fix: normalize numeric local-plugin source refs (#2312)
## Summary
- canonicalize evidence-backed SHA aliases before final release-note
validation
- repair the exact `#10786401` numeric-SHA formatting failure from the
v2.0.18 dry-run
- support short/full/unique-prefix SHA forms plus explicit commit/PR
wrappers and GitHub URLs
- preserve real PR references and keep explicit unknown PRs, ambiguous
SHAs, foreign-repository URLs, and unknown references fail-closed
- deduplicate repeated evidence commits so one real SHA cannot become
spuriously ambiguous
- fail closed when every generated item becomes invalid during
normalization
- write sanitized failure diagnostics on a best-effort basis without
masking the original validation error
- place failure diagnostics under `RUNNER_TEMP` so the existing Action
upload step always finds them
- render every stable public GitHub Release body in English, including
evidence-bound manual input, while retaining bilingual text and evidence
refs in the hidden Doc Agent payload
- normalize a single GitHub URL `source_refs` value consistently with
array inputs and tolerate evidence producers that omit either SHA alias
## Root cause
The v2.0.18 dry-run covered all 9 required evidence groups, but the
draft returned `#10786401` for the real short SHA `10786401`. Final
postprocessing treated that value as an unknown PR number. The prior fix
protected evidence generation, but not equivalent source-ref formats
returned by the draft service.
## Safety boundaries
A bare numeric `#ref` is repaired only when it exactly equals a short or
full SHA already present in collected evidence; numeric prefixes are
never coerced. Bare SHA values and explicit `sha:` wrappers may use a
unique evidence prefix. Explicit commit wrappers and same-repository
commit URLs are resolved as SHAs. Explicit PR wrappers and
same-repository pull URLs are accepted only when that PR is present in
evidence. Repository URLs are trusted only when they match
`GITHUB_REPOSITORY`; absent repository context and foreign-repository
URLs fail closed. Invented PRs, ambiguous SHA prefixes, invented refs,
missing refs, and missing required commit coverage still stop the
workflow.
Duplicate evidence commit rows are collapsed by full SHA before prefix
matching. Only references that actually resolve to collected evidence
increment `normalized_evidence_backed_source_refs`; unresolved and
ambiguous references remain visible in diagnostics and fail validation.
Failure-diagnostic I/O or a non-serializable validation report can no
longer replace the real release-note validation error; an artifact-write
failure is still visible as a CI warning. By default the files are now
written under `$RUNNER_TEMP/memos-local-plugin-release-notes-failure`,
matching the workflow upload path. `{ ok: true, needs_review: true }` is
explicitly tested and rejected.
The public GitHub Release body is always re-rendered from validated
`text_en`, including the manual-notes path. The hidden
`doc-agent-release-notes-json` payload continues to carry `text_cn`,
`text_en`, and `source_refs`, so the Chinese website output and the 106
evidence contract remain unchanged. Package-only prerelease notes were
already English.
This PR changes only the MemOS local-plugin release-note caller and
tests. It does not modify 106 Doc Agent, CLI, cloud-plugin, weekly
release notifications, npm publication, tag creation, or Release
creation.
## Verification
- targeted release-note tests: `57/57`
- complete release automation script tests: `186/186`
- real v2.0.18 evidence replay (`memos-local-plugin-v2.0.17..bc9ccd1e`):
35 path commits and 57 changed files compacted into 9 topics, 9/9
covered, 0 missing, 0 invalid; injected `#10786401` normalized once; 7
final items
- replayed public body contains no CJK text, while the hidden payload
retains Chinese text for docs generation
- manual stable input with a Chinese visible bullet is re-rendered to
English after evidence validation; its hidden bilingual payload remains
intact
- explicit unknown PR, foreign/similarly-named repository URL, missing
repository boundary, numeric/hex ambiguous SHA-prefix, duplicate commit
rows, malformed-all-items, and unwritable-diagnostic tests remain
fail-closed
- exact evidence short-SHA aliases resolve even when supplied by a
nonstandard evidence producer that does not make them a full-SHA prefix
- fork/canonical repository commit and PR URLs are tested independently
- final postprocess rejection produces a sanitized failure artifact at
the exact workflow upload path and always preserves the original
validation failure Z
zhaxi committed
28dfb4e7d3adad1c93fd5574675f913921367d36
Committed by GitHub <noreply@github.com>
on 9/1/2026, 3:49:31 AM