fix(ci): exempt release-please PRs from no-mistakes gate - #2616
Closed
kunchenguid wants to merge 2 commits into
Closed
kunchenguid wants to merge 2 commits into
kunchenguid wants to merge 2 commits into
Conversation
release-please opens its release PRs with a personal access token, so the author login is the repository owner rather than github-actions[bot]. The required "PR must be raised via no-mistakes" check therefore failed on every release PR (kunchenguid/sshhip#293 is a real one) and each release needed a manual owner override. Identify those PRs by what release-please itself produces rather than by author: a branch under its reserved release-please prefix, pushed to this repository rather than a fork, whose body carries the generated Release Please footer. All three must hold, so a hand-written human PR cannot claim the exemption with a borrowed branch name or a copied body, and a human PR without the pipeline signature still fails. Move the bot exemptions out of the job-level `if` into the same step script so the whole decision is one executable contract, and add a test that loads the workflow through a YAML parser and runs that script over the exempt and non-exempt cases.
Owner
Author
|
Closing unmerged: misscoped. The firstmate repo does not use release-please and has no release-please PRs; firstmate is NOT a template for SSHHIP release-please/no-mistakes-required. The release-please exemption belongs in SSHHIP directly, where release-please actually runs. Re-scoping the fix to SSHHIP. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Exempt release-please's own release PRs from firstmate's required no-mistakes enforcement check (.github/workflows/no-mistakes-required.yml).
Problem: the workflow requires every PR to main to carry the no-mistakes pipeline signature in its body, exempting only github-actions[bot] and dependabot[bot]. release-please now authors its release PRs under the kunchenguid identity via a personal access token, not the exempt bot, so automated release PRs FAIL the required check and need a manual owner override on every release. This was reproduced first, as the brief required: kunchenguid/sshhip PR #293 ('chore(main): release sshhip 1.22.0', head branch release-please--branches--main--components--sshhip, user kunchenguid) has check run 'PR must be raised via no-mistakes' with conclusion failure; running the pre-fix step script locally with that PR's environment also exits 1.
CRITICAL DESIGN CONSTRAINT stated by the requester: do NOT exempt the kunchenguid human identity broadly, because that would also exempt the captain's own hand-authored PRs and defeat the gate. The release PRs must be identified by a reliable release-please-specific signal determined from how release-please actually opens these PRs.
Deliberate decisions made while doing the work:
Test: tests/fm-no-mistakes-required-workflow.test.sh loads the workflow through a real YAML parser (ruby/psych, the same approach tests/fm-test-run.test.sh already uses for ci.yml) and EXECUTES the extracted step script with the environment GitHub supplies, asserting observable exit status and output - it never asserts workflow source text. Cases: a real release-please release PR (using the exact body of sshhip#293) is exempt; the older release-please branch layout is exempt; both bot authors stay exempt; a human PR without the pipeline signature still FAILS; a release-please-shaped branch name alone without the generated body FAILS; a fork copying a release-please body FAILS. It also asserts, through the parsed semantic model, that the job carries no job-level 'if', so the decision cannot silently move back out of the executable step and escape the test. The new test is classified into the pure-contract-unit family in bin/fm-test-run.sh; it was deliberately NOT added to the proven-isolated set, which requires a new concurrent isolation proof archive.
Acceptance criteria from the requester: a release-please release PR passes without an owner override; a non-exempt human PR to main without the no-mistakes signature still fails; the failure was reproduced first; a test asserts both the exemption and the still-fails-for-humans behavior; the change stays adoptable by consumer repositories and the PR notes that consumers carrying a verbatim copy (SSHHIP) must re-sync this workflow.
What Changed
Risk Assessment
✅ Low: The change is narrowly scoped and the three-factor release-please exemption preserves failure behavior for ordinary unsigned human and fork PRs while retaining existing bot exemptions.
Testing
Inspected the workflow change, ran its focused executable contract test directly and through the classified test runner, then captured an end-user-style CI transcript proving the pre-fix failure, successful release-please exemption, and continued rejection of unsigned human and fork PRs; all checks behaved as intended and the worktree remained clean.
Evidence: Required-check behavior before and after the release-please exemption
Source: Required-check behavior before and after the release-please exemption
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ **Review** - passed
✅ No issues found.
✅ **Test** - passed
✅ No issues found.
Inspectedgit diff 03bb1d8b78a8632ae2d9cea4c10868eb100e885e..607f5d52051b2f65a3d87a9a7472daf44fd3d2a4.bash tests/fm-no-mistakes-required-workflow.test.shbin/fm-test-run.sh tests/fm-no-mistakes-required-workflow.test.shParsed the pre-fix and fixed workflow scripts with Ruby Psych and executed them using release-please, ordinary-human, and fork PR environments; confirmed pre-fix rejection, fixed exemption, and retained rejection safeguards.git status --shortconfirmed testing left the worktree clean.✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.