Repository navigation
docs: inventory the CI lists that must track something else - #13778
Merged
Merged
Conversation
Five of today's incidents were the same bug: a hand-maintained list that had to move in lockstep with something else, where the pull request that forgot was green on its own and main went red for everyone. This is the inventory of every such list in .github/, scripts/ci/ and tests/ -- what each duplicates, what drift costs, whether it fails the offending pull request or everyone, and whether it can be derived -- plus the three rules the incidents imply. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Contributor
|
All contributors have signed the CLA ✍️ ✅ |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Row 23 turned out to be already drifted, not just drift-prone: the guard was scanning one step while 31 went unchecked. Fixed in #13780. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
teamleaderleo
enabled auto-merge (squash)
September 22, 2026 23:14
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Five of today's incidents were the same bug wearing different clothes. Something in the tree had to be updated in lockstep with something else, the pull request that forgot was green on its own, and main went red for everyone:
ci-guards.yml's ownif:conditions)macos / macOS statusrejecting an unsetcompile_admittedinstead of defaulting (ci: read an unset compile_admitted as compile in macOS status #13727)Each was fixed where it was found. Nothing wrote down that they are one class, so the next copy of the same shape keeps landing.
Resulting behavior
docs/ci/derived-not-declared.mdinventories 30 of these across.github/,scripts/ci/andtests/— for each: what it duplicates, what drift costs, whether it fails only the offending pull request or everyone, and whether it could be derived instead. Ordered by blast radius times likelihood, with a section on whyci.yml's trigger set makes most of these merge-queue problems rather than main problems, and which five workflows do run onpush: mainand so are everyone's problem immediately.Three rules fall out: derive from the source of truth; fail only the pull request that causes the drift; treat missing configuration as the cheap default, never the expensive one. Plus the corollary the #13738/#13739 collision makes concrete — an append-only file where two pull requests can add the same line merges cleanly into an invalid file, because git cannot see a semantic conflict between two appends to different regions.
Two rows are implemented alongside this doc, in their own pull requests: #13775 derives the Linux guard route inputs from
ci-guards.yml, and #13777 writes the cheap default next to 21 barevars.reads and adds a guard. Everything else carries a one-line note on why not and what it would take.Validation and remaining gap
Four rows were verified against the tree rather than reasoned about:
ci-artifact-transport.ymlreally does guard nine paths on pull requests and not onpush: main;.github/review-bot-rules/README.mdindexes 27 of 29 rule files and is missingtest-determinism.md;ROUTING_POLICY_PATHSomitstests/test_ci_source_lint_guard_structure.pythough it lists the other four*_guard_structure.pyfiles; 43 distinct repository variables are in use anddocs/ci-runners.mddocuments 27.This is a documentation change only — no workflow, script or test is touched, and
docs/**.mdroutes as plain documentation.Remaining gap: rows 1 and 2 (branch-protection required checks, and workflow display names that
merge-group-fail-fast.ymlmatches on) are the two that can hang the merge queue for everyone with no red check anywhere, and neither is derivable from the tree — GitHub owns both. The doc says what reconciling them would need; it does not solve them.Part of #13095.
🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Adds
docs/ci/derived-not-declared.md, documenting the CI lists that duplicate another source of truth — the same bug shape behind five incidents today where a hand-maintained list went stale, the fixing pull request was green on its own, and main went red for everyone..github/,scripts/ci/, andtests/: what each duplicates, what drift costs, who it fails, and whether it can be derived.Written for commit 0cd6a66. Summary will update on new commits.
Summary by CodeRabbit