repos, and added
B3 to verify the harness pins equal the RC's digests rather than
the final tag's own (different, since the build isn't reproducible)
digests.

The release.yml GoReleaser fix for same-commit RC/final tagging
(GORELEASER_CURRENT_TAG) is out of scope here per the issue -- it is
a workflow file change tracked separately. Automating the repin PR
is also out of scope; this documents the manual flow.

Note: pre-commit could not fetch its hook repos in this sandbox
(TLS/network restriction). Ran the hooks relevant to the changed
markdown files directly instead: no trailing whitespace, no CRLF,
no merge-conflict markers, single trailing newline (matches
end-of-file-fixer/trailing-whitespace/mixed-line-ending/
check-merge-conflict). make lint-md-links (lychee --offline)
passed repo-wide.

Closes fullsend-ai#6607
Closes fullsend-ai#7954

This branch was successfully deployed

1 active deployment
dev — 464978aa Deployed Oct 2, 2026 by waynesun09 via behaviour #309
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant