Revert "feat(ci): download macOS preview DMGs without signing in" - #113

Merged
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads
Aug 27, 2026
Merged

Revert "feat(ci): download macOS preview DMGs without signing in"#113
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads

Conversation

@rynfar

@rynfarrynfar commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Reverts #111 and records the decision as DEF-7 in .agents/upstream-review.md, so a later session can pick it back up rather than rediscovering it.

Nothing was wrong with the port. It cherry-picked cleanly, the runner adaptation was right, and the four silent-failure paths the pre-merge review found were all fixed in 9d112329e. The feature just does not earn its cost for Pylon.

The premise does not hold here. Upstream's motivation was that Actions artifacts require a signed-in account, which "breaks testing on headless devices." Three things undercut that for us:

  • Fork PRs cannot trigger it. Both the build and cleanup jobs require head.repo.full_name == github.repository. External contributors — the people a login-free download most helps — are excluded by design.
  • gh run download <run-id> already does this. The gate is a browser login gate; an authenticated gh CLI retrieves artifacts on a headless box without one.
  • Pylon Nightly already publishes public builds every three hours for anything merged.

That leaves one beneficiary: a maintainer testing an unmerged same-repo branch on a machine where a browser login is inconvenient.

Against that sat: 210 lines of concurrency-sensitive YAML whose four review findings were all silent failures; a new contents: write token on a PR-triggered workflow; an unsigned binary hosted publicly under the org's name; and a Releases widget advertising it as this repository's only release, while real builds live in pylon-code/pylon-releases.

Leaving it merged but inert behind an unapplied label was the alternative. Unexercised machinery carrying a write token rots — the next person to touch it inherits four races they have no reason to know about — so removing it is the more honest state.

The workflow file is byte-identical to its state before #111 merged; actionlint reports 0 findings. The preview:mac label created earlier today is being deleted alongside this.

DEF-7's revisit condition is concrete: Pylon deciding to distribute unsigned previews publicly, or upstream lifting the same-repo restriction / dropping the contents: write publish job, checkable with a path-filtered git log over the workflow. Earliest revisit 2026-11-01, so it is not re-litigated every review. If it is ever revived, the note says to start from #111 plus 9d112329e rather than from upstream.

Model: Claude Opus 5. Harness: Claude Code.


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Reverts the #111 merge and records the decision as DEF-7 in the upstream
ledger, so a later session can pick it back up if the premise changes.
Nothing was wrong with the port and its four review findings were fixed. The
feature just does not earn its cost here. Fork PRs are excluded by
head.repo.full_name == github.repository on both the build and cleanup jobs, so
external contributors cannot trigger it at all. `gh run download <run-id>`
already retrieves artifacts headlessly with an authenticated CLI, which covers
upstream's stated motivation, and Pylon Nightly already publishes builds every
three hours for anything merged. That leaves a maintainer testing an unmerged
same-repo branch on a machine where a browser login is inconvenient.
Against that: 210 lines of concurrency-sensitive YAML the pre-merge review
found four silent-failure paths in, a new contents: write token on a
PR-triggered workflow, an unsigned binary hosted publicly under the org's name,
and a Releases widget advertising it as this repository's only release.
Unexercised machinery carrying a write token rots, so it is removed rather than
left inert behind an unapplied label.
The workflow is byte-identical to its state before #111 merged.
@github-actionsgithub-actionsBot added size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Aug 27, 2026
@github-actions

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB+50 B (+0.4%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB+54 B (+0.8%)7.8 KiB
CodexLive turn WebSocket decoded55.5 KiB55.6 KiB+44 B (+0.1%)66.4 KiB
CodexLive turn messages910+1 (+11.1%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB+9 B (+0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−1 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB+10 B (+0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.3 KiB56.3 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages990 (0.0%)21

Baseline: 59a9c46 · PR result: 9491b73 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@rynfar
rynfar merged commit 0b3e147 into pylonAug 27, 2026
14 checks passed
@rynfar
rynfar deleted the revert/2026-08-27-preview-dmg-downloads branch August 27, 2026 07:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Revert "feat(ci): download macOS preview DMGs without signing in" - #113

Merged
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads
Aug 27, 2026
Merged

Revert "feat(ci): download macOS preview DMGs without signing in"#113
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads

Conversation

@rynfar

@rynfarrynfar commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Reverts #111 and records the decision as DEF-7 in .agents/upstream-review.md, so a later session can pick it back up rather than rediscovering it.

Nothing was wrong with the port. It cherry-picked cleanly, the runner adaptation was right, and the four silent-failure paths the pre-merge review found were all fixed in 9d112329e. The feature just does not earn its cost for Pylon.

The premise does not hold here. Upstream's motivation was that Actions artifacts require a signed-in account, which "breaks testing on headless devices." Three things undercut that for us:

  • Fork PRs cannot trigger it. Both the build and cleanup jobs require head.repo.full_name == github.repository. External contributors — the people a login-free download most helps — are excluded by design.
  • gh run download <run-id> already does this. The gate is a browser login gate; an authenticated gh CLI retrieves artifacts on a headless box without one.
  • Pylon Nightly already publishes public builds every three hours for anything merged.

That leaves one beneficiary: a maintainer testing an unmerged same-repo branch on a machine where a browser login is inconvenient.

Against that sat: 210 lines of concurrency-sensitive YAML whose four review findings were all silent failures; a new contents: write token on a PR-triggered workflow; an unsigned binary hosted publicly under the org's name; and a Releases widget advertising it as this repository's only release, while real builds live in pylon-code/pylon-releases.

Leaving it merged but inert behind an unapplied label was the alternative. Unexercised machinery carrying a write token rots — the next person to touch it inherits four races they have no reason to know about — so removing it is the more honest state.

The workflow file is byte-identical to its state before #111 merged; actionlint reports 0 findings. The preview:mac label created earlier today is being deleted alongside this.

DEF-7's revisit condition is concrete: Pylon deciding to distribute unsigned previews publicly, or upstream lifting the same-repo restriction / dropping the contents: write publish job, checkable with a path-filtered git log over the workflow. Earliest revisit 2026-11-01, so it is not re-litigated every review. If it is ever revived, the note says to start from #111 plus 9d112329e rather than from upstream.

Model: Claude Opus 5. Harness: Claude Code.


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Reverts the #111 merge and records the decision as DEF-7 in the upstream
ledger, so a later session can pick it back up if the premise changes.
Nothing was wrong with the port and its four review findings were fixed. The
feature just does not earn its cost here. Fork PRs are excluded by
head.repo.full_name == github.repository on both the build and cleanup jobs, so
external contributors cannot trigger it at all. `gh run download <run-id>`
already retrieves artifacts headlessly with an authenticated CLI, which covers
upstream's stated motivation, and Pylon Nightly already publishes builds every
three hours for anything merged. That leaves a maintainer testing an unmerged
same-repo branch on a machine where a browser login is inconvenient.
Against that: 210 lines of concurrency-sensitive YAML the pre-merge review
found four silent-failure paths in, a new contents: write token on a
PR-triggered workflow, an unsigned binary hosted publicly under the org's name,
and a Releases widget advertising it as this repository's only release.
Unexercised machinery carrying a write token rots, so it is removed rather than
left inert behind an unapplied label.
The workflow is byte-identical to its state before #111 merged.
@github-actionsgithub-actionsBot added size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Aug 27, 2026
@github-actions

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB+50 B (+0.4%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB+54 B (+0.8%)7.8 KiB
CodexLive turn WebSocket decoded55.5 KiB55.6 KiB+44 B (+0.1%)66.4 KiB
CodexLive turn messages910+1 (+11.1%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB+9 B (+0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−1 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB+10 B (+0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.3 KiB56.3 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages990 (0.0%)21

Baseline: 59a9c46 · PR result: 9491b73 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@rynfar
rynfar merged commit 0b3e147 into pylonAug 27, 2026
14 checks passed
@rynfar
rynfar deleted the revert/2026-08-27-preview-dmg-downloads branch August 27, 2026 07:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Revert "feat(ci): download macOS preview DMGs without signing in" - #113

Merged
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads
Aug 27, 2026
Merged

Revert "feat(ci): download macOS preview DMGs without signing in"#113
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads

Conversation

@rynfar

@rynfarrynfar commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Reverts #111 and records the decision as DEF-7 in .agents/upstream-review.md, so a later session can pick it back up rather than rediscovering it.

Nothing was wrong with the port. It cherry-picked cleanly, the runner adaptation was right, and the four silent-failure paths the pre-merge review found were all fixed in 9d112329e. The feature just does not earn its cost for Pylon.

The premise does not hold here. Upstream's motivation was that Actions artifacts require a signed-in account, which "breaks testing on headless devices." Three things undercut that for us:

  • Fork PRs cannot trigger it. Both the build and cleanup jobs require head.repo.full_name == github.repository. External contributors — the people a login-free download most helps — are excluded by design.
  • gh run download <run-id> already does this. The gate is a browser login gate; an authenticated gh CLI retrieves artifacts on a headless box without one.
  • Pylon Nightly already publishes public builds every three hours for anything merged.

That leaves one beneficiary: a maintainer testing an unmerged same-repo branch on a machine where a browser login is inconvenient.

Against that sat: 210 lines of concurrency-sensitive YAML whose four review findings were all silent failures; a new contents: write token on a PR-triggered workflow; an unsigned binary hosted publicly under the org's name; and a Releases widget advertising it as this repository's only release, while real builds live in pylon-code/pylon-releases.

Leaving it merged but inert behind an unapplied label was the alternative. Unexercised machinery carrying a write token rots — the next person to touch it inherits four races they have no reason to know about — so removing it is the more honest state.

The workflow file is byte-identical to its state before #111 merged; actionlint reports 0 findings. The preview:mac label created earlier today is being deleted alongside this.

DEF-7's revisit condition is concrete: Pylon deciding to distribute unsigned previews publicly, or upstream lifting the same-repo restriction / dropping the contents: write publish job, checkable with a path-filtered git log over the workflow. Earliest revisit 2026-11-01, so it is not re-litigated every review. If it is ever revived, the note says to start from #111 plus 9d112329e rather than from upstream.

Model: Claude Opus 5. Harness: Claude Code.


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Reverts the #111 merge and records the decision as DEF-7 in the upstream
ledger, so a later session can pick it back up if the premise changes.
Nothing was wrong with the port and its four review findings were fixed. The
feature just does not earn its cost here. Fork PRs are excluded by
head.repo.full_name == github.repository on both the build and cleanup jobs, so
external contributors cannot trigger it at all. `gh run download <run-id>`
already retrieves artifacts headlessly with an authenticated CLI, which covers
upstream's stated motivation, and Pylon Nightly already publishes builds every
three hours for anything merged. That leaves a maintainer testing an unmerged
same-repo branch on a machine where a browser login is inconvenient.
Against that: 210 lines of concurrency-sensitive YAML the pre-merge review
found four silent-failure paths in, a new contents: write token on a
PR-triggered workflow, an unsigned binary hosted publicly under the org's name,
and a Releases widget advertising it as this repository's only release.
Unexercised machinery carrying a write token rots, so it is removed rather than
left inert behind an unapplied label.
The workflow is byte-identical to its state before #111 merged.
@github-actionsgithub-actionsBot added size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Aug 27, 2026
@github-actions

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB+50 B (+0.4%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB+54 B (+0.8%)7.8 KiB
CodexLive turn WebSocket decoded55.5 KiB55.6 KiB+44 B (+0.1%)66.4 KiB
CodexLive turn messages910+1 (+11.1%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB+9 B (+0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−1 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB+10 B (+0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.3 KiB56.3 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages990 (0.0%)21

Baseline: 59a9c46 · PR result: 9491b73 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@rynfar
rynfar merged commit 0b3e147 into pylonAug 27, 2026
14 checks passed
@rynfar
rynfar deleted the revert/2026-08-27-preview-dmg-downloads branch August 27, 2026 07:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Revert "feat(ci): download macOS preview DMGs without signing in" - #113

Merged
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads
Aug 27, 2026
Merged

Revert "feat(ci): download macOS preview DMGs without signing in"#113
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads

Conversation

@rynfar

@rynfarrynfar commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Reverts #111 and records the decision as DEF-7 in .agents/upstream-review.md, so a later session can pick it back up rather than rediscovering it.

Nothing was wrong with the port. It cherry-picked cleanly, the runner adaptation was right, and the four silent-failure paths the pre-merge review found were all fixed in 9d112329e. The feature just does not earn its cost for Pylon.

The premise does not hold here. Upstream's motivation was that Actions artifacts require a signed-in account, which "breaks testing on headless devices." Three things undercut that for us:

  • Fork PRs cannot trigger it. Both the build and cleanup jobs require head.repo.full_name == github.repository. External contributors — the people a login-free download most helps — are excluded by design.
  • gh run download <run-id> already does this. The gate is a browser login gate; an authenticated gh CLI retrieves artifacts on a headless box without one.
  • Pylon Nightly already publishes public builds every three hours for anything merged.

That leaves one beneficiary: a maintainer testing an unmerged same-repo branch on a machine where a browser login is inconvenient.

Against that sat: 210 lines of concurrency-sensitive YAML whose four review findings were all silent failures; a new contents: write token on a PR-triggered workflow; an unsigned binary hosted publicly under the org's name; and a Releases widget advertising it as this repository's only release, while real builds live in pylon-code/pylon-releases.

Leaving it merged but inert behind an unapplied label was the alternative. Unexercised machinery carrying a write token rots — the next person to touch it inherits four races they have no reason to know about — so removing it is the more honest state.

The workflow file is byte-identical to its state before #111 merged; actionlint reports 0 findings. The preview:mac label created earlier today is being deleted alongside this.

DEF-7's revisit condition is concrete: Pylon deciding to distribute unsigned previews publicly, or upstream lifting the same-repo restriction / dropping the contents: write publish job, checkable with a path-filtered git log over the workflow. Earliest revisit 2026-11-01, so it is not re-litigated every review. If it is ever revived, the note says to start from #111 plus 9d112329e rather than from upstream.

Model: Claude Opus 5. Harness: Claude Code.


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Reverts the #111 merge and records the decision as DEF-7 in the upstream
ledger, so a later session can pick it back up if the premise changes.
Nothing was wrong with the port and its four review findings were fixed. The
feature just does not earn its cost here. Fork PRs are excluded by
head.repo.full_name == github.repository on both the build and cleanup jobs, so
external contributors cannot trigger it at all. `gh run download <run-id>`
already retrieves artifacts headlessly with an authenticated CLI, which covers
upstream's stated motivation, and Pylon Nightly already publishes builds every
three hours for anything merged. That leaves a maintainer testing an unmerged
same-repo branch on a machine where a browser login is inconvenient.
Against that: 210 lines of concurrency-sensitive YAML the pre-merge review
found four silent-failure paths in, a new contents: write token on a
PR-triggered workflow, an unsigned binary hosted publicly under the org's name,
and a Releases widget advertising it as this repository's only release.
Unexercised machinery carrying a write token rots, so it is removed rather than
left inert behind an unapplied label.
The workflow is byte-identical to its state before #111 merged.
@github-actionsgithub-actionsBot added size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Aug 27, 2026
@github-actions

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB+50 B (+0.4%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB+54 B (+0.8%)7.8 KiB
CodexLive turn WebSocket decoded55.5 KiB55.6 KiB+44 B (+0.1%)66.4 KiB
CodexLive turn messages910+1 (+11.1%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB+9 B (+0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−1 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB+10 B (+0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.3 KiB56.3 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages990 (0.0%)21

Baseline: 59a9c46 · PR result: 9491b73 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@rynfar
rynfar merged commit 0b3e147 into pylonAug 27, 2026
14 checks passed
@rynfar
rynfar deleted the revert/2026-08-27-preview-dmg-downloads branch August 27, 2026 07:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Revert "feat(ci): download macOS preview DMGs without signing in" - #113

Merged
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads
Aug 27, 2026
Merged

Revert "feat(ci): download macOS preview DMGs without signing in"#113
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads

Conversation

@rynfar

@rynfarrynfar commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Reverts #111 and records the decision as DEF-7 in .agents/upstream-review.md, so a later session can pick it back up rather than rediscovering it.

Nothing was wrong with the port. It cherry-picked cleanly, the runner adaptation was right, and the four silent-failure paths the pre-merge review found were all fixed in 9d112329e. The feature just does not earn its cost for Pylon.

The premise does not hold here. Upstream's motivation was that Actions artifacts require a signed-in account, which "breaks testing on headless devices." Three things undercut that for us:

  • Fork PRs cannot trigger it. Both the build and cleanup jobs require head.repo.full_name == github.repository. External contributors — the people a login-free download most helps — are excluded by design.
  • gh run download <run-id> already does this. The gate is a browser login gate; an authenticated gh CLI retrieves artifacts on a headless box without one.
  • Pylon Nightly already publishes public builds every three hours for anything merged.

That leaves one beneficiary: a maintainer testing an unmerged same-repo branch on a machine where a browser login is inconvenient.

Against that sat: 210 lines of concurrency-sensitive YAML whose four review findings were all silent failures; a new contents: write token on a PR-triggered workflow; an unsigned binary hosted publicly under the org's name; and a Releases widget advertising it as this repository's only release, while real builds live in pylon-code/pylon-releases.

Leaving it merged but inert behind an unapplied label was the alternative. Unexercised machinery carrying a write token rots — the next person to touch it inherits four races they have no reason to know about — so removing it is the more honest state.

The workflow file is byte-identical to its state before #111 merged; actionlint reports 0 findings. The preview:mac label created earlier today is being deleted alongside this.

DEF-7's revisit condition is concrete: Pylon deciding to distribute unsigned previews publicly, or upstream lifting the same-repo restriction / dropping the contents: write publish job, checkable with a path-filtered git log over the workflow. Earliest revisit 2026-11-01, so it is not re-litigated every review. If it is ever revived, the note says to start from #111 plus 9d112329e rather than from upstream.

Model: Claude Opus 5. Harness: Claude Code.


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Reverts the #111 merge and records the decision as DEF-7 in the upstream
ledger, so a later session can pick it back up if the premise changes.
Nothing was wrong with the port and its four review findings were fixed. The
feature just does not earn its cost here. Fork PRs are excluded by
head.repo.full_name == github.repository on both the build and cleanup jobs, so
external contributors cannot trigger it at all. `gh run download <run-id>`
already retrieves artifacts headlessly with an authenticated CLI, which covers
upstream's stated motivation, and Pylon Nightly already publishes builds every
three hours for anything merged. That leaves a maintainer testing an unmerged
same-repo branch on a machine where a browser login is inconvenient.
Against that: 210 lines of concurrency-sensitive YAML the pre-merge review
found four silent-failure paths in, a new contents: write token on a
PR-triggered workflow, an unsigned binary hosted publicly under the org's name,
and a Releases widget advertising it as this repository's only release.
Unexercised machinery carrying a write token rots, so it is removed rather than
left inert behind an unapplied label.
The workflow is byte-identical to its state before #111 merged.
@github-actionsgithub-actionsBot added size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Aug 27, 2026
@github-actions

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB+50 B (+0.4%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB+54 B (+0.8%)7.8 KiB
CodexLive turn WebSocket decoded55.5 KiB55.6 KiB+44 B (+0.1%)66.4 KiB
CodexLive turn messages910+1 (+11.1%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB+9 B (+0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−1 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB+10 B (+0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.3 KiB56.3 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages990 (0.0%)21

Baseline: 59a9c46 · PR result: 9491b73 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@rynfar
rynfar merged commit 0b3e147 into pylonAug 27, 2026
14 checks passed
@rynfar
rynfar deleted the revert/2026-08-27-preview-dmg-downloads branch August 27, 2026 07:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Revert "feat(ci): download macOS preview DMGs without signing in" - #113

Merged
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads
Aug 27, 2026
Merged

Revert "feat(ci): download macOS preview DMGs without signing in"#113
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads

Conversation

@rynfar

@rynfarrynfar commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Reverts #111 and records the decision as DEF-7 in .agents/upstream-review.md, so a later session can pick it back up rather than rediscovering it.

Nothing was wrong with the port. It cherry-picked cleanly, the runner adaptation was right, and the four silent-failure paths the pre-merge review found were all fixed in 9d112329e. The feature just does not earn its cost for Pylon.

The premise does not hold here. Upstream's motivation was that Actions artifacts require a signed-in account, which "breaks testing on headless devices." Three things undercut that for us:

  • Fork PRs cannot trigger it. Both the build and cleanup jobs require head.repo.full_name == github.repository. External contributors — the people a login-free download most helps — are excluded by design.
  • gh run download <run-id> already does this. The gate is a browser login gate; an authenticated gh CLI retrieves artifacts on a headless box without one.
  • Pylon Nightly already publishes public builds every three hours for anything merged.

That leaves one beneficiary: a maintainer testing an unmerged same-repo branch on a machine where a browser login is inconvenient.

Against that sat: 210 lines of concurrency-sensitive YAML whose four review findings were all silent failures; a new contents: write token on a PR-triggered workflow; an unsigned binary hosted publicly under the org's name; and a Releases widget advertising it as this repository's only release, while real builds live in pylon-code/pylon-releases.

Leaving it merged but inert behind an unapplied label was the alternative. Unexercised machinery carrying a write token rots — the next person to touch it inherits four races they have no reason to know about — so removing it is the more honest state.

The workflow file is byte-identical to its state before #111 merged; actionlint reports 0 findings. The preview:mac label created earlier today is being deleted alongside this.

DEF-7's revisit condition is concrete: Pylon deciding to distribute unsigned previews publicly, or upstream lifting the same-repo restriction / dropping the contents: write publish job, checkable with a path-filtered git log over the workflow. Earliest revisit 2026-11-01, so it is not re-litigated every review. If it is ever revived, the note says to start from #111 plus 9d112329e rather than from upstream.

Model: Claude Opus 5. Harness: Claude Code.


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Reverts the #111 merge and records the decision as DEF-7 in the upstream
ledger, so a later session can pick it back up if the premise changes.
Nothing was wrong with the port and its four review findings were fixed. The
feature just does not earn its cost here. Fork PRs are excluded by
head.repo.full_name == github.repository on both the build and cleanup jobs, so
external contributors cannot trigger it at all. `gh run download <run-id>`
already retrieves artifacts headlessly with an authenticated CLI, which covers
upstream's stated motivation, and Pylon Nightly already publishes builds every
three hours for anything merged. That leaves a maintainer testing an unmerged
same-repo branch on a machine where a browser login is inconvenient.
Against that: 210 lines of concurrency-sensitive YAML the pre-merge review
found four silent-failure paths in, a new contents: write token on a
PR-triggered workflow, an unsigned binary hosted publicly under the org's name,
and a Releases widget advertising it as this repository's only release.
Unexercised machinery carrying a write token rots, so it is removed rather than
left inert behind an unapplied label.
The workflow is byte-identical to its state before #111 merged.
@github-actionsgithub-actionsBot added size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Aug 27, 2026
@github-actions

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB+50 B (+0.4%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB+54 B (+0.8%)7.8 KiB
CodexLive turn WebSocket decoded55.5 KiB55.6 KiB+44 B (+0.1%)66.4 KiB
CodexLive turn messages910+1 (+11.1%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB+9 B (+0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−1 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB+10 B (+0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.3 KiB56.3 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages990 (0.0%)21

Baseline: 59a9c46 · PR result: 9491b73 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@rynfar
rynfar merged commit 0b3e147 into pylonAug 27, 2026
14 checks passed
@rynfar
rynfar deleted the revert/2026-08-27-preview-dmg-downloads branch August 27, 2026 07:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Revert "feat(ci): download macOS preview DMGs without signing in" - #113

Merged
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads
Aug 27, 2026
Merged

Revert "feat(ci): download macOS preview DMGs without signing in"#113
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads

Conversation

@rynfar

@rynfarrynfar commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Reverts #111 and records the decision as DEF-7 in .agents/upstream-review.md, so a later session can pick it back up rather than rediscovering it.

Nothing was wrong with the port. It cherry-picked cleanly, the runner adaptation was right, and the four silent-failure paths the pre-merge review found were all fixed in 9d112329e. The feature just does not earn its cost for Pylon.

The premise does not hold here. Upstream's motivation was that Actions artifacts require a signed-in account, which "breaks testing on headless devices." Three things undercut that for us:

  • Fork PRs cannot trigger it. Both the build and cleanup jobs require head.repo.full_name == github.repository. External contributors — the people a login-free download most helps — are excluded by design.
  • gh run download <run-id> already does this. The gate is a browser login gate; an authenticated gh CLI retrieves artifacts on a headless box without one.
  • Pylon Nightly already publishes public builds every three hours for anything merged.

That leaves one beneficiary: a maintainer testing an unmerged same-repo branch on a machine where a browser login is inconvenient.

Against that sat: 210 lines of concurrency-sensitive YAML whose four review findings were all silent failures; a new contents: write token on a PR-triggered workflow; an unsigned binary hosted publicly under the org's name; and a Releases widget advertising it as this repository's only release, while real builds live in pylon-code/pylon-releases.

Leaving it merged but inert behind an unapplied label was the alternative. Unexercised machinery carrying a write token rots — the next person to touch it inherits four races they have no reason to know about — so removing it is the more honest state.

The workflow file is byte-identical to its state before #111 merged; actionlint reports 0 findings. The preview:mac label created earlier today is being deleted alongside this.

DEF-7's revisit condition is concrete: Pylon deciding to distribute unsigned previews publicly, or upstream lifting the same-repo restriction / dropping the contents: write publish job, checkable with a path-filtered git log over the workflow. Earliest revisit 2026-11-01, so it is not re-litigated every review. If it is ever revived, the note says to start from #111 plus 9d112329e rather than from upstream.

Model: Claude Opus 5. Harness: Claude Code.


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Reverts the #111 merge and records the decision as DEF-7 in the upstream
ledger, so a later session can pick it back up if the premise changes.
Nothing was wrong with the port and its four review findings were fixed. The
feature just does not earn its cost here. Fork PRs are excluded by
head.repo.full_name == github.repository on both the build and cleanup jobs, so
external contributors cannot trigger it at all. `gh run download <run-id>`
already retrieves artifacts headlessly with an authenticated CLI, which covers
upstream's stated motivation, and Pylon Nightly already publishes builds every
three hours for anything merged. That leaves a maintainer testing an unmerged
same-repo branch on a machine where a browser login is inconvenient.
Against that: 210 lines of concurrency-sensitive YAML the pre-merge review
found four silent-failure paths in, a new contents: write token on a
PR-triggered workflow, an unsigned binary hosted publicly under the org's name,
and a Releases widget advertising it as this repository's only release.
Unexercised machinery carrying a write token rots, so it is removed rather than
left inert behind an unapplied label.
The workflow is byte-identical to its state before #111 merged.
@github-actionsgithub-actionsBot added size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Aug 27, 2026
@github-actions

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB+50 B (+0.4%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB+54 B (+0.8%)7.8 KiB
CodexLive turn WebSocket decoded55.5 KiB55.6 KiB+44 B (+0.1%)66.4 KiB
CodexLive turn messages910+1 (+11.1%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB+9 B (+0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−1 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB+10 B (+0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.3 KiB56.3 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages990 (0.0%)21

Baseline: 59a9c46 · PR result: 9491b73 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@rynfar
rynfar merged commit 0b3e147 into pylonAug 27, 2026
14 checks passed
@rynfar
rynfar deleted the revert/2026-08-27-preview-dmg-downloads branch August 27, 2026 07:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Revert "feat(ci): download macOS preview DMGs without signing in" - #113

Merged
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads
Aug 27, 2026
Merged

Revert "feat(ci): download macOS preview DMGs without signing in"#113
rynfar merged 1 commit into
pylonfrom
revert/2026-08-27-preview-dmg-downloads

Conversation

@rynfar

@rynfarrynfar commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Reverts #111 and records the decision as DEF-7 in .agents/upstream-review.md, so a later session can pick it back up rather than rediscovering it.

Nothing was wrong with the port. It cherry-picked cleanly, the runner adaptation was right, and the four silent-failure paths the pre-merge review found were all fixed in 9d112329e. The feature just does not earn its cost for Pylon.

The premise does not hold here. Upstream's motivation was that Actions artifacts require a signed-in account, which "breaks testing on headless devices." Three things undercut that for us:

  • Fork PRs cannot trigger it. Both the build and cleanup jobs require head.repo.full_name == github.repository. External contributors — the people a login-free download most helps — are excluded by design.
  • gh run download <run-id> already does this. The gate is a browser login gate; an authenticated gh CLI retrieves artifacts on a headless box without one.
  • Pylon Nightly already publishes public builds every three hours for anything merged.

That leaves one beneficiary: a maintainer testing an unmerged same-repo branch on a machine where a browser login is inconvenient.

Against that sat: 210 lines of concurrency-sensitive YAML whose four review findings were all silent failures; a new contents: write token on a PR-triggered workflow; an unsigned binary hosted publicly under the org's name; and a Releases widget advertising it as this repository's only release, while real builds live in pylon-code/pylon-releases.

Leaving it merged but inert behind an unapplied label was the alternative. Unexercised machinery carrying a write token rots — the next person to touch it inherits four races they have no reason to know about — so removing it is the more honest state.

The workflow file is byte-identical to its state before #111 merged; actionlint reports 0 findings. The preview:mac label created earlier today is being deleted alongside this.

DEF-7's revisit condition is concrete: Pylon deciding to distribute unsigned previews publicly, or upstream lifting the same-repo restriction / dropping the contents: write publish job, checkable with a path-filtered git log over the workflow. Earliest revisit 2026-11-01, so it is not re-litigated every review. If it is ever revived, the note says to start from #111 plus 9d112329e rather than from upstream.

Model: Claude Opus 5. Harness: Claude Code.


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Reverts the #111 merge and records the decision as DEF-7 in the upstream
ledger, so a later session can pick it back up if the premise changes.
Nothing was wrong with the port and its four review findings were fixed. The
feature just does not earn its cost here. Fork PRs are excluded by
head.repo.full_name == github.repository on both the build and cleanup jobs, so
external contributors cannot trigger it at all. `gh run download <run-id>`
already retrieves artifacts headlessly with an authenticated CLI, which covers
upstream's stated motivation, and Pylon Nightly already publishes builds every
three hours for anything merged. That leaves a maintainer testing an unmerged
same-repo branch on a machine where a browser login is inconvenient.
Against that: 210 lines of concurrency-sensitive YAML the pre-merge review
found four silent-failure paths in, a new contents: write token on a
PR-triggered workflow, an unsigned binary hosted publicly under the org's name,
and a Releases widget advertising it as this repository's only release.
Unexercised machinery carrying a write token rots, so it is removed rather than
left inert behind an unapplied label.
The workflow is byte-identical to its state before #111 merged.
@github-actionsgithub-actionsBot added size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Aug 27, 2026
@github-actions

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB+50 B (+0.4%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB+54 B (+0.8%)7.8 KiB
CodexLive turn WebSocket decoded55.5 KiB55.6 KiB+44 B (+0.1%)66.4 KiB
CodexLive turn messages910+1 (+11.1%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB+9 B (+0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−1 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB+10 B (+0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.3 KiB56.3 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages990 (0.0%)21

Baseline: 59a9c46 · PR result: 9491b73 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@rynfar
rynfar merged commit 0b3e147 into pylonAug 27, 2026
14 checks passed
@rynfar
rynfar deleted the revert/2026-08-27-preview-dmg-downloads branch August 27, 2026 07:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rynfar