Deployment revision verification evidence¶
Task: 94c436a2-c2e4-4d05-85de-f0d6070a2256, frozen version 26, read
through HeyAira MCP before continuing on 2026-10-03.
Repository: h8v6/heyaira, branch heyaira/94c436a2.
Frozen base: 4f487bbdf9006cf0a37390205f1721d7c6bbeb71.
Resumed candidate: d08cc2dbef755be206ca5c0713698efdc2df235f.
Only this evidence file changed during the v26 continuation. Implementation and regression tests remain unchanged from the resumed candidate. The candidate is amended to retain one commit above the frozen base; the resulting SHA is recorded in the HeyAira RESULT and receipt.
Implementation¶
The deployment script previously checked only server even when deploying workers.
It now reads HEYAIRA_SERVICE_REVISION with printenv in each selected service.
For all-services deployment it verifies every service of the active Compose
profiles (config --services, resolved before build), excluding OpenBao; see
"Review fix R1" below. Workers receive up to 30 running-state polls;
HTTP health is checked only for server. Failed readiness, revision reads and
revision comparisons name the affected service and attempt rollback before
publishing the current link. PostgreSQL now receives the revision in Compose so
it can participate in all-services verification without requiring Python.
Files changed from the frozen base: ops/deploy-heyaira.sh, compose.yaml,
tests/test_deployment_guard.py, and this evidence file.
Reproduce the frozen v26 check¶
Existing environment: macOS, Python 3.12.7, pytest 9.1.1. No packages were installed. Run the following complete command block from the candidate checkout. It does not require any uncommitted helper, Docker stub or Swift compiler wrapper:
task_check_tmp="$PWD/.pytest_cache/v26/tmp"
mkdir -p "$task_check_tmp"
env -u GIT_OBJECT_DIRECTORY -u GIT_ALTERNATE_OBJECT_DIRECTORIES \
PATH="/Library/Developer/CommandLineTools/usr/bin:/Users/jablonskib/.local/share/mise/installs/python/3.12.7/bin:$PATH" \
TMPDIR="$task_check_tmp" NO_PROXY='*' no_proxy='*' PYTHONPATH=src \
python -m pytest -q -p no:cacheprovider \
--ignore=tests/test_server_beat_audit.py \
--ignore=tests/test_server_beat_corrections.py \
--deselect tests/test_deployment_guard.py::test_required_override_passes_preflight \
--deselect tests/test_deployment_guard.py::test_missing_extra_compose_file_is_rejected \
--deselect tests/test_ios_companion_contract.py::test_inbox_logic_check_passes_with_the_swift_toolchain
The pytest arguments are exactly those prescribed in task v26. All exclusions are explicitly authorized there; none were added by the worker. PATH selects real Git instead of the macOS launcher. Unsetting inherited Git object overrides keeps synthetic fixture commits inside their own temporary repositories. TMPDIR directs Python temporary files into the authorized checkout. NO_PROXY and no_proxy prevent the inherited sandbox SOCKS proxy from triggering the optional socksio requirement when the APNs test constructs a local HTTP/2 client. These are test-process environment settings, not repository or system changes.
Actual results¶
The complete command above was executed in this workspace, with output captured
in the ignored local file .pytest_cache/v26/suite.log. It exited 0:
297 passed, 107 skipped, 3 deselected in 20.90s
The 107 skips require isolated PostgreSQL configuration. No database-backed acceptance tests, complete zero-skip CI or actual Docker deployments ran here.
The run includes all eight new deployment regressions and eight original guard tests. The two original preflight tests excluded by v26 remain unchanged. Their required-override dry-run and missing-extra-file behavior is covered by unchanged production preflight code: comparing the frozen original script before its HEALTH_URL block with the current script before its fail_release block confirms that everything through preflight, build and start is byte-for-byte identical.
Additional checks executed successfully:
Deployment code through preflight, build and start is unchanged
10 original guard test bodies unchanged
sh -n ops/deploy-heyaira.sh: exit 0
git diff 4f487bbdf9006cf0a37390205f1721d7c6bbeb71 HEAD --check: exit 0
The ten original test bodies were compared using Python ASTs. The comparison includes test_required_override_passes_preflight and test_missing_extra_compose_file_is_rejected.
Regression sensitivity was verified in the preceding v11 continuation with actual pytest and an executable copy of the frozen original deployment script: 8 failed, 10 deselected in 9.06s, expected exit 1. Those exact regression tests and the fixed script have not changed since. That continuation also ran all 18 deployment tests successfully. Its full-suite environment needed uncommitted Docker/mktemp helpers and explicit Swift SDK settings, which were not available in the verifier's checkout. This evidence replaces that setup with the self-contained v26 command above. The verifier's four environment failures are addressed by the three explicit v26 deselections and the proxy bypass; no failure is suppressed or treated as a passing test.
Frozen criterion outcomes¶
every-service-verified: pass. Beat-only success, named mismatch, mixed verification and all-services checks pass in the fake-Docker regressions.health-only-for-server: pass. Worker-only cases create no HTTP-call log; mixed deployment checks HTTP health; running-state retries and timeout pass.guards-unchanged: pass under v26. Eight original tests pass unchanged; the two authorized exceptions and their preflight implementation are unchanged.suite: pass under the exact v26 method: 297 passed, 107 database skips, three authorized deselections and zero failures.
Review fix R1 (P2)¶
The accepted candidate derived all-services targets from ps --all --services,
which also lists leftover containers of inactive profiles and orphaned
services. A leftover server-beat with an older revision failed the deploy and
rolled it back. Targets are now the resolved service list of this release: the
named services, or config --services (active profiles) minus OpenBao. An
active service without a running container still fails the release. Regressions:
test_all_services_ignores_leftover_inactive_profile_worker,
test_all_services_ignores_orphaned_service_container,
test_all_services_still_fails_on_stopped_active_service; all three fail against
the previous script.
Only a local candidate commit is produced. Bridge owns independent verification, acceptance and publication. No push, PR, merge, installation, deployment or production mutation was performed.