fix(codeql): wake required jobs with the exchanged target app token - #2040
fix(codeql): wake required jobs with the exchanged target app token#2040seonghobae wants to merge 144 commits into
Conversation
Preserve the existing four-file rerun recovery delta without emitter or concurrency policy changes. Local contract verification: 144 passed, 2 failed. Existing verdict-reader fixtures still expect the pre-pagination gh invocation; these files and the requester are unchanged from bf732f9. Workflow actionlint and diff checks passed. No hosted dispatch or push performed. Signed-off-by: Seongho Bae <me@seonghobae.me>
Match exact gh arguments and page-shaped responses. Preserve trusted-publisher assertions and exercise second-page success and failure after a full page of forged statuses. Signed-off-by: Seongho Bae <me@seonghobae.me>
Request PR state in GraphQL and preserve it in REST normalization. Reject missing state and empty or malformed heads before OpenCode dispatch, Strix dispatch, or Strix job rerun. Preserve explicit positive fixtures and add fail-closed regressions. Focused RED: 17 failed, 19 passed; final scheduler regressions: 380 passed under both normal and GITHUB_ACTIONS=true environments with warnings treated as errors. No dispatch, permission, queue, or cancellation policy changes. Signed-off-by: Seongho Bae <me@seonghobae.me>
Validate selected check, job, run, workflow and publisher before rerunning Strix. Preserve PR-target base-SHA executions through association and target-title checks; defer dispatch runs without authenticated target provenance. Local mock-only regressions: 402 passed in normal and CI environments with warnings treated as errors. No token, permission, queue or cancellation changes. Signed-off-by: Seongho Bae <me@seonghobae.me>
Signed-off-by: Seongho Bae <me@seonghobae.me>
Block terminal status publication and exact-job wake when SARIF upload does not succeed. Preserve existing finding verdicts and document the unresolved receipt boundary. Co-authored-by: Codex <codex@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Compare already-fetched live base identity with event inputs before status consumption. Keep historical verdict provenance and artifact authority as unresolved follow-ups. Co-authored-by: Codex <codex@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Supply the real base repository, ref and SHA required by the production dispatch shell. Preserve later-attempt redispatch coverage without weakening the live-base guard. Co-authored-by: Codex <codex@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Merge exact 82ca0b8 into the handoff branch. Consolidate equivalent publication regressions and SARIF documentation while preserving live-base validation and rerun fixtures. Co-authored-by: Codex <codex@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Fresh Orgmetra consumer canary reproduces the remaining ordering defect on a new exact head; this is not a request for a no-op rerun.
This is the same causal RED #2040 is intended to remove: a consumer can terminalize before authoritative dispatch publication/settlement exists. Acceptance should require an unchanged-head run where producer/dispatch terminal publication necessarily precedes consumer enforcement (or an equivalent evidence-settlement dependency), then the exact consumer shards read that bound terminal evidence and finish GREEN. Please do not convert the canary into sleep/poll/no-op retry semantics, synthetic status, or predecessor-evidence transfer. |
|
Fresh LineageWeave consumer evidence for the canonical CodeQL producer/handler owner: |
|
Second LineageWeave branch reproduces the central current-head CodeQL receipt gap. On |
seonghobae
left a comment
There was a problem hiding this comment.
P1 liveness finding from exact current-head CodeQL run 34251822255: both matrix jobs are now terminal FAILURE (actions job 102154521648, python job 102154523061), but coordinator job 102154736341 failed with CodeQL coordinator could not bind every pending language to an exact failed job. The workflow correctly declares needs: [detect-languages, analyze-head], yet the coordinator snapshots the run-jobs REST collection only once and builds required_jobs only from entries already observed as status=completed && conclusion=failure. The exact run demonstrates that needs completion and REST job-state visibility are not sufficiently atomic for that one-shot read: a language remained pending with no terminal job in the snapshot even though its matrix job subsequently/externally reads terminal failure. Treat this as owner RED, not a ConceptWeave leaf defect. A bounded repair should re-read the exact run/job set until every detected matrix name has one stable terminal rerunnable identity (or a bounded fail-closed deadline), while continuing to reject duplicate/unrelated/rewritten jobs. Add a regression where the first Jobs API snapshot exposes one matrix job as nonterminal and a later snapshot exposes both terminal failures; dispatch must neither fail prematurely nor fire against a partial required_jobs set. No manual rerun or leaf churn is warranted before the owner repair is exact-head GREEN.
|
Fresh This exact consumer therefore reaches central dispatch but does not receive an acceptable terminal/base-bound verdict. No LineageWeave-local CodeQL substitute, synthetic status, manual rerun, or gate waiver was added. Please retain this as an independent consumer acceptance case for #2040: after the owner successor reaches immutable protected main and LineageWeave pins/consumes it, these same exact-base/head language shards must resolve the central receipt to a terminal passing verdict rather than fail at enforcement. |
|
Owner-path fresh evidence only; no source/ref/state mutation from the fleet lane. Exact head New causal specimen in job RED: unchanged exact GREEN acceptance: before deriving |
|
Fresh LineageWeave consumer evidence on exact |
|
Orgmetra consumer canary, read-only owner handoff from #55. Exact consumer head |
|
Fresh Orgmetra consumer canary reproduces the same required-CodeQL settlement ordering defect on a new exact head. Consumer: |
|
AIP owner-path evidence from exact Exact required run
The current coordinator freezes Canonical repair suggestion: keep exact run/head/base/language identity fail-closed, but add a bounded settlement/re-read of the latest run jobs immediately before deriving/finalizing |
|
Fresh Orgmetra consumer canary on Exact required CodeQL run:
This exact chronology is incompatible with treating the leaf failure as an Orgmetra source/SARIF defect: both compatibility consumers can terminally enforce before their same-run dispatch publication has even begun. Orgmetra will keep #63 Draft and will not use blind rerun, sleep/polling, synthetic status, predecessor verdicts, or leaf gate weakening. Canonical repair remains here: producer/dispatch settlement must causally precede consumer enforcement (or an equivalent evidence-settlement barrier must make the authoritative evidence set complete before enforcement). |
|
Fresh LineageWeave consumer evidence from CodeQL PR run This is another immutable consumer RED for the canonical producer/handler path. Acceptance remains a terminal authenticated current-head/base-bound receipt from the owner workflow; LineageWeave has not added a substitute CodeQL workflow, synthetic status, provider/model pin, or waiver. |
|
Fresh Orgmetra consumer canary for the same publication/settlement ordering boundary; no leaf rerun or workaround was applied. Consumer:
This ordering makes the consumer fail before its same-run authoritative dispatch can settle, so the Orgmetra source head cannot causally repair it. Please retain this as an exact downstream acceptance fixture for #2040. GREEN requires the compatibility consumers to bind the settled exact base/head producer evidence rather than terminally enforcing a pre-settlement verdict. Do not solve this with sleep/polling in Orgmetra, synthetic statuses, predecessor verdict reuse, or gate weakening. |
|
Fresh LineageWeave consumer canary on exact |
|
Fresh Orgmetra downstream canary on an unchanged exact head reproduces the publication/settlement ordering defect; this is evidence for the existing canonical repair, not a request for a leaf rerun or a second writer. Consumer:
The consumer can therefore become terminal RED roughly nine minutes before its authoritative current-head producer/dispatch even starts. This is the same falsifiable ordering boundary #2040 owns: consumer enforcement can outrun producer settlement. Preserve fail-closed behavior, but settle/wake producer evidence before terminal enforcement. No sleep/polling workaround, synthetic status, predecessor verdict transfer, or Orgmetra-local workflow change was made. |
|
DiskSage downstream evidence confirms the cross-repository wake boundary on protected
This is not a DiskSage SARIF/source failure and I am not adding a leaf workaround or synthesizing a status. It is concrete cross-repository evidence for this PR's target Actions-capable wake credential boundary. Separately, this PR's own exact CodeQL run |
|
Fresh Orgmetra downstream canary reproduces the same producer/consumer settlement-ordering defect on an unchanged exact head and should be included in #2040 acceptance rather than retried locally. Consumer:
So both consumers became terminal RED roughly six minutes before their own current-head producer/dispatch was allowed to execute. This is not an Orgmetra source failure and predecessor verdicts are not transferable. Please preserve this exact run/job timing as a downstream RED fixture for the run-wide settlement/wake repair and prove the repaired central workflow on an unchanged exact consumer head. Orgmetra will not use unchanged-head reruns, sleeps/polling, synthetic statuses, or leaf workflow weakening to work around it. |
|
LineageWeave consumer evidence update. Exact predecessor |
|
Fresh downstream exact-head canary from
This reproduces the same producer/consumer settlement-ordering defect on a new immutable consumer head: both compatibility consumers exhaust/enforce before the authoritative exact-head dispatch is even scheduled to run. Orgmetra will not rerun the unchanged head, add sleeps/polling, synthesize a status, or transfer a predecessor verdict. Fresh read of this central PR still has exact head |
|
Fresh downstream canary from Required CodeQL run This is the same exact required run/head, not historical evidence: both compatibility receivers become terminal FAILURE before the producer/dispatch job begins. A bounded jobs re-read after receiver start cannot repair a receiver that has already irreversibly failed because its required producer evidence does not yet exist. Please make producer/dispatch publication an explicit prerequisite/evidence barrier before receiver terminal enforcement (or equivalent exact-run settlement architecture). Preserve repo/PR/base/head/language/required-run/SARIF/creator binding and fail closed on ambiguity/staleness; do not solve with fixed sleeps, unrelated-run polling, synthetic status, no-op pushes, PAT bypass, or predecessor verdict transfer. Add a deterministic RED where receiver execution is scheduled before dispatch and GREEN only when terminal enforcement waits for authenticated exact-run publication. |
|
Fresh LineageWeave consumer evidence, exact PR #983 head |
|
Fresh downstream canary: Orgmetra PR #96 exact head The settlement-ordering RED still reproduces on this exact consumer head:
So both consumers can terminal-fail before their exact-head producer gets a chance to run. This is not an Orgmetra source finding and I am not applying a leaf rerun/sleep, synthetic status, predecessor verdict transfer, or local gate patch. Please retain this exact run/job timing as a downstream acceptance canary for #2040's run-wide settlement owner and required-run wake/recovery contract. |
|
Fresh downstream exact-run evidence from
So both receivers became irreversible FAILURE roughly 1m43s–2m01s before the producer/dispatch job even began. This is stronger than a transient Jobs-view settlement lag: a bounded final re-read cannot repair a receiver that has already failed before authoritative same-run evidence exists. Keep the repair fail closed, but make receiver/current-head enforcement wait on an authenticated exact-run producer/publication barrier (same repository, PR/base/head, language, required-run and protected workflow identity) before terminal verdict. Do not replace this with fixed sleep, unrelated-run polling, predecessor verdict transfer, historical rerun, PAT/status synthesis or no-op push. A realistic RED should model receiver-visible state before producer dispatch exists, then the same run/job identities becoming authoritative only after dispatch/publication; GREEN must avoid terminal failure until that barrier resolves or boundedly times out/ambiguous-fails. |
|
Fresh LineageWeave consumer reproduction from #983 exact |
|
Current LineageWeave consumer confirmation on #983 exact |
|
Fresh Orgmetra #96 exact-head canary after an ordinary-forward test-docstring provenance correction (no CodeQL consumer workflow/config change): head |
|
Fresh downstream canary from Exact consumer: Central dispatch run Downstream required compatibility shards therefore remain failed even though the dispatched analyses are clean. This is useful acceptance evidence for the exchanged target-App/status-publication + exact required-job wake path here. Please preserve the exact repo/PR/head/base/required-run binding and prove an unchanged downstream head can publish the authenticated terminal status and wake/settle the exact required jobs. OriginWeave will not copy this workflow, synthesize a status, make a no-op retrigger commit, weaken CodeQL, or consume this mutable PR head as a dependency. |
|
Fresh accounting-information-platform consumer canary confirms the same P1 ordering defect on a new exact head. AIP |
|
DiskSage consumer-owner handoff, fresh 2026-09-09 KST evidence: exact #2040 head |
Owner session:
fast-mlsirm-commercializationOutcome
Canonical combined successor for the central CodeQL producer/handler cycle, exact required-run recovery, strict head-envelope validation, and stacked-PR check admission.
6706c231ab06a3c91c43fdb5b989cfcd79fff5930f07c4e60f2e02fc60a0204a4cdfb0f42efbabc2main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4dbRoot causes and repair
codeql-dispatch/<language>/<base_sha>.pr_headtypes/schema and independently supplied legacy scalars must agree.PR_REVIEW_MERGE_TOKEN→OPENCODE_APPROVE_TOKEN→ same-repository token fallback chain remains explicit and authenticated..github/main, not against the target PR synthetic merge history; unprotected, rewritten, sibling, and unrelated sources fail closed.branchesandbranches-ignorefilters.failed-mode dispatch sends one top-levelrequired_jobsauthority that the protected pre-cutover handler can consume; only whole-attemptallmode uses the nested envelope, preserving the ten-property limit.Complete carryover and non-force lineage
This head completely carries the valid commits, tests, documentation, and requirements from #1902, #2004, #2043, and #2044. They remain open Proposed predecessors; none is closed or treated as delivered before ordinary integration.
6901dd6: two-parent merge of prior fix(codeql): wake required jobs with the exchanged target app token #2040 and exact fix(codeql): recover reruns after missing dispatch verdict #1902, with the contract rejecting the remaining head-only bridge.d7bb95f: base-bound-only publication, SARIF preservation gate, and response-creator validation.91a94a2: protected-handler source authentication plus the two current-head review repairs.6706c23: protected-handler wire compatibility after exact handler run34249932036exposedSUPPLIED_REQUIRED_JOBS: null.Exact-tree verification
git diff --check: passed0f07c4e60f2e02fc60a0204a4cdfb0f42efbabc2)Fresh exact-head hosted checks
Predecessor CodeQL run 34249195529 is terminal FAILURE. Exact handler run 34249932036 proved the cutover defect: protected main received the nested-only payload as
SUPPLIED_REQUIRED_JOBS: null. That failure is not transferred to the new child.The ordinary child generated a new exact-head generation:
git diff --checkpassed.Merge gates
Fresh exact-head terminal checks and a qualifying current-head independent approval remain mandatory. No predecessor check or review transfers. No merge, self-approval, auto-merge authorization, protection bypass, manual rerun, synthetic status, empty push, force push, destructive rebase, or Close was performed.
Summary by CodeRabbit
새 기능
버그 수정
문서