fix(release): gate releases only on the allowlisted required checks - #1259
Conversation
scripts/ci/release_checks_gate.sh required every check-run on the release commit to be terminal and non-failing, so the hourly opencode-hourly-loop and provider-catalog-sync runs attached to main's tip could block a release. Evaluate only the explicit RELEASE_EXPECTED_PUSH_CHECKS allowlist (the four required security.yml jobs); keep failing closed when a required check is missing, pending, not success, or the allowlist is empty or malformed.
|
Warning Review limit reachedNext included review available in 26 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (8)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Review follow-up on the release checks gate. Judging every check-run with a required name let security.yml's scheduled runs (jobs skipped on schedule) or any old failed run block a commit forever. Select the newest push-event .github/workflows/security.yml run on main for TARGET_SHA (highest run id, then run_attempt) and evaluate only its jobs (explicit filter=latest) against the RELEASE_EXPECTED_PUSH_CHECKS allowlist; fail closed when the run is missing or unfinished or a required job is missing or not success. Drop the details_url self-exclusion and the check-runs listing. publish gains read-only actions: read for the recheck.
Admission correction — exact head
|
Problem
scripts/ci/release_checks_gate.shdecides whether a commit can be released, and two versions of it have been wrong on protectedmain:opencode-hourly-loop.ymlandprovider-catalog-sync.ymlruns attach check-runs to main's tip, so a failed or in-flight maintenance run could block a release.success.security.yml's weeklyscheduleruns also execute on main's tip, and their jobs areif: github.event_name != 'schedule', so they leave skipped (or failed) check-runs under the same required names.main@5665b0adfails for that reason today (runs 35581051361, 35710548003), and any old failed run blocks a SHA forever.Change
The gate now certifies a commit from exactly one workflow run:
actions/runs?head_sha=$TARGET_SHA&event=pushand re-filters locally topath == .github/workflows/security.yml,event == push,head_branch == mainandhead_sha == TARGET_SHA.run_attempt, so a re-run replaces a red attempt.jobs?filter=latest(each job's most recent attempt, which covers "re-run failed jobs"). It checks them against the explicit allowlistRELEASE_EXPECTED_PUSH_CHECKS: "Tests and package quality", "Property and coverage-guided fuzzing", "Rust workspace gate", "CodeQL, supply chain, and SBOM".completed;completed+success(skipped and neutral count as failures);security.ymlruns, the hourly maintenance workflows, and this release run itself. This is an allowlist, not a denylist.check-runslisting and the brittledetails_url contains /actions/runs/<GITHUB_RUN_ID>/self-exclusion.release.yml: thepublishjob gains read-onlyactions: read, needed for the recheck.verifyalready had it. Two comments were updated. There are no other workflow changes.main's branch rules (read through the public API) contain no required-status-checks rule, only org-required PR workflows. The allowlist therefore stays the pinnedsecurity.ymljob list, which a test keeps equal tosecurity.yml's job names. ADR 0129 rejected a live ruleset lookup because it needsadministration: read.Tests
tests/test_release_checks_required_allowlist.pyruns the real script against a stubbedghthat serves the Actions runs/jobs API. Covered scenarios:run_attemptwins, including the case where the newest attempt is red;filter=latest, nocheck-runs, nodetails_url, noGITHUB_RUN_ID, both release jobs haveactions: read, and no other workflow reuses a required job name.test_release_workflow_contract.py,test_release_checks_required_success_contract.py) now serve the runs/jobs API.test_release_workflow_idempotency_contract.pynow allows job-scopedactions: readonpublishand still forbids it workflow-wide and forbidsactions: write.actionlint1.7.7 with shellcheck: clean.main@5665b0adalso has (mainis red; fix(ci): repair protected-main security and runtime regressions #1209 addresses it). No new failures.Merge order
Merge this before #1258. #1258 will then resolve its one expected conflict, in
docs/RELEASING.md(precondition 4).release.ymlmerges cleanly.