Skip to content

Fix consumer Gate summary publication - #3623

Merged
stranske merged 2 commits into
mainfrom
codex/issue-3621-gate-summary-alias
Sep 29, 2026
Merged

stranske merged 2 commits into
mainfrom
codex/issue-3621-gate-summary-alias

Conversation

@stranske

@stranske stranske commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Source: Issue #3621

Closes #3621

Automated Status Summary

Scope

Manifest sync to stranske/Portable-Alpha-Extension-Model#2318 exposed a source-owned fork-status bug. Consumer Gate workflows report the summary job as gate-summary, while .github/scripts/gate-fork-status-publication.js currently recognizes only summary. A successful trusted fork Gate can therefore be published as Gate / gate=error even though the exact run completed successfully.

Context for Agent

Related Issues/PRs

Tasks

  • Update .github/scripts/gate-fork-status-publication.js so publicationState accepts the exact supported Gate summary job names (summary and gate-summary) while still requiring exactly one matching completed summary job.
  • Mirror the source fix in templates/consumer-repo/.github/scripts/gate-fork-status-publication.js without changing .github/sync-manifest.yml path ownership.
  • Extend tests/workflows/test_gate_fork_status_publication.py with consumer-style gate-summary success coverage and fail-closed coverage for missing or ambiguous summary jobs.
  • Document in the pull request that the source repair is intended to unblock the next manifest refresh of stranske/Portable-Alpha-Extension-Model#2318.

Acceptance criteria

  • python -m pytest tests/workflows/test_gate_fork_status_publication.py -q --no-cov exits 0 and reports passing cases for both summary and gate-summary; removing gate-summary support makes the named consumer-style regression test fail.
  • node --check .github/scripts/gate-fork-status-publication.js and node --check templates/consumer-repo/.github/scripts/gate-fork-status-publication.js both exit 0, and cmp -s .github/scripts/gate-fork-status-publication.js templates/consumer-repo/.github/scripts/gate-fork-status-publication.js exits 0.
  • python scripts/validate_template_completeness.py exits 0; capture the command results in the pull request validation section.
  • The ready-for-review Workflows pull request references stranske/Portable-Alpha-Extension-Model#2318 and identifies .github/scripts/gate-fork-status-publication.js as the managed consumer path for the follow-on sync.

Summary by CodeRabbit

  • Bug Fixes
    • Workflow status reporting now recognizes exactly one completed job named summary or gate-summary when determining whether results are ready for publication.
    • Missing or duplicate summary jobs, and names with different capitalization, spacing, prefixes, or suffixes, are treated as incomplete.

@stranske stranske added agent:codex Agent-created issues from Codex agents:keepalive Use to initiate keepalive functionality with agents autofix Opt-in automated formatting & lint remediation agent:retry Add to trigger agent retry after rate limit or pause codex codex-automation agent:auto Delegates agent routing to the auto-delegation policy labels Sep 29, 2026
@stranske
stranske deployed to agent-standard September 29, 2026 14:15 — with GitHub Actions Active
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T14:18:30.455988Z ff4a1bb PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: stranske/Workflows/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Essentials

Run ID: a91e681c-8685-4009-ae31-5729e9d720bf

📥 Commits

Reviewing files that changed from the base of the PR and between ff4a1bb and 58032ca.

📒 Files selected for processing (1)
  • docs/keepalive/FORK_GATE_STATUS_PUBLICATION.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


📝 Walkthrough

Walkthrough

The fork-status publisher now recognizes the exact job names summary and gate-summary. Tests cover successful publication for both names and reject missing, duplicate, or altered names.

Changes

Gate status publication

Layer / File(s) Summary
Summary name matching and validation
.github/scripts/gate-fork-status-publication.js, templates/consumer-repo/.github/scripts/gate-fork-status-publication.js, tests/workflows/test_gate_fork_status_publication.py, docs/keepalive/FORK_GATE_STATUS_PUBLICATION.md
Both publisher copies match the exact names summary and gate-summary. Tests cover both supported names, invalid or duplicate matches, successful publication, and byte identity between the scripts. The documentation describes the accepted names and completion requirements.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 58032

The Gate publisher now supports both summary and gate-summary while retaining fail-closed validation. No material merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 11 functions across 3 files. (1 skipped: 1… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: fixing consumer Gate summary status publication.
Linked Issues check ✅ Passed The changes satisfy the coding requirements in #3621. Both publisher copies use the exact case-sensitive allowlist summary and gate-summary. The existing one-summary, completed-job, exact-run, exa…
Out of Scope Changes check ✅ Passed The whole-PR diff is limited to the two publisher copies, focused regression tests, and related documentation. The documentation supports the linked objective. No manifest ownership change, generated …
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 11 functions across 3 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@stranske
stranske deployed to agent-standard September 29, 2026 14:16 — with GitHub Actions Active
@stranske
stranske deployed to agent-standard September 29, 2026 14:16 — with GitHub Actions Active
@agents-workflows-bot

Copy link
Copy Markdown
Contributor

🤖 Keepalive Loop Status

PR #3623 | Agent: Codex | Iteration 0/12

Current State

Metric Value
Iteration progress [----------] 0/12
Action run (agent-run-skipped)
Agent status ✅ ALL TASKS COMPLETE
Gate unknown
Tasks 8/8 complete
Timeout 45 min (default)
Timeout usage 0m elapsed (2%, 45m remaining)
Keepalive ✅ enabled
Autofix ❌ disabled

Agent Delegation (auto mode)

Field Value
Selected agent Codex
Reason initial-selection-label
Delegation source static

Last Codex Run

Result Value
Status ⏭️ Skipped
Reason agent-run-skipped

To retry:

  • Add the agent:retry label, OR
  • Wait for conditions to resolve (e.g., Gate success, labels present)

🔍 Failure Classification

| Error type | infrastructure |
| Error category | transient |
| Suggested recovery | Capture logs and context; retry once and escalate if the issue persists. |

@agents-workflows-bot

agents-workflows-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor
Keepalive Work Log (click to expand)
# Time (UTC) Agent Action Result Files Tasks Progress Commit Gate
0 2026-09-29 14:16:51 Codex run (agent-run-skipped) retry skipped — 0 8/8 — —
0 2026-09-29 14:17:42 Codex wait (gate-cancelled-transient) retry skipped — 0 8/8 — cancelled
0 2026-09-29 14:22:44 Claude run (agent-run-skipped) retry skipped — 0 8/8 — success
0 2026-09-29 14:35:04 Codex run (agent-run-skipped) retry skipped — 0 8/8 — success
0 2026-09-29 14:50:03 Claude run (agent-run-skipped) retry skipped — 0 8/8 — success
0 2026-09-29 14:58:05 Claude fix (agent-run-skipped) retry skipped — 0 8/8 — —
0 2026-09-29 15:03:52 Codex run (agent-run-skipped) skipped — 0 8/8 — success

@stranske-keepalive

stranske-keepalive Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Keepalive Loop Status

PR #3623 | Agent: Codex | Iteration 0/12

Current State

Metric Value
Iteration progress [----------] 0/12
Action run (agent-run-skipped)
Agent status ✅ ALL TASKS COMPLETE
Gate success
Tasks 8/8 complete
Timeout 45 min (default)
Timeout usage 6m elapsed (15%, 39m remaining)
Keepalive ✅ enabled
Autofix ❌ disabled

Agent Delegation (auto mode)

Field Value
Selected agent Codex
Reason cooldown (5 rounds remaining)
Delegation source static

Last Codex Run

Result Value
Status ⏭️ Skipped
Reason agent-run-skipped

To retry:

  • Add the agent:retry label, OR
  • Wait for conditions to resolve (e.g., Gate success, labels present)

🔍 Failure Classification

| Error type | infrastructure |
| Error category | transient |
| Suggested recovery | Capture logs and context; retry once and escalate if the issue persists. |

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ff4a1bbb55

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/scripts/gate-fork-status-publication.js
@agents-workflows-bot

Copy link
Copy Markdown
Contributor

🤖 Bot Comment Handler

  • Agent: codex
  • Bot comments to address: 1
  • Exact PR head: ff4a1bb
  • Controller part: 1 of 1

The agent is reassigned only after every controller part is durable on the PR.
Each entry links to the authoritative review thread containing its full context.

Active thread controller

  • PRRT_kwDOQprj9M6nJdo- — .github/scripts/gate-fork-status-publication.js:5
    • Fix consumer Gate summary publication #3623 (comment)
    • Acceptance criterion: P2 Badge Document both trusted summary-job names Update docs/keepalive/FORK_GATE_STATUS_PUBLICATION.md:28-31, which still states that completed runs must contain exactly one summary job. After this change, a gate-summary job is equally trusted, so the documente...

Required outcome

  1. Inspect every listed active thread on the exact head.
  2. Implement and validate any still-valid criterion; do not make no-op edits.
  3. Reply with exact-head evidence and request a thread-specific reviewer disposition.
  4. Never self-resolve reviewer threads.
  5. Do not report completion while any listed thread remains active; a generic top-level review is insufficient.

Document that the trusted summary allowlist accepts exactly one completed
summary or gate-summary job so the security contract matches the helper.

Co-authored-by: Cursor <cursoragent@cursor.com>
@stranske

Copy link
Copy Markdown
Owner Author

Addressed the P2 documentation thread on head 58032ca: docs/keepalive/FORK_GATE_STATUS_PUBLICATION.md now documents the case-sensitive allowlist for exactly one completed summary or gate-summary job and clarifies branch-protection naming vs publisher trust. Local pytest tests/workflows/test_gate_fork_status_publication.py -q --no-cov — 25 passed.

@stranske
stranske deployed to agent-standard September 29, 2026 14:44 — with GitHub Actions Active
@stranske

Copy link
Copy Markdown
Owner Author

Exact-head check-presence disposition for 58032ca4bacbfd845e947c289381978747d2f549: the Orchestrator check reporter is repo-specific, so I applied its frequency comparison to Workflows as an advisory check and inspected each of its 23 reported absences against the prior merged PR #3618. The absent names are from event-driven Agents Auto-Pilot, Agents Bot Comment Handler, Agents Keepalive Loop, CI Autofix Loop, Create Issue from Verification, Create New PR from Verification, and Agents Verifier runs: Cleanup, Evaluate keepalive loop, Handle bot comments, Keepalive next task (Claude/Codex/Cursor/Gemini), Mark agent running, Record autofix dispatch completion, Record keepalive dispatch completion, Resolve Context, Resolve PR, Review agent progress alignment, Update keepalive summary, Verify secrets available, auto-pilot, autofix, check, create-issue, create-new-pr, format-pause-wakeup, gate, and verifier / Run post-merge verifier. These workflows are not the PR-head Gate/reusable CI reporters for this PR; the post-merge verifier is deliberately later. The exact head has Gate / gate, Gate summary, Python 3.12/3.13, lint, format, mypy, script tests, Selftest CI, security, and manifest checks reported successful; no active non-outdated review threads were found. This disposition explains those absences only; any new head needs a fresh gate.

@stranske
stranske merged commit 094558f into main Sep 29, 2026
55 checks passed
@stranske
stranske deleted the codex/issue-3621-gate-summary-alias branch September 29, 2026 14:56
@stranske stranske added the verify:compare Compare multiple LLM evaluations label Sep 29, 2026
@stranske
stranske deployed to agent-standard September 29, 2026 14:57 — with GitHub Actions Active
@stranske
stranske deployed to agent-standard September 29, 2026 14:57 — with GitHub Actions Active
@stranske
stranske deployed to agent-standard September 29, 2026 14:57 — with GitHub Actions Active
@github-actions

Copy link
Copy Markdown
Contributor

Provider Comparison Report

Provider Summary

Provider Model Verdict Confidence Summary
openai gpt-5.6-terra PASS 97% The implementation correctly recognizes the two explicitly supported Gate summary job names, summary and gate-summary, while preserving fail-closed behavior when there is not exactly one matchi...
anthropic claude-sonnet-5 CONCERNS N/A Review the PR manually or re-run once LLM credentials are available.
📋 Full Provider Details (click to expand)

openai

  • Model: gpt-5.6-terra
  • Verdict: PASS
  • Confidence: 97%
  • Scores:
    • Correctness: 10.0/10
    • Completeness: 10.0/10
    • Quality: 9.0/10
    • Testing: 9.0/10
    • Risks: 9.0/10
  • Summary: The implementation correctly recognizes the two explicitly supported Gate summary job names, summary and gate-summary, while preserving fail-closed behavior when there is not exactly one matching summary job or any job is incomplete. The source and consumer-template scripts receive the same change, preserving managed-path parity. The expanded workflow tests cover consumer-style gate-summary success plus missing and ambiguous summary-job failure cases, matching the requested regression and fail-closed coverage. The Set-based allowlist is clear, constrained to exact supported names, and introduces no meaningful security, compatibility, or performance risk.

anthropic

  • Model: claude-sonnet-5
  • Verdict: CONCERNS
  • Confidence: N/A
  • Summary: Review the PR manually or re-run once LLM credentials are available.
  • Concerns:
    • LLM evaluation could not run.
  • Error: LLM invocation failed: Error code: 400 - {'type': 'error', 'error': {'type': 'invalid_request_error', 'message': 'You have reached your specified API usage limits. You will regain access on 2026-10-01 at 00:00 UTC.'}, 'request_id': 'req_011CfXwBsdpAkDwKfTndtEaH'}

Agreement

  • No clear areas of agreement.

Disagreement

Dimension openai anthropic
Verdict PASS CONCERNS

Unique Insights

  • openai: The implementation correctly recognizes the two explicitly supported Gate summary job names, summary and gate-summary, while preserving fail-closed behavior when there is not exactly one matching summary job or any job is incomplete. The source and consumer-template scripts receive the same c...
  • anthropic: LLM evaluation could not run.

🔍 LangSmith Traces

@stranske stranske mentioned this pull request Sep 29, 2026
3 of 11 tasks

This branch was successfully deployed

1 active deployment
agent-standard — 58032ca4 Deployed Sep 29, 2026 by stranske via Update keepalive summary #20705
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent:auto Delegates agent routing to the auto-delegation policy agent:codex Agent-created issues from Codex agent:retry Add to trigger agent retry after rate limit or pause agents:keepalive Use to initiate keepalive functionality with agents autofix Opt-in automated formatting & lint remediation codex codex-automation verify:compare Compare multiple LLM evaluations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[sync-review] Fix upstream manifest-synced paths blocking stranske/Portable-Alpha-Extension-Model#2318

1 participant