fix(codeql): wake required jobs with the exchanged target app token - #2040
seonghobae wants to merge 203 commits into
Conversation
No workflow ran `tests/` on an unfiltered `main` push. Verified directly: - `agent-review-runtime-quality-ci.yml` has only a `pull_request` trigger (no `push:` key at all) with a narrow paths list. - `opencode-review-dispatch.yml` triggers solely on `repository_dispatch: types: [opencode-review]`. - `trusted-uv-materializer-quality-ci.yml` does run on `push: branches: [main]` but filters to the materialize/uv surface. - Seven workflows do push to main unfiltered (security scanners, SBOM, scorecard, secret-scan, the merge scheduler) and none of them run `tests/`. So merging a change to, say, `pr_review_merge_scheduler_core.py` or `opencode-review.yml` triggered no full-suite run, a suite-breaking merge landed silently on `main`, and the breakage first appeared as a red check on the next unrelated pull request. That is the failure mode behind #1823, #1826, #1828, #1892, and #1895, and behind the repair PRs #1829, #1874, and #1883. The new workflow deliberately carries no `paths` filter, since the point is to catch merges no path list anticipated. It is not in the organization required-workflow ruleset and is not injected into sibling repositories, so it costs one runner slot per `main` push in this repository only; successive pushes coalesce through its concurrency group instead of stacking. Root cause found by a peer session; this is the prescription half, kept separate from that session's documentation of the gap. actionlint: clean. Full suite with this file present: 2883 passed, 1 skipped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
A read-only Codex audit (a different model family, run per AGENTS.md's verification discipline) caught two claims that were broader than the evidence: - "Every other workflow that runs the full suite is either PR-only or carries a narrow paths filter" missed `repository-metadata-reconcile.yml`, which runs an unrestricted `pytest -q` on an hourly schedule. That does not contradict this workflow's reason to exist — a schedule is not a push, so a broken merge still sits undetected until the schedule fires — but the sweeping phrasing was wrong. - The materializer workflow does not watch "only the materialize/uv surface": its push paths also cover `tests/conftest.py`, `pyproject.toml`, the tooling requirements lock, and the repository branch-coverage tests. The same audit confirmed the two things that would have made this gate inert if wrong: `coverage report` enforces `fail_under = 100` from pyproject.toml without the flag (coverage 7.15.4 exits 2 below threshold), and no-argument `interrogate` reads `fail-under = 100` and the `tests` exclusion from the same file (interrogate 1.7.0). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…e gate -W error made the whole suite reject every warning, which is what this branch set out to buy. It also promoted PytestUnraisableExceptionWarning, raised when a dependency's `_TemporaryFileCloser.__del__` runs during garbage collection, into a hard failure. pytest attributes an unraisable warning to whichever test happens to be executing when the collector runs, so the gate failed 11 unrelated tests (run 34024435377) and named none of them accurately. Keep -W error and exempt that one class back to a printed warning. Verified as a four-arm control on Python 3.12, so this is not a 3.14-specific behaviour: the warning is raised with no flags (1 passed, 1 warning); -W error alone turns it into a failure; this command returns it to a warning; and a UserWarning is still fatal under it, so test_full_suite_command_rejects_warnings keeps asserting what it was written to assert. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Both changelog entries kept: this branch's shared-runner quality gate stays on top as the not-yet-merged change, with #1958's dispatch-concurrency entry below it in merge order. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Changelog prepend siblings again: this branch's entry stays on top as the not-yet-merged change, with #1957's entry below it in merge order. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Fourth changelog prepend collision on this branch today; both entries kept, this branch's on top as the not-yet-merged change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Fifth changelog prepend collision today; both entries kept, this branch's on top as the not-yet-merged change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Exact-head owner repair at
Fresh exact-head hosted Checks and a qualifying independent approval remain mandatory; predecessor evidence does not transfer. @coderabbitai review |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo="ContextualWisdomLab/.github"
pr="2040"
head="652764a37fc8af032f03cbe75da84ca88aee96bb"
echo '== Pull request metadata =='
gh pr view "$pr" --repo "$repo" \
--json headRefOid,baseRefOid,isDraft,mergeable,reviewDecision,statusCheckRollup \
--jq '{headRefOid,baseRefOid,isDraft,mergeable,reviewDecision,checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'
echo '== Repair commits =='
git log --format='%H %P %s' -3 "$head"
echo '== Exact repair range =='
git diff --check e70094b3d85b2fdb54c0d24ef9a1fe0299e09237.."$head"
git diff --stat e70094b3d85b2fdb54c0d24ef9a1fe0299e09237.."$head"
git diff --name-status e70094b3d85b2fdb54c0d24ef9a1fe0299e09237.."$head"
git diff --no-ext-diff --unified=25 e70094b3d85b2fdb54c0d24ef9a1fe0299e09237.."$head" -- \
.github/workflows/codeql-scan-dispatch.yml \
tests/test_codeql_scan_dispatch_workflow_contract.py
echo '== Validation block =='
rg -n -C 30 -e 'TARGET_REPOSITORY' -e 'target outside ContextualWisdomLab' .github/workflows/codeql-scan-dispatch.yml
echo '== Relevant production-path contract assertions =='
rg -n -C 15 -i -e 'repo\.\.name' -e 'repository\.' -e '\.github' -e 'repo\.name' \
tests/test_codeql_scan_dispatch_workflow_contract.py
echo '== Reviews =='
gh api "repos/$repo/pulls/$pr/reviews?per_page=100" --paginate \
--jq '.[] | {user:.user.login,state,commit_id,submitted_at}'Length of output: 78383
The validation block now rejects a repository component that contains The contract verifies both hostile inputs fail before API access:
The contract also preserves these valid inputs:
The repair range changes only the handler workflow and its contract file. I found no new issue in this repair scope. I cannot approve the PR. It remains Draft, all current hosted checks are queued, and GitHub reports If you found this review helpful, would you consider giving us a shout-out on X? Thank you for using CodeRabbit! You are interacting with an AI system. |
seonghobae
left a comment
There was a problem hiding this comment.
Terminal Trusted uv failure 35452353616 is not a uv-materializer defect. The focused materializer suite is GREEN (108 tests, 100% statement/branch coverage), but the subsequent repository-wide pytest tests -q collection imports scripts/ci/noema_review_document.py, which requires defusedxml. This job installs only requirements-opencode-review-ci-hashes.txt; the canonical Noema document lock already owns defusedxml==0.7.1 in requirements-noema-document-ci-hashes.txt. The causal fix is to make this repository-wide quality job install both existing hash-locked requirement surfaces (and cache both), not to weaken coverage, skip Noema tests, or duplicate an unpinned dependency. I will first bind this dependency closure as a workflow-contract RED, then minimally repair the workflow.
|
Naruon consumer fresh-read found an owner-overlap repair finding on current #2040 exact The two commits after Do not drop the new #2040 evidence, but do not let #2040 become a second Trusted-uv owner either. Before #2040 can be accepted, reconcile this overlap ordinary/non-force through the canonical #1911 path: first bring #1911 onto current protected Separately, the current #2040 body correctly treats Runtime Quality as a Strix command-level RCA lane; do not mix the Trusted-uv ownership repair with speculative Strix/path-policy changes. |
|
Fresh Naruon consumer audit confirms that this branch's Trusted-uv dependency-closure delta overlaps canonical owner #1911. Current #1911 is Please converge losslessly through #1911: preserve #2040's distinct CodeQL/scheduler/runtime-quality contracts, ordinary/non-force adopt the accepted/current #1911 owner result once #1911 is reconciled to protected Current central execution pressure is still abnormal (fresh observation: 223 queued / 1 in progress, with the sole in-progress run a long-lived Strix job on protected main), so queued exact-head evidence is not a reason for a no-op wake commit or blind rerun. |
|
Fresh exact-head acceptance update (2026-09-20 KST): current head remains |
|
Lifecycle authority repair: live PR metadata had drifted to Ready ( |
|
Current exact-head CodeQL evidence has advanced beyond the PR body snapshot. Producer That source delta had previously existed on the #2106 lineage ( |
|
Fresh current-generation evidence from Required CodeQL run So there is not yet producer SARIF for this specimen and no basis to call #2352's CodeQL RED a source finding. If |
|
Read-only handoff to this lane, which owns the CodeQL dispatch/verdict files. Routed here by path ownership: this PR touches Case: late-life-anxiety-reanalysis#257 at Decisive fact, from two single GETs (no polling): job 107084906428 is That also removes a reading trap: Two more points worth stating plainly:
Where the mechanisms live, for whoever picks this up:
Suggested first check: the triggered Not verified without a hosted run: whether a The separate late-life#257 defect — the central Pingora policy rejecting a tracked DOCX as invalid UTF-8 — is fixed in #2355 and does not belong to this lane. |
Keep the repository-component boundary and the proof that a head-mutation credential actually starts workflows. The producer stays on codeql-scan-v2 with the live merge revision and top-level required jobs, and the dispatch step pages through commit statuses before treating a verdict as absent.
Current authority
Status: OPEN / Draft / Proposed / do not merge.
main@e6334e229581a918e2f22de18733b76fa65d7e71bd039185ddf8df88480971cdd3b69c38f4558609Exact-head acceptance
Fresh exact-head hosted evidence is mixed and therefore not GREEN:
35706035099: SUCCESS35706035091: SUCCESS35706035103: FAILURE.Detect Pythonand Bandit are GREEN;pip-audit (Python dependency audit)job106725528592fails atRun pip-audit (hard gate on any known vulnerability). This is a real dependency-audit gate failure and must not be suppressed or relabeled as scheduler noise. The active shared dependency owner chore(deps): bump anyio from 4.14.0 to 4.14.2 #2278 remains separate and is not assumed to be the causal fix without exact audit-log/CVE evidence.35706035119: FAILURE. Python receiver106725681922and Actions receiver106725681960each successfully read the current-head dispatch verdict and then failed atRelease runner or enforce current-head CodeQL verdict; the later coordinator106770747682obtained a runner andDispatch current-head CodeQL scancompleted SUCCESS. The earlier failed receivers did not reconcile afterward.The CodeQL sequence is a same-head reproduction of the terminal publication/reconciliation ordering defect already tracked by #1929. A later successful coordinator is not retroactive terminal acceptance for receivers that already failed.
Landing order
This PR remains a foundation prerequisite, not a consumer-side place to synthesize required statuses or rerun leaf jobs blindly. Repair the CodeQL publication/reconciliation owner, resolve the dependency-audit failure through its canonical dependency owner once causality is proved, then reacquire all exact-head required checks and an independent current-head review before normal protected merge.
No force push, destructive rebase, self-approval, review dismissal, gate weakening, source-neutral wake commit, synthetic status, or predecessor-GREEN transfer is authorized.