Repository navigation
ci: ignore a GitHub API error in the stale-run check - #14603
Conversation
On a rate limit `gh api --jq` prints the error body on stdout and exits non-zero. The step's `|| true` kept that body as the current PR head, so #14486's compile admission refused its own current run as stale (job 108058643725). This test fails until the step ignores non-SHA output. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`gh api --jq` prints an API error body on stdout, and `|| true` kept it, so a rate limit made compile admission (and the remote-daemon admission) refuse the PR's current run as stale. Treat anything but a 40-hex SHA as an unresolved head, which already continues with normal CI. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: Your plan provides up to 10 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughBoth CI workflows now accept API-returned head values only when they match a 40-character lowercase hexadecimal SHA. Regression tests cover API failures, matching heads, and differing heads. ChangesStale rerun identity checks
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to No actionable issue is identified that would hold up merging the stale-rerun checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to API errors will no longer incorrectly stop current CI runs, but they can also let an older run proceed when its head cannot be checked. Confirmed stale heads are still rejected, and no new privilege or verified security exploit was identified. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 1 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
The stale-run check now treats anything but a 40-hex SHA as an unresolved head, so the placeholder heads "head" and "newer-head" read as unresolved and the stale case passed. Use 40-hex values. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Merge receipt for |
74b3778 test: restore manaflow-ai#14406's sidebar AX walk assertion lost in the manaflow-ai#14408 squash (manaflow-ai#14593) 3b14475 ci: run swift-package-tests on owned minis when the run builds no Release helper (manaflow-ai#14411) 2a40caa Handle WebAuthn assertions without user handles (manaflow-ai#9060) 6cdb469 Match upload rules on HostName when a broker rewrites the host (manaflow-ai#11477) 265bef2 fix: hide browser affordances while the browser is disabled (manaflow-ai#10866) (manaflow-ai#13023) 99c4404 ci: ignore a GitHub API error in the stale-run check (manaflow-ai#14603) ceae537 test(cloud): bind the first workspace receipt before discovery (manaflow-ai#14618) # Conflicts: # .github/workflows/ci-macos.yml # .github/workflows/ci.yml # .github/workflows/remote-daemon.yml
Why
#14486's compile admission failed in its first step (job 108058643725):
gh api --jqprints an API error body on stdout and exits non-zero. The step's|| truekept that body as the "current head", so any rate limit or outage made the run refuse itself as stale. The same pattern is inremote-daemon.yml.What
Both "Reject stale pull request rerun" steps treat anything but a 40-hex SHA as an unresolved head. That path already exists: it prints "Could not resolve run/PR head identity" and continues with normal CI.
The step is in
NON_PRODUCT_RECIPE_STEPS, so product identity and seeds are unchanged.Testing
Two commits:
103ed32d1b4addstest_stale_run_check_ignores_github_api_errors, which runs both steps against a fakegh(API error, current head, newer head). It fails on that commit with the error above and passes on75284a9b0af. actionlint,test_ci_fork_runner_routing.py,test_ci_guard_workflow_structure.pyandtest_ci_app_host_identity.shpass.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Fixes the stale-run check reading a GitHub API error as the current PR head, so a rate limit or outage no longer makes compile admission refuse its own run as stale. The step now only accepts a 40-hex SHA as a head; any other output falls through to the existing normal-CI path.
ci-macos.ymlandremote-daemon.yml.gh, and updates the existing remote-daemon stale-run test to use real 40-hex SHAs.Written for commit be62096. Summary will update on new commits.
Summary by CodeRabbit