ci: leave a merge receipt on each merged pull request - #14519
Conversation
A pull request can merge before every check on its head finishes; on 2026-09-25, 9 of 60 did. A post-merge workflow now comments once on each merged pull request with what was verified at merge, what was still running or missing, and what policy skipped, reading each check as of the merge time. When a judging check (compile admission, app-host unit tests, ci-status, required checks) was not green, the pull request gets the merged-unverified label, and main regression attribution prefers such pull requests in a tie. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 1 minute. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (10)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
Only a github-actions comment carrying the marker is edited, check names are escaped so a pull request's own job names cannot mention people or hide the receipt, and a failed gh call prints GitHub's error. Attribution now lists merged-unverified pull requests first in a tie instead of dropping the rest, since a verified head can still break main through another merge. Known limits are noted in the script's docstring. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
|
Merge receipt for |
Why
main behaves like nightly: pull requests merge fast and conflict fast, and fixing breakage quickly matters more than blocking merges. But nobody records what CI had actually verified when a pull request landed. On 2026-09-25, 9 of 60 merged pull requests (15%) landed before any green
ci-statuson their head: #14461 merged while macOS compile admission was still running, and #14382 later brokeSidebarAccessibilityTreeTests(also #14455 #14409 #14408 #14403 #14395 #14384 #14379).What
.github/workflows/merge-receipt.yml:pull_request_targetonclosedwhen merged, so fork pull requests get it too. It checks out onlyscripts/ci/merge_receipt.pyatgithub.workflow_sha(never pull request code), reads the GitHub API, and runs after the merge, so it cannot block or slow one.scripts/ci/merge_receipt.py: reads the head commit's check runs and statuses (GraphQLstatusCheckRollup), takes each check's state as of the merge time (finished before it, still running, or not started), groups the noise (guards jobs fold into one, app-host shards into one, bots and CLA hidden unless they failed), and posts one comment, edited in place on a re-run through a hidden marker. A judging check (macOS compile admission, app-host unit tests,ci-status, required checks) that was not green adds the newmerged-unverifiedlabel; a re-run that finds it green removes it.scripts/ci/main_regression_attribution.py(ci: name the merged pull request behind each new main full-suite failure #14436): when suspects tie on score, pull requests labeledmerged-unverifiedare listed first; the verified ones stay in the list, since a verified head can still break main through another merge. The label never creates a suspect on its own, and the existing caps are unchanged.github-actionscomment carrying the marker is edited, and check names are escaped so a pull request's own job names cannot mention people or hide the receipt. Known limits (100-comment marker search, statuses show current state, merge queue would need gating) are noted in the script docstring.tests/test_ci_merge_receipt.py, fixture-driven from real snapshots of Wire AgentChatProseStreamWakeDriver.swift into the app target #14461 (unverified) and ci: weigh a package source change when an owned Mac picks its starting build #14433 (all green), no network. Registered on thelinux-guardlane and in the guardscigroup, withworkflow_guard_groups.pyowners for the script, workflow, fixtures, and the attribution script.Sample receipt, dry run on #14461:
An all-green merge (#14433) gets one line: "every check was green at merge (14 verified; 15 skipped by policy). Full suite runs on main after merge."
How validated
python3 tests/test_ci_merge_receipt.py(17 tests) andpython3 tests/test_ci_main_regression_attribution.py(28 tests, 2 new) pass locally.python3 scripts/ci/validate_test_execution_registry.pypasses.merge_receipt.py post --dry-runagainst Wire AgentChatProseStreamWakeDriver.swift into the app target #14461, Fix sidebar accessibility children cycle #14382, ci: weigh a package source change when an owned Mac picks its starting build #14433, ci: name the merged pull request behind each new main full-suite failure #14436 and ci(ios): charge in-flight iOS runs the simulators their title says they need #14437 printed the expected receipts.merged-unverifiedlabel now exists in the repo.🤖 Generated with Claude Code