fix(ci): resync actions.lock, restore codeql hold, retire dead CI jobs with a written determination (#67) - #72
Merged
Conversation
…s with a written determination (#67) Root cause of the outage this issue sits on top of: four consecutive merges after #66 (#68, #69, #70, #71) rewrote uses: refs without touching .github/workflows/actions.lock. At main=d50a857 every push-triggered workflow was startup_failure with zero jobs, including the Lock Sync Gate itself and the CI workflow that would have run the two checks in #67. Changes: - actions.lock: resynchronised and transitively closed (check-lock-sync.sh exit 0). ci.yml entries pruned to what it uses; haskell-actions/setup v2.12.1 recorded; unreferenced alias records pruned. - codeql.yml, hypatia-scan.yml: codeql-action re-pinned to b96794f (true v4.38.0), restoring the estate hold #64 set and #68 re-asserted. The '# v4.38.0' comment Dependabot left beside the 4.38.1 SHA was false. - dependabot.yml: ignore glob corrected to 'github/codeql-action*'. The bare name never matched the /init, /analyze, /upload-sarif subpath dependency names Dependabot tracks, which is how #69 bumped straight through the hold. Weekly cadence + open-PR limit per estate DEPENDABOT-POLICY. - ci.yml: keep rust-core; drop the duplicate workflow-lock job, which ran from inside a workflow GitHub refuses to start on exactly the fault it checked. lock-sync-gate.yml (no uses:) is the authoritative gate. - docs/ci/CHECK-DETERMINATIONS.adoc: ledger. core-fill-tests and extension-build are RETIRED (their deno tasks were deleted by #43 a month before #66; red on main since; coverage subsumed by rust-core). Nothing was muted. Review date 2026-12-27. - TEST-NEEDS.adoc, TOPOLOGY.adoc, CHANGELOG.adoc: stop describing a Deno/Jest pipeline that does not exist. Closes #67 Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…used triggering actor Run annotations (web page only; not in REST) separate the two classes: 'Invalid lockfile ... could not be validated' -> lock drift (fixed here) 'Actor is not allowed to trigger Actions workflows' -> every run whose triggering actor is arena-ai-coding-agent[bot], including a workflow with no uses: and a verified-clean lock (run 36295605950). All 9 push runs at d50a857 and all 6 PR runs on this branch are the second class; the 3 startup failures at a0e8674 (actor hyperpolymath) are the first. Owner-side; same signature as wordpress-tools#96 and statistikles#112. rust-core's row is downgraded to 'fixed -- verification pending an owner-actor run': it has never executed, and it is not green until it has. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #67.
What #67 asked, and the answers
maintoo?core-fill-testsdeno.json, a month before #66. Its task wascargo test … fill_blocks_, a strict subset of therust-corejob.extension-buildNeither was in a required-check set (the repo's rulesets have no
required_status_checksrule). Nothing was muted: nocontinue-on-error, no demotion, and the full ledger with a review date is indocs/ci/CHECK-DETERMINATIONS.adoc.The larger thing underneath it
At
main= d50a857, all nine push-triggered workflows werestartup_failure, jobs=0 — including the Lock Sync Gate and the CI workflow that would run any check at all. Four consecutive merges after #66 rewroteuses:refs without touchingactions.lock:1c5b675(= v4.38.1, the held version) → killedcodeql.yml,hypatia-scan.yml. It got through the hold because the ignore wasgithub/codeql-action, which does not match the/init,/analyze,/upload-sarifsubpath names Dependabot tracks. Merged with the gate red.casket-pages.yml. Merged with the gate red.ci.ymljobs, leaving stalesetup-deno/wasm-pack-actionlock entries → killedci.yml. By then the gate was already dead from chore(deps): bump the actions group with 3 updates #69/chore(deps): bump haskell-actions/setup from 2.12.0 to 2.12.1 in the actions group #70, so nothing could flag it.Changes
actions.lockresynchronised and transitively closed —scripts/check-lock-sync.shexits 0 on all four clauses.codeql.yml/hypatia-scan.yml: re-pinned tob96794f(true v4.38.0), restoring the hold fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold (estate-wide startup_failure) #64 set and ci: re-pin codeql-action to the true v4.38.0 commit #68 re-asserted. The# v4.38.0comment Dependabot left next to the 4.38.1 SHA was false; it is now true.dependabot.yml: ignore globgithub/codeql-action*(estate-canonical form fromhyperpolymath/standards), weekly cadence,open-pull-requests-limit: 2, header explaining the lock contract.ci.yml:rust-corekept; the duplicateworkflow-lockjob dropped — it ran inside a workflow GitHub refuses to start on exactly the fault it checked, so it could never report.lock-sync-gate.yml(nouses:) is the authoritative gate.docs/ci/CHECK-DETERMINATIONS.adoc: the ledger, root-cause table, standing rules, review date 2026-12-27.TEST-NEEDS.adoc,TOPOLOGY.adoc,CHANGELOG.adoc: stop describing a Deno/Jest pipeline that does not exist.Verification
scripts/check-lock-sync.sh→actions.lock is in sync and transitively closed(run locally with gawk).rust-corehas never had a run that reached execution (every priorci.ymlrun was a Deno failure or a startup failure), and this sandbox cannot reach crates.io, so this PR's checks are the first real run. Ifrust-coreis red here, that is a genuine finding about the crate and I will fix it in this PR rather than merge over it.Owner action that this PR cannot do (needs admin)
Add
actions.lock is in sync with the workflow YAMLandRust core (tests, formatting, lint)as required status checks onmain. #69 and #70 were merged by hand with the gate red; without a required-check rule the standing rule "never merge over a red gate" is a convention, not an enforcement. This is the piece that makes the fix permanent.