Skip to content

measure(actions): 재측정 필요 — inherited required-workflow rules가 기존 게이팅 분류에서 누락됨 #1928

Description

@seonghobae

2026-09-21 정정 — 게이팅 비율은 다시 측정해야 함

기존 본문의 61.3% / 71개 수치와 댓글에서 정정한 47.1% / 67개 수치는 모두 현재 권위로 쓰지 마십시오. 두 번째 정정은 기본 브랜치와 required_status_checks 판정은 고쳤지만, organization/repository ruleset의 type: workflows를 merge-blocking gate로 계산하지 않았습니다.

Fresh repository-effective ruleset reads reproduce that omission:

  • OriginWeave와 wardnet 모두 inherited organization ruleset **18156473 (CWL Central required workflows)**가 enforcement=active, ~DEFAULT_BRANCH에 적용됩니다. 이 ruleset은 pull_request rule과 7개 required workflow (opencode-review.yml, pr-review-merge-scheduler.yml, security-scan.yml, strix.yml, sast-semgrep.yml, noema-review.yml, codeql-pr.yml)를 요구합니다.
  • naruon에도 같은 organization ruleset 18156473가 effective ruleset으로 반환됩니다.
  • noema에는 별도 inherited organization ruleset **18794436 (CWL Noema central security scan)**가 enforcement=active, ~DEFAULT_BRANCH에 적용되고 security-scan.yml을 required workflow로 요구하며 bypass actor도 없습니다.

따라서 기존 분류에서 OriginWeave, wardnet, noema 등을 “중앙 리뷰가 merge를 막지 못하는 저장소”로 취급한 부분은 적어도 현재 effective ruleset과 모순됩니다. 특히 댓글의 재현식은 /rules/branches/$db에서 type=="required_status_checks"만 추출하므로 type=="workflows"를 구조적으로 놓칩니다.

다음 측정 계약

76개 저장소 전수 재측정 전에는 merge-blocking / non-blocking 비율을 새로 제시하지 않습니다. 새 측정은 저장소별 default branch를 확인하고, classic branch protection뿐 아니라 repository-effective inherited ruleset을 읽어 다음을 모두 판정해야 합니다.

  1. required_status_checks contexts;
  2. workflows rules의 required workflow 목록;
  3. ruleset enforcement, ref 조건, bypass semantics;
  4. 현재 queued-run depth와의 exact join.

현재 연결로 repository-effective inherited ruleset은 읽을 수 있으므로 “admin:org가 없어 확인도 불가능하다”는 기존 blocker 표현도 더 이상 정확하지 않습니다. 조직 ruleset 자체의 mutation은 별도 권한/소유자 판단이 필요하지만, 측정·검증은 repo-effective view로 진행할 수 있습니다.

아래 최초 측정과 댓글의 47.1% 정정은 원인 분석의 역사적 증거로 보존하되, 새 전수 결과가 나올 때까지 비율 인용에는 사용하지 마십시오.


최초 측정 — historical / superseded classifier

org 전체 대기 실행 2093건 가운데 1282건(61.3%)이 중앙 리뷰 체크가 merge를 막지 않는 저장소에서 나온다고 최초 계산했습니다.

중앙 리뷰 체크가 merge를 막는 저장소   5개 :  811건 (38.7%)
중앙 리뷰 체크를 merge gate로 보지 못한 저장소 71개 : 1282건 (61.3%)
                                    합계   : 2093건

이 최초 분류는 이후 기본 브랜치 상수 오류가 발견되어 댓글에서 47.1%로 한 차례 정정됐고, 이번 2026-09-21 검증에서 다시 required-workflow rules 누락이 확인됐습니다. 수치 자체보다 아래 운영 관찰만 역사적 근거로 남깁니다.

  • queue depth는 저장소별 actions/runs?status=queued&per_page=1의 total_count로 측정해야 하며, 필터 없는 최근-run 목록으로 깊이를 추정하면 안 됩니다.
  • PR-triggered central/repository workflows가 queue pressure의 주요 공급원이라는 관찰은 별도 event 분포로 확인됐습니다.
  • queue가 줄었다는 사실만으로 recovery를 뜻하지 않습니다. 실제 runner execution과 cancellation/skip을 구분해야 합니다.
  • merge gate를 약화하거나 리뷰 역량을 제거하는 것은 해결책으로 승인되지 않았습니다. 정확한 effective-gating 분류가 먼저입니다.

재현 방향

repo="ContextualWisdomLab/<repo>"
db=$(gh api "repos/$repo" --jq .default_branch)
gh api "repos/$repo/actions/runs?status=queued&per_page=1" --jq .total_count
gh api "repos/$repo/rulesets"
# 각 effective ruleset id를 다시 읽고 .rules[]에서
# required_status_checks와 workflows를 모두 분류한다.

최초 측정 시각은 2026-09-05 11:2x UTC입니다. queue depth는 snapshot이며, gating classification도 ruleset revision과 함께 versioned evidence로 다뤄야 합니다.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions