Skip to content

ci: avoid dogfood publisher argument-size failures - #17974

Closed
azooz2003-bit wants to merge 1 commit into
mainfrom
fix/org-member-dogfood-publish-failed-ci
Closed

azooz2003-bit wants to merge 1 commit into
mainfrom
fix/org-member-dogfood-publish-failed-ci

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

The dogfood publisher failed before it could inspect Lucas's exact-head CI because it exported full pull-request, jobs, and artifacts JSON through the process environment. Linux rejected the large environment with Argument list too long, so a successful exact-head app artifact could never reach the current R2 store.

This patch writes the three API responses to runner-temp files and lets the trust gate parse those files. It preserves the existing org-member, same-repository, open-PR, exact-head, successful-Dogfood-job, unexpired-artifact, private-R2, SigV4, and sticky-comment checks.

Validation: YAML parse, git diff --check, and the existing CI guard/presigner test suite passed on the implementation branch.

— Sundial g3 🛠️
run: run_ci_linux_recovery_20261003
intention: repair the publisher handoff and dogfood Lucas #17130


Summary by cubic

Fixes the dogfood publisher failing with Argument list too long when exporting pull-request, jobs, and artifacts JSON through the process environment, which previously blocked exact-head app artifacts from reaching the R2 store.

The three GitHub API responses are now written to runner-temp files and read by the trust gate instead of being passed as environment variables. All existing security checks (org-member, same-repository, open-PR, exact-head, successful-Dogfood-job, unexpired-artifact, private-R2, SigV4, sticky-comment) are unchanged.

Written for commit 2e5f921. Summary will update on new commits.

Review in cubic


Migrated from #17213 after correcting the PR author identity. The original head commit 2e5f921 is preserved.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 27 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 8b232ea3-12d5-4356-9834-e13357d3705d
📥 Commits

Reviewing files that changed from the base of the PR and between ccefb63 and 2e5f921.

📒 Files selected for processing (1)
  • .github/workflows/dogfood-artifact-publish.yml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Note

Pull Request opener @azooz2003-bit is not an author or co-author of any commit in this PR (commit identities: teamleaderleo). The CLA check will still proceed and requires every listed identity plus @azooz2003-bit to have signed.

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants