Repository navigation
ci: identify the merge-group fail-fast watcher's source workflow by file, not display name - #13793
Conversation
`on.workflow_run.workflows:` matches a workflow's display `name:`. Renaming a workflow for clarity stops every consumer from triggering, and nothing turns red: the consumer simply never runs again. Four workflows depend on a name this way, and `merge-group-fail-fast.yml` is the expensive one -- when it stops firing, a doomed merge group runs its macOS jobs to the end and every queue entry behind it waits. This test requires each consumer to declare the workflow file it means, derives the expected name from that file, and requires the fail-fast watcher to confirm `github.event.workflow_run.path` before it cancels anything. It fails until the next commit adds those declarations. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Each workflow_run consumer now declares the file whose display name its `workflows:` filter spells out, so the pairing is written down in terms that do not change when someone renames a workflow for clarity. `merge-group-fail-fast.yml` also checks that identity at run time. The workflow_run object carries `path` next to the presentation `name`, and display names are not unique, so the watcher confirms it was started by merge-group-policy-checks.yml before it cancels a CI run. The CI run it then watches was already located by workflow file rather than by name. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 5 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (8)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
This comment has been minimized.
This comment has been minimized.
…text (#13788) test_ci_executes_review_fabric_contracts grepped scripts/ci/detect_linux_guard_changes.py for each review-fabric path as a literal string. #13775 made the guard routes derived from PATH_OWNERS and from ci-guards.yml's run: lines, so those literals are no longer in the file and the test fails on a clean main -- taking preflight, Guard status, linux-preflight, tests and ci-status down with it on every pull request routing that lane. The routing is intact; only the check was stale. Assert the behaviour instead: the path must route linux_guard_tests, and groups_for_path must explicitly own it with preflight. That second assertion uses groups_for_path rather than classify_test_groups because classify_test_groups falls open to every group for an unknown path, and so would keep passing if ownership were dropped. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
* ci: bound the suite coverage gate * ci: align timeout placement with in-flight branch fixes
Three claims in the inventory were wrong, found while implementing the rows they describe. Row 2 listed `ci.yml` as a display-name dependency of merge-group-fail-fast.yml. It is not: that reference is `actions/workflows/ci.yml/runs`, a file path, which is already stable. Only the `workflow_run` trigger names a workflow by display name. The row also said deriving it was impossible; a test can pin the trigger against the producer's own `name:`, which #13793 does. Row 8 called `release_only_jobs` a set of job names. They are job ids: the surrounding code partitions on `\njobs:\n` and splits on the YAML keys, so a display name never participates. Row 4's deferral reason estimated that syncing the path lists would make "nearly every push to main" run the workflow. Measured against this checkout it is 11 of 67 merges, and the expensive half stays gated. #13789 implements the row. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
.github/workflows/merge-group-fail-fast.ymldecides which workflow may start it by matching a human-readable display name:on.workflow_run.workflows: [Merge-group policy checks]. That string is thename:ofmerge-group-policy-checks.yml. Anyone who renames that workflow for clarity disables the watcher, and nothing reports it — the watcher simply never triggers again, so a merge group whose first macOS job fails runs the rest of its shards to the end and every queue entry behind it waits. The merge queue is disabled on this repository right now (flaky and cancelled runs clogged it), so the watcher is dormant and this can rot unnoticed until the queue is turned back on. Three more workflows depend on another workflow's display name the same way:persistent-macos-router.yml(CI),update-homebrew.yml(Release macOS app) andcmux-tui-release-delivery.yml(cmux-tui release binaries).Resulting behavior
on.workflow_run.workflows:accepts only a workflow's display name, so the name stays in the trigger. It is no longer the only copy of the pairing:env.SOURCE_WORKFLOW_PATHS, the file that must carry the name it waits for.tests/test_ci_workflow_run_sources.pyreads that file's ownname:and fails when the two disagree, so a rename fails the pull request that renames it instead of silently switching a guard off.merge-group-fail-fast.ymlconfirms the identity at run time as well. Theworkflow_runpayload carriespathandworkflow_idnext to the presentationname, and display names are not unique, so the watcher now refuses to cancel anything unless it was started by.github/workflows/merge-group-policy-checks.yml. The CI run it then watches was already located by file (actions/workflows/ci.yml/runs), and the test asserts every such lookup names a workflow that exists.API evidence for the fields used, from a real merge-group run of the source workflow:
Sweep for the same shape
Every other place in
.github/andscripts/ci/that matches a job, check or workflow by display text:merge-group-fail-fast.yml,persistent-macos-router.yml,update-homebrew.yml,cmux-tui-release-delivery.ymlname:update-homebrew.yml:58select(.name == "build-sign-notarize")release.ymltests/test_release_homebrew_gate.py, which also asserts the job carries noname:overrideios-testflight.yml:159,377job.name === 'Upload to TestFlight'uploadjob'sname:tests/test_ci_merge_queue_required_checks.pyREQUIRED_CHECKSadministration: read, which PR CI must not holdtests/test_tui_publish_workflow_security.py:1604cmux-tui release binaries, written out againci.yml:458release_only_jobsci-macos.ymljob idsThe jobs API has no stable alternative for the job matches: its objects expose
nameandworkflow_name, never the YAML job id (gh api .../jobs --jq '.jobs[0] | keys'on release run 35225939389). That is why those stay name matches with a test pinning them.Validation and remaining gap
python3 tests/test_ci_workflow_run_sources.pyfails on the first commit and passes on the second.merge-group-policy-checks.yml, renaming the TestFlightuploadjob, replacing the run-timepathcheck withname, and pointing the CI lookup at a file that does not exist. Each is reported as a distinct failure.actionlintclean on all five changed workflows.test_ci_change_areas.py(which asserts this watcher's shape),test_release_homebrew_gate.py,test_tui_publish_workflow_security.py,test_ci_persistent_mac_compile.py,test_ci_merge_queue_required_checks.py,test_ci_guard_workflow_structure.py,test_ci_linux_guard_routing.py,test_ci_reusable_workflow_permissions.pyand the execution-registry validator all pass. Twotest_ci_change_areas.pyfailures (test_workflow_self_change_guard_runs_before_detector_imports,test_router_change_with_app_source_uses_trusted_base_product_routing) reproduce unchanged on a clean checkout of the base commit 95e843a and are unrelated to this branch.REQUIRED_CHECKSstill duplicates branch protection with no way to derive it.Part of #13095. Row 2 of
docs/ci/derived-not-declared.md.🤖 Generated with Claude Code
Summary by cubic
Pins four
workflow_runconsumers to the workflow files they expect, while retaining GitHub's display-name trigger filter. Renames now fail CI instead of silently disabling consumers, and the merge-group watcher verifies the triggering file before cancelling runs.SOURCE_WORKFLOW_PATHSvalidation and runs it in CI guards, covering missing workflows, mismatched names, and file-based run lookups.suite-coveragejob with a 5-minute timeout.Written for commit c1865e5. Summary will update on new commits.