Skip to content

ci(canary): remove provider-matrix lanes and zizmor scan - #7418

Merged
serrrfirat merged 2 commits into
nearai:mainfrom
serrrfirat:remove-canary-ci
Aug 10, 2026
Merged

serrrfirat merged 2 commits into
nearai:mainfrom
serrrfirat:remove-canary-ci

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Summary

  • Remove the provider-matrix job from live-canary.yml and its weekly cron (30 5 * * 1) — both provider lanes were failing in seconds because they invoke cargo test --test e2e_live against test targets deleted with the v1 monolith (refactor(tier-b): delete v1 legacy monolith (src/) and cut deploy over to Reborn #6375), so they were running dead code paths.
  • Remove the zizmor scan: the Pre-install zizmor steps in public-smoke / release-public-full, the zizmor_scan / zizmor_scan_v2 scenario runs in run.sh, the dead tests/fixtures/llm_traces/live/zizmor_scan*.json fixtures, and the stale nextest.toml overrides referencing the deleted live_tests::zizmor_scan* tests.
  • Unpin the retired markers from ws12_workflow_contracts.py (3-hourly Reborn WebUI cadence pins kept) and update the canary docs/lane lists.
  • The reborn-webui-v2-live-qa lane, its 3-hourly schedule, /canary PR command, and all other lanes are untouched.

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

None — maintainer-requested retirement of the failing canary lanes.

Validation

  • cargo fmt --all -- --check
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings
  • cargo build
  • Relevant tests pass: python3 scripts/ci/test_ws12_workflow_contracts.py (52/52), scripts/reborn_webui_v2_live_qa/test_run_live_qa.py::test_live_canary_workflow_shards_cover_non_telegram_qa_suite (OK, py3.14), python3 scripts/ci/test-check-regression-promotions.py (11/11), python3 scripts/live-canary/test_emit_results_json.py (27/27)
  • cargo test -p <owning-crate> --features integration if database-backed or runtime-integration behavior changed (the root integration feature is empty — the flag is per-crate)
  • Manual testing: bash -n scripts/live-canary/run.sh; live-canary.yml parsed — 17 jobs, single 3-hourly cron, provider-matrix absent from jobs / canary-report needs / dispatch options
  • If a coding agent was used and supports it, review-pr or pr-shepherd --fix was run before requesting review

Test Strategy

User behavior: no user-facing behavior changes — removes two failing scheduled CI lanes and the zizmor scenario from the live canary.

Risk areas:

  • Model behavior
  • Browser
  • Side effect
  • Persistence
  • Security or permissions
  • External provider
  • Cross-component behavior (workflow ↔ contract-test ↔ dispatcher/docs consistency)

Tests added or updated:

  • Unit or contract: test_ws12_workflow_contracts.py markers unpinned; full suite passes with the edited workflow
  • Reborn integration: Not applicable — no Rust changes
  • Recorded fixture: zizmor_scan*.json deleted (consuming tests/e2e_live*.rs were removed in refactor(tier-b): delete v1 legacy monolith (src/) and cut deploy over to Reborn #6375; no remaining consumers)
  • Browser E2E: Not applicable
  • Backend or runtime: Not applicable
  • Live canary: provider-matrix lanes removed; reborn-webui-v2-live-qa shard contract test still passes

What the tests prove: the workflow-contract sabotage suite still passes with the retired markers unpinned (i.e., no required schedule disappeared), and the live QA shard coverage contract is unaffected.

Commands run:

  • python3 scripts/ci/test_ws12_workflow_contracts.py
  • /opt/homebrew/bin/python3.14 -m unittest scripts.reborn_webui_v2_live_qa.test_run_live_qa.RebornWebUiV2LiveQaRunnerTests.test_live_canary_workflow_shards_cover_non_telegram_qa_suite
  • python3 scripts/ci/test-check-regression-promotions.py
  • python3 scripts/live-canary/test_emit_results_json.py
  • bash -n scripts/live-canary/run.sh
  • PyYAML parse of live-canary.yml (jobs, schedule, needs)

Security Impact

None. Retires CI lanes that consumed live provider credentials (ANTHROPIC_API_KEY, LIVE_OPENAI_COMPATIBLE_API_KEY); no new permissions, network calls, or secret handling introduced.

Reborn Trust-Boundary Checklist

N/A — no Rust, runtime, or trust-boundary code touched; CI workflow/scripts/docs only.

Database Impact

None.

Blast Radius

  • live-canary.yml — scheduled runs lose the weekly provider-matrix jobs; manual dispatch option removed; canary-report no longer depends on it
  • scripts/live-canary/run.sh — provider-matrix lane and zizmor scenarios removed; remaining lanes unchanged
  • scripts/ci/ws12_workflow_contracts.py — weekly-cron markers unpinned (would otherwise fail CI after the workflow edit)
  • scripts/ci/check-regression-promotions.py, test_run_live_qa.py — untouched, verified still passing

Rollback Plan

Revert this commit (git revert) — all changes are additive-restore (job block, cron, scenario lines, fixtures, contract pins). The deleted fixtures are recoverable from git history if the zizmor lanes are ever reinstated.

Review Follow-Through

None — reviewer judgment only on whether the remaining zizmor_scan strings in scripts/live-canary/emit_results_json.py / test_emit_results_json.py (log-parser sample fixtures, not live wiring) and .coderabbit.yaml (CodeRabbit's own scanner) should stay; both intentionally left.


Review track: C (CI)

@github-actions github-actions Bot added scope: ci CI/CD workflows scope: docs Documentation size: M 50-199 changed lines risk: medium Business logic, config, or moderate-risk modules labels Aug 10, 2026
@coderabbitai

coderabbitai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • CI/CD

    • Removed the weekly provider-matrix lane from live-canary runs and manual dispatch options.
    • Retained the three-hour live-canary schedule.
    • Simplified public smoke and release checks by removing unused scanning steps.
    • Adjusted timeout handling for integration tests without changing timeout values.
    • Changes to test configuration now trigger the exhaustive test plan.
  • Documentation

    • Updated workflow and live-canary documentation to reflect available lanes and scheduling.
    • Removed obsolete provider-matrix execution instructions.

Walkthrough

The live-canary workflow no longer schedules or runs the provider-matrix lane. Runner dispatch, documentation, workflow contracts, and timeout filters reflect the remaining lanes. Changes to .config/nextest.toml now select exhaustive test coverage.

Changes

CI execution updates

Layer / File(s) Summary
Remove provider-matrix workflow execution
.github/workflows/live-canary.yml
The weekly schedule, dispatch lane, provider-matrix job, related setup steps, and report dependency were removed.
Align live-canary runner lanes
scripts/live-canary/run.sh
public-smoke no longer defaults to zizmor_scan. The provider-matrix lane and diagnostic entry were removed.
Update contracts and documentation
scripts/ci/ws12_workflow_contracts.py, docs/internal/live-canary.md, .github/workflows/README.md, .config/nextest.toml
Contracts and documentation describe the remaining schedule and lanes. Extended timeout filters no longer match the removed zizmor tests.
Route nextest changes to exhaustive plans
scripts/ci/reborn_pr_test_plan.py, scripts/ci/test_reborn_pr_test_plan.py
Changes to .config/nextest.toml select an exhaustive plan. A regression test covers the selected partitions and integration lanes.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers: benkurrek

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and accurately describes removal of the provider-matrix lanes and zizmor scan.
Description check ✅ Passed The description follows the repository template and documents scope, validation, risks, security, rollback, and review follow-through.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the contributor: core 20+ merged PRs label Aug 10, 2026
@ironloopai

ironloopai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown
Contributor

🧭 IronLoop Run · Review

This comment updates in place as the Run moves through its stages.

⬛ Final result · Stopped

🟨 Queued → 🟦 Working → ⬛ Stopped

Automatic trigger · attempt 1 of 3 · stopped after 4m 56s

IronLoop stopped because the pull request target branch or head changed while this Run was active.

Run details

Run: 38db38e5-5d23-4f8b-9d1f-0932b0dcac60
Base: main at cd38d88
Head: remove-canary-ci at ec4e6bd
Created: 2026-08-10 07:34 UTC
Updated: 2026-08-10 07:39 UTC

.config/nextest.toml is read by every Tests (Reborn) lane, so the
fail-closed planner arm raised 'unclassified pull-request path' on any
PR touching it, skipping all downstream Reborn lanes. Widen it to the
exhaustive plan like crate deletions.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/ci/test_reborn_pr_test_plan.py`:
- Around line 918-935: Expand test_nextest_config_widens_to_exhaustive_plan to
assert every field returned by _full_plan, including package buckets,
run_group_tests, run_qa_replay, run_sandbox_docker, and coverage_mode, in
addition to the existing exhaustive-plan fields. Use the canonical exhaustive
values so regressions in any part of the plan fail the test.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 94e6e1e7-ffee-4a06-938c-5f0b1888ddc3

📥 Commits

Reviewing files that changed from the base of the PR and between ec4e6bd and 0c48703.

📒 Files selected for processing (2)
  • scripts/ci/reborn_pr_test_plan.py
  • scripts/ci/test_reborn_pr_test_plan.py

Comment on lines +918 to +935
def test_nextest_config_widens_to_exhaustive_plan(self) -> None:
"""`.config/nextest.toml` is runner config every test lane reads.

Regression for the provider-matrix retirement PR: deleting the dead
`live_tests::zizmor_scan*` overrides from `.config/nextest.toml` made
the fail-closed arm raise `unclassified pull-request path`, which
failed `Detect Reborn test scope` and skipped every downstream Reborn
lane. The file is read by every `Tests (Reborn)` lane, so no narrow
lane can exercise a change to it; it must NOT go to static control
(whose membership rule is "no Reborn test lane reads the file").
Widening to the exhaustive plan is the safe resolution — a superset
can never under-select.
"""
plan = self.plan("pull_request", [".config/nextest.toml"])
self.assertEqual(plan["mode"], "full")
self.assertEqual(plan["root_partitions"], [0, 1, 2, 3])
self.assertEqual(plan["integration_lanes"], [0, 1, 2, 3, "groups"])
self.assertIn("nextest runner config changed", plan["reasons"][0])

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Pin the complete exhaustive-plan contract.

The test checks only mode, root partitions, integration lanes, and the reason. It can still pass if package buckets, run_group_tests, run_qa_replay, run_sandbox_docker, or coverage_mode regress.

Add assertions for all fields that make _full_plan exhaustive.

Proposed assertions
         plan = self.plan("pull_request", [".config/nextest.toml"])
         self.assertEqual(plan["mode"], "full")
+        self.assertEqual(plan["changed_packages"], [])
+        self.assertEqual(plan["affected_packages"], self.canonical)
+        self.assertEqual(
+            plan["crate_buckets"],
+            [{"name": "selected", "packages": self.canonical}],
+        )
         self.assertEqual(plan["root_partitions"], [0, 1, 2, 3])
         self.assertEqual(plan["integration_lanes"], [0, 1, 2, 3, "groups"])
+        self.assertTrue(plan["run_group_tests"])
+        self.assertTrue(plan["run_qa_replay"])
+        self.assertTrue(plan["run_sandbox_docker"])
+        self.assertEqual(plan["coverage_mode"], "full")
         self.assertIn("nextest runner config changed", plan["reasons"][0])
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
def test_nextest_config_widens_to_exhaustive_plan(self) -> None:
"""`.config/nextest.toml` is runner config every test lane reads.
Regression for the provider-matrix retirement PR: deleting the dead
`live_tests::zizmor_scan*` overrides from `.config/nextest.toml` made
the fail-closed arm raise `unclassified pull-request path`, which
failed `Detect Reborn test scope` and skipped every downstream Reborn
lane. The file is read by every `Tests (Reborn)` lane, so no narrow
lane can exercise a change to it; it must NOT go to static control
(whose membership rule is "no Reborn test lane reads the file").
Widening to the exhaustive plan is the safe resolution — a superset
can never under-select.
"""
plan = self.plan("pull_request", [".config/nextest.toml"])
self.assertEqual(plan["mode"], "full")
self.assertEqual(plan["root_partitions"], [0, 1, 2, 3])
self.assertEqual(plan["integration_lanes"], [0, 1, 2, 3, "groups"])
self.assertIn("nextest runner config changed", plan["reasons"][0])
def test_nextest_config_widens_to_exhaustive_plan(self) -> None:
"""`.config/nextest.toml` is runner config every test lane reads.
Regression for the provider-matrix retirement PR: deleting the dead
`live_tests::zizmor_scan*` overrides from `.config/nextest.toml` made
the fail-closed arm raise `unclassified pull-request path`, which
failed `Detect Reborn test scope` and skipped every downstream Reborn
lane. The file is read by every `Tests (Reborn)` lane, so no narrow
lane can exercise a change to it; it must NOT go to static control
(whose membership rule is "no Reborn test lane reads the file").
Widening to the exhaustive plan is the safe resolution — a superset
can never under-select.
"""
plan = self.plan("pull_request", [".config/nextest.toml"])
self.assertEqual(plan["mode"], "full")
self.assertEqual(plan["changed_packages"], [])
self.assertEqual(plan["affected_packages"], self.canonical)
self.assertEqual(
plan["crate_buckets"],
[{"name": "selected", "packages": self.canonical}],
)
self.assertEqual(plan["root_partitions"], [0, 1, 2, 3])
self.assertEqual(plan["integration_lanes"], [0, 1, 2, 3, "groups"])
self.assertTrue(plan["run_group_tests"])
self.assertTrue(plan["run_qa_replay"])
self.assertTrue(plan["run_sandbox_docker"])
self.assertEqual(plan["coverage_mode"], "full")
self.assertIn("nextest runner config changed", plan["reasons"][0])
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/ci/test_reborn_pr_test_plan.py` around lines 918 - 935, Expand
test_nextest_config_widens_to_exhaustive_plan to assert every field returned by
_full_plan, including package buckets, run_group_tests, run_qa_replay,
run_sandbox_docker, and coverage_mode, in addition to the existing
exhaustive-plan fields. Use the canonical exhaustive values so regressions in
any part of the plan fail the test.

@serrrfirat
serrrfirat enabled auto-merge August 10, 2026 07:58
@serrrfirat
serrrfirat added this pull request to the merge queue Aug 10, 2026
Merged via the queue into nearai:main with commit 226bd49 Aug 10, 2026
58 checks passed
@serrrfirat
serrrfirat deleted the remove-canary-ci branch August 10, 2026 08:51
Kampouse pushed a commit to Kampouse/ironclaw that referenced this pull request Aug 13, 2026
* ci(canary): remove provider-matrix lanes and zizmor scan

* fix(ci): classify nextest config as exhaustive-plan change

.config/nextest.toml is read by every Tests (Reborn) lane, so the
fail-closed planner arm raised 'unclassified pull-request path' on any
PR touching it, skipping all downstream Reborn lanes. Widen it to the
exhaustive plan like crate deletions.
Kampouse pushed a commit to Kampouse/ironclaw that referenced this pull request Aug 13, 2026
* ci(canary): remove provider-matrix lanes and zizmor scan

* fix(ci): classify nextest config as exhaustive-plan change

.config/nextest.toml is read by every Tests (Reborn) lane, so the
fail-closed planner arm raised 'unclassified pull-request path' on any
PR touching it, skipping all downstream Reborn lanes. Widen it to the
exhaustive plan like crate deletions.
l3ocifer pushed a commit to l3ocifer/frick-ironclaw that referenced this pull request Sep 3, 2026
* ci(canary): remove provider-matrix lanes and zizmor scan

* fix(ci): classify nextest config as exhaustive-plan change

.config/nextest.toml is read by every Tests (Reborn) lane, so the
fail-closed planner arm raised 'unclassified pull-request path' on any
PR touching it, skipping all downstream Reborn lanes. Widen it to the
exhaustive plan like crate deletions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows scope: docs Documentation size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants