ci: wait for no-mistakes attestation convergence - #81
Merged
Merged
Conversation
This was referenced Aug 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Fix the no-mistakes CI attestation feedback loop observed on 2026-08-28 on withally/firstmate PRs #79 and #80, where the required check named PR must be raised via no-mistakes compares the current PR head SHA with head_sha in the hidden no-mistakes-pipeline-attestation:v1 PR-body comment, fails within seconds after each pipeline auto-fix push, and causes the CI step to treat its own transient stale attestation as a failure and push another repair even though real checks are green. Reproduce first by fetching and reading the require-no-mistakes action source at pinned commit 32d396ac0f29135daf7fcb9964aba9d5f4e796d6, confirming exactly what it compares and emits on mismatch, and inspecting PR #80 check-run history through GitHub API explicitly against withally/firstmate; record that evidence in the PR body. Implement the smallest robust change in .github/workflows/no-mistakes-required.yml: re-fetch live PR body and head and wait/retry every 60 seconds for a bounded window justified by observed push-to-attestation latency before final failure, then invoke the pinned action once with the freshest facts. A merely behind attestation must converge to green, while a PR with no valid attestation or a permanently stale attestation must still fail at the end. Preserve cancel-in-progress concurrency for fresh synchronize pushes so stale head-change runs are cancelled. Add or update a behavior test only if the repository workflow-testing pattern supports it; tests must exercise executable behavior rather than source bytes. Otherwise document manual verification. Draft concise text under an Upstream follow-up PR-body section for kunchenguid/no-mistakes asking its CI step to ignore its own attestation check while converging; do not open the upstream issue. Keep the change small and add no new script unless the one-owner rule demands it. The measured evidence is that the pinned verifier reports Pipeline attestation head_sha does not match the current PR head and names both SHAs; PR #80 passed on attested/current c8e5ed2, then synchronize runs failed on d7e26f4, 3933dba, and ae15ed5 in 6 to 10 seconds while the body remained attested to c8e5ed2. The initial c8e5ed2 commit-to-compliant-check lag was five minutes, so use a ten-minute retry window as two-times margin. The repository test pattern covers the shared verifier but cannot execute delayed GitHub workflow events without source-parsing tests, so validate the actual inline script manually with mocked live PR responses for stale-to-current convergence, permanently missing or empty attestation, matching fast path, and transient API error retry, plus run pinned action tests, actionlint, changed-file tests, and coverage. Ship through no-mistakes without --yes. Known self-hosting hazard: this PR is governed by the pre-fix workflow until merge. Once the pipeline CI step is running, if the only red check is PR must be raised via no-mistakes while all real checks are green, do not start another repair round; report done with the PR URL, real checks green, attestation stale, and stop so Firstmate can merge on real-CI-green. Do not run any Herdr lifecycle commands; the brief has no herdr-lab authorization.
What Changed
Risk Assessment
✅ Low: The change is a bounded read-only PR refresh with a ten-minute retry window, preserves concurrency cancellation, and correctly delegates the final decision to the pinned verifier.
Testing
Stale-to-current convergence, bounded permanent-stale/missing/empty failures, matching fast path, transient API retry, workflow semantics, pinned verifier behavior, and coverage inventory all passed. Actionlint was not run because this assigned phase prohibits linters/static analysis. No UI evidence was applicable; no worktree files were modified.
Evidence: Inline workflow behavior
Source: Inline workflow behavior
Evidence: Pinned verifier tests
Source: Pinned verifier tests
Evidence: PR #80 API history
Source: PR #80 API history
Evidence: Workflow structure and coverage
Source: Workflow structure and coverage
Evidence: Pinned action contract
Source: Pinned action contract
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ **Review** - passed
✅ No issues found.
✅ **Test** - passed
✅ No issues found.
bash tests/fm-no-mistakes-required.test.shRuby/Psych semantic workflow validationMocked execution of the exact inline retry script through the pinned verifierbin/fm-test-run.sh --check-coverageExplicit GitHub API reads forwithally/firstmatePR #80 and four supplied SHAsPinned action source reads at32d396ac0f29135daf7fcb9964aba9d5f4e796d6🔧 **Document** - 1 issue found → auto-fixed ✅
🔧 Fix: Document attestation convergence and upstream follow-up
✅ Re-checked - no issues remain.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.