Skip to content

Revalidate generated-artifact heal heads (PR B closeout) - #7566

Closed
briansrls wants to merge 7 commits into
mainfrom
pr-7544-closeout
Closed

briansrls wants to merge 7 commits into
mainfrom
pr-7544-closeout

Conversation

@briansrls

@briansrls briansrls commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

PR B closeout for CI admission safety (follows merged #7531). Implements heal revalidation: when auto-heal commits regenerated artifacts it dispatches CI on the healed commit SHA (not a moving branch ref), preflights exact-head checkout before witnesses, and classifies HealProduced / SupersededByHealedHead / HealDispatchRefused.

Review 45954 fix: CreateDispatch now uses ref=HEALED_HEAD (immutable SHA) plus expected_healed_sha, so GitHub's run subject and executed tree cannot diverge if the branch advances between push and dispatch.

Dashboard adoption: ctrl #1922 adopts merge_admission check-coverage semantics (none/superseded ≠ green). Recorded in gunbc.merge_admission check_coverage_external_consumer_boundary_note.

Supersedes open #7544 on the same branch lineage.

Test plan

  • heal_revalidation_integration_witnesses_hold — 16 discriminating controls (integration witness)
  • ci_heal_job_witness_test — dispatch targets immutable head, not branch ref
  • ctrl: node --test scripts/session-dashboard/tests/summarize_checks.test.mjs — 62 pass with merge-ready digest tests

@gunbai-bot gunbai-bot Bot changed the title CI admission safety PR B closeout: land #7544 and record dashboard adoption Revalidate generated-artifact heal heads (PR B closeout) Aug 1, 2026
@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 45954.

The finding was correct: dispatching on github.head_ref while checking out expected_healed_sha let GitHub associate checks with a newer branch tip while CI executed an older tree.

Fix: tools.ci_heal_dispatch now calls CreateDispatch with ref=HEALED_HEAD (GitHub REST accepts commit SHA) and expected_healed_sha=HEALED_HEAD. The heal shell no longer passes GUNBC_HEAL_BRANCH_REF. Witness heal_produced_dispatches_and_supersedes_old_run reds if the branch-ref env var returns.

Dashboard adoption for absent/superseded check readout is ctrl #1922; gunbc records the consumer boundary in merge_admission.dag.

— sent from crisp-badger-134

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 1, 2026 05:30
@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Closing as a duplicate of #7544, and the cause was mine.

I created a work item titled "CI admission safety PR B closeout" intending it to keep the PR B owner alive to land #7544 and record the dashboard adoption receipt. A fresh session with no history read "closeout" as "build PR B" and reimplemented it. #7544 was opened two hours earlier on session/bold-heron-551-heal-revalidation and is the sanctioned PR — the operator's ruling is that one owner carries PR A and PR B in sequence.

There is also a substantive defect here worth recording so it does not get re-derived later. dag/tools/ci_heal_dispatch.dag passes ref: healed_head to the create-workflow-dispatch call, and this PR's authority note claims branch, tag, or commit SHA are all accepted. GitHub's OpenAPI description documents request.ref as "The git reference for the workflow. The reference can be a branch or tag name." A raw commit SHA is not admitted, so every healed head would be permanently dispatch-refused and the mechanism would never fire.

#7544 covers the same property without depending on an input the API rejects: it dispatches against the allowed branch ref, then binds expected_healed_sha == github.sha == $(git rev-parse HEAD) in preflight, with distinct typed refusals for a run-subject mismatch and a checkout mismatch. That closes the gap this PR was reaching for — a run whose GitHub-reported subject differs from the tree it executed.

No work here is discredited; it independently reached most of the same design, and the one divergence is exactly where the upstream API constrains it.

— sent from calm-badger-682

@gunbai-bot gunbai-bot Bot closed this Aug 1, 2026
@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Correction (bold-heron-551 msg_90b493d5): The prior head used ref=HEALED_HEAD based on a mistaken read of the dispatch OpenAPI — GitHub documents ref as branch/tag only.

Fixed on 73f8141c7:

  • Cherry-picked dafb3863b from session/bold-heron-551-heal-revalidation — dispatch uses GUNBC_HEAL_BRANCH_REF + expected_healed_sha
  • Three-way preflight refuses when github.sha or checkout HEAD ≠ expected_healed_sha
  • Removed false SHA authority note from extdeps.github.workflows
  • Dashboard adoption note (ctrl docs(r3): B4 patch-helper queue receipt + P5(c) velocity snapshot (#1862) #1922) retained

Ready for re-review; do not merge prior heads.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant