Repository navigation
ci: avoid dogfood publisher argument-size failures - #17974
azooz2003-bit wants to merge 1 commit into
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 27 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Note Pull Request opener @azooz2003-bit is not an author or co-author of any commit in this PR (commit identities: All contributors have signed the CLA ✍️ ✅ |
The dogfood publisher failed before it could inspect Lucas's exact-head CI because it exported full pull-request, jobs, and artifacts JSON through the process environment. Linux rejected the large environment with
Argument list too long, so a successful exact-head app artifact could never reach the current R2 store.This patch writes the three API responses to runner-temp files and lets the trust gate parse those files. It preserves the existing org-member, same-repository, open-PR, exact-head, successful-Dogfood-job, unexpired-artifact, private-R2, SigV4, and sticky-comment checks.
Validation: YAML parse,
git diff --check, and the existing CI guard/presigner test suite passed on the implementation branch.— Sundial g3 🛠️
run: run_ci_linux_recovery_20261003
intention: repair the publisher handoff and dogfood Lucas #17130
Summary by cubic
Fixes the dogfood publisher failing with
Argument list too longwhen exporting pull-request, jobs, and artifacts JSON through the process environment, which previously blocked exact-head app artifacts from reaching the R2 store.The three GitHub API responses are now written to runner-temp files and read by the trust gate instead of being passed as environment variables. All existing security checks (org-member, same-repository, open-PR, exact-head, successful-Dogfood-job, unexpired-artifact, private-R2, SigV4, sticky-comment) are unchanged.
Written for commit 2e5f921. Summary will update on new commits.
Migrated from #17213 after correcting the PR author identity. The original head commit 2e5f921 is preserved.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.