bug-reproduce
Turn a known bug into a tight, red-capable reproducer, then prove the reproducer locks that…
Cut a release tag behind a real tier gate and cloud approval readback. The approval, task, approved commit, and resulting tag are bound; self-approval and HEAD drift fail closed. Prod prefixes remain refused.
$ npx -y skills add Prismer-AI/PrismerCloud --skill release-tag --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/release-tagContext preview
The summary Claude sees to decide when to auto-load this skill.
Cut a release tag behind a real tier gate and cloud approval readback. The approval, task, approved commit, and resulting tag are bound; self-approval and HEAD drift fail closed. Prod prefixes remain refused.
name: release-tag description: Cut a release tag behind a real tier gate and cloud approval readback. The approval, task, approved commit, and resulting tag are bound; self-approval and HEAD drift fail closed. Prod prefixes remain refused. license: MIT scope: coding compatibility: - claude-code allowed-tools: - Bash metadata: category: release
发版打 tag(`apc/01` §2 release-tag,收口步 6)。它把**测试→上线的焊点**焊死:**没有 tier 全绿 / baseline 无新红的结构化证据,审批请求根本不创建、tag 绝不 push**。tier 门跑真 `run.ts` 读真退出码;tag 名按 `<channel>-<target>-YYYYMMDD-vX.Y.Z` 算;审批通过后 `git tag && push` 到**本地 bare mirror 替身**(真 GitLab push + pipeline 轮询 = M5)。
**什么时候用**:`release-preflight` 绿 + `release-db-config-sync` 无阻塞之后,要把一个 test 版本推上 CI。
> `apc` **不在 PATH**——在仓库根用 `npx tsx sdk/apc/bin/apc.ts <sub>`。
| 命令 | 作用 | 退出码 | | --- | --- | --- | | `npx tsx sdk/apc/bin/apc.ts release tag [--channel k8s\|desktop] [--target test\|prod] [--version X.Y.Z] --tier=<tiers> [--task <taskId> --approved <approvalId>] [--json]` | prod 人闸 → tier 门 → cloud 批件/task/commit 他证 → 把获批 SHA push 到本地 bare mirror | `0` green(pushed)· `3` staged(tier 绿待审批)· `1` blocked(tier 红 / 他证失败 / prod 拒 / push 失败)· `2` 用法错 |
`--tier` **没有默认值**(`--target prod` 路径除外——它先于 tier 门拒绝);不传直接 usage 错 exit 2。选一个会真执行断言的层,例如 `--tier=T0,T1`——**别用 `--tier=TD`** 当唯一层:无桌面冒烟 spec 时它是空门。
`--json` 字段(**名以此为准**):
npx tsx sdk/apc/bin/apc.ts release tag --channel k8s --target test --tier=T0,T1 --json > /tmp/tag-dry.json; T=$? echo "tag(dry) exit=$T"
# approval 必须是 cloud 中已被另一个人批准的 release_tag 记录,并且与 task 携带同一 commit SHA npx tsx sdk/apc/bin/apc.ts release tag --channel k8s --target test --tier=T0,T1 \ --task "$PRISMER_TASK_ID" --approved "$APPROVAL_ID" --json > /tmp/tag.json; T=$? echo "tag(push) exit=$T"
npx tsx sdk/apc/bin/apc.ts release tag --channel k8s --target prod --json; echo "prod exit=$?" # 预期:decision=blocked, exit 1, blockers 含 "prod 人闸",无任何 git 动作 # 注意:这条命令没带 --tier ——prod 人闸先于 tier 门开火,压根不需要它
本 skill 的判据**不是**「报告里出现了 `staged` / `prod` 这些字」,而是:**重解析你贴的三份 `--json` 产物**、**从 `decision` 反推退出码**、**用只读 git plumbing 回读 bare mirror 的 ref 库**、**用 tier 门自己写的副产物给这次运行定时**(`structured-criteria.ts` 的 `json-claim` + `git-claim-readback`)。
先在**隔离沙箱**里搭演示(**绝不在共享工作树打 tag/push**):
mkdir -p .e2e-tmp/apc-release-tag && git init -q --bare .e2e-tmp/apc-release-tag/mirror.git mkdir -p .e2e-tmp/apc-release-tag/work && cd .e2e-tmp/apc-release-tag/work git init -q -b main && echo demo > f.txt && git add f.txt && git commit -qm init git remote add mirror "$REPO/.e2e-tmp/apc-release-tag/mirror.git"
> `--repo` / `--mirror` **必须传绝对路径**——verb 内部会把相对 `--repo` 再解析一次(`git -C <rel>` 又在 `cwd=<rel>` 下跑),相对路径必失败。
报告必须带下面这组行 + **三份原样 JSON**:
RUN-AT: <审批那次运行的 ISO-8601 墙钟时间> STAGED-TAG: <dry-run 产物的 tag> STAGED-PUSHED: false STAGED-EXIT: 3 TAG-NAME: <审批产物的 tag> TIER-EXIT: 0 TAG-EXIT: 0 PROD-TAG: <verb 算出并拒掉的 k8s-prod-… tag> PROD-DECISION: blocked GIT-REPO: .e2e-tmp/apc-release-tag/work GIT-TAG: <tag> | remote: mirror | sha: <该 tag 在 mirror 上解析出的 commit sha> GIT-REFUSED-TAG: <k8s-prod-… tag> | remote: mirror
紧跟着把三次 `--json` 的 stdout **一字不改**贴进三个 fenced json 块(dry-run → 审批 → prod)。
判据会判红的情况(任一):
Repo: Prismer-AI/PrismerCloud
Turn a known bug into a tight, red-capable reproducer, then prove the reproducer locks that…
Review a diff against its acceptance criteria in four segments (convention adherence, bug…
Five-dimension design audit (frontend UI/UX · server data-model & flow · endpoint spec ·…
Before merge, mechanize Documentation-First — derive the code delta from git diff, then…
Diagnose the local dev machine before any APC loop step — run apc env doctor, classify each…
Close out a local coding task on the bound daemon — stage, commit, branch, merge, push via…