Skip to content

ci(feedback): record three gate gaps found adopting shield - #23

Merged
eilandert merged 2 commits into
mainfrom
feedback/shield-adoption-2026-08-05
Aug 5, 2026
Merged

eilandert merged 2 commits into
mainfrom
feedback/shield-adoption-2026-08-05

Conversation

@eilandert

@eilandert eilandert commented Aug 5, 2026 •

Copy link
Copy Markdown
Member

Findings from an adoption run against nginx-http-shield-module, which was already at 3/3 markers with anchor 872fc33. The forward path found no candidate, so all three findings are of the shape "the target has a gate this repo does not".

Three gaps, one file, no code changed. They are ports rather than fixes to existing files, which is why the PR describes them instead of making them: dropping new checkers into ci/linter/ and ci/tools/ changes the gate set of every module that adopts this skeleton next, and two of the three need a scope decision first.

The runner finding is the one worth reading. check_runners validates a runs-on selector against an allowlist of label sets (workflow_policy.py:87), but the stated reason that allowlist exists is trigger-shaped: a pull_request-triggered job checks out and executes scripts from the PR head (:78-80). The check never reads the trigger. It asks whether the selector has an approved shape, so an approved label set used without the fork ternary passes the membership test at :243. The target closes this with a 64-line trigger-based script that is label-set independent.

The other two: nothing asserts that a workflow_call member carries no push: (the current workflow set happens not to contain one, and nothing stops the next copied workflow from bringing it back), and ci/fuzz/fuzz.dict is hand-maintained with no drift gate. The third proposes no change to this repo's dictionary, only a sentence in PROMPT.md step 27, since the skeleton's patterns are illustrative and a generator here would be scaffolding for a table that does not exist.

Testing

Docs only. Every claim cites a file:line in this repo, verified against the current tree:

  • ci/linter/workflow_policy.py:460 — COMMANDS is {runners, ports, docs}; no cadence check exists
  • ci/linter/workflow_policy.py:243 — runner in TRUST_SPLITS, membership test with no trigger read
  • ls ci/tools/check-workflow-runners.sh ci/linter/lint-ci-cadence.sh ci/tools/gen-fuzz-dict.py — all absent here, all present in the target

No workflow, script or gate is touched, so the gate set is unchanged.

Adoption run against nginx-http-shield-module, already at 3/3 markers with
anchor 872fc33. The forward path found no candidate, so every finding is of
the shape "the target has a gate this repo does not".

All three are ports rather than fixes to existing files, which is why they
are described here instead of changed in this commit: adding checkers to
ci/linter/ and ci/tools/ changes the gate set of every module that adopts
this skeleton next, and two of the three need a scope decision first.

The runner one is the sharp finding. check_runners validates a runs-on
selector against an allowlist of label sets, but the reason the allowlist
exists is trigger-shaped -- a pull_request job executes scripts from the PR
head. The check never reads the trigger, so an approved label set used
without the fork ternary passes.
@coderabbitai

coderabbitai Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Review Change Stack

Walkthrough

The PR adds an adoption feedback document. It records three unported CI safeguards, their affected paths, observed costs, implementation options, and the decision not to add fuzz-dictionary tooling.

Changes

CI safeguard adoption

Layer / File(s) Summary
Safeguard adoption analysis
ci/feedback/nginx-http-shield-module-2026-08-05.md
Documents trigger-aware self-hosted runner checks, workflow_call trigger validation, and fuzz-dictionary generator and drift checks. It records scope decisions and proposes no direct repository changes.

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly states that the pull request records three CI gate gaps found during Shield adoption.
Description check ✅ Passed The description directly explains the three documented CI gate gaps and why no code changes are included.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feedback/shield-adoption-2026-08-05
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch feedback/shield-adoption-2026-08-05

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2


ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d2ca2f97-a38f-43a1-b6fe-98669b3b6c2e

📥 Commits

Reviewing files that changed from the base of the PR and between dc3dedf and e498740.

📒 Files selected for processing (1)
  • ci/feedback/nginx-http-shield-module-2026-08-05.md

Comment thread ci/feedback/nginx-http-shield-module-2026-08-05.md Outdated
Comment thread ci/feedback/nginx-http-shield-module-2026-08-05.md Outdated
Both from the CodeRabbit review on #23.

"holds by construction" implied an enforced invariant in the same sentence
that said nothing enforces it. The point of the finding is that the property
is unguarded, so the wording was arguing against itself.

"costs nothing visible" collided with the 23 -> 35 signature-reach figure
quoted 15 lines further down. What an incomplete dictionary actually does is
pass the crash-only gate, which is narrower and true.
@eilandert
eilandert merged commit b7f42b4 into main Aug 5, 2026
14 checks passed
@eilandert
eilandert deleted the feedback/shield-adoption-2026-08-05 branch August 5, 2026 00:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant