Skip to content

ci: avoid dogfood publisher argument-size failures - #17213

Open
teamleaderleo wants to merge 1 commit into
mainfrom
fix/org-member-dogfood-publish-failed-ci
Open

teamleaderleo wants to merge 1 commit into
mainfrom
fix/org-member-dogfood-publish-failed-ci

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

The dogfood publisher failed before it could inspect Lucas's exact-head CI because it exported full pull-request, jobs, and artifacts JSON through the process environment. Linux rejected the large environment with Argument list too long, so a successful exact-head app artifact could never reach the current R2 store.

This patch writes the three API responses to runner-temp files and lets the trust gate parse those files. It preserves the existing org-member, same-repository, open-PR, exact-head, successful-Dogfood-job, unexpired-artifact, private-R2, SigV4, and sticky-comment checks.

Validation: YAML parse, git diff --check, and the existing CI guard/presigner test suite passed on the implementation branch.

— Sundial g3 🛠️
run: run_ci_linux_recovery_20261003
intention: repair the publisher handoff and dogfood Lucas #17130


Summary by cubic

Fixes the dogfood publisher failing with Argument list too long when exporting pull-request, jobs, and artifacts JSON through the process environment, which previously blocked exact-head app artifacts from reaching the R2 store.

The three GitHub API responses are now written to runner-temp files and read by the trust gate instead of being passed as environment variables. All existing security checks (org-member, same-repository, open-PR, exact-head, successful-Dogfood-job, unexpired-artifact, private-R2, SigV4, sticky-comment) are unchanged.

Written for commit 2e5f921. Summary will update on new commits.

Review in cubic

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 5 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: d530c8a7-2757-4406-bb4e-b74e49dd8126
📥 Commits

Reviewing files that changed from the base of the PR and between d8ef7e7 and 2e5f921.

📒 Files selected for processing (1)
  • .github/workflows/dogfood-artifact-publish.yml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

CI failure attribution

CI failed on 2e5f921945 (run 37156132053 attempt 1): 1 code, 1 unknown.

Job Verdict Why
Fast static checks code a static check failed
guards / workflow-guard-tests / ci unknown no known signature; failed step: Propagate failed independent fast guard
Matched log lines
Fast static checks: FAILED localization (1.22s)

Not re-run automatically: Fast static checks, guards / workflow-guard-tests / ci are not machine failures.

Written by scripts/ci/classify_failures.py (ci-failure-attribution.yml); signatures are its SIGNATURES table. A machine verdict is the runner's fault, not this PR's.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants