Skip to content

fix(ci): run exact-head gates on stacked pull requests #298

Description

@seonghobae

Current authoritative state

The stacked-PR/exact-checkout CI evidence defects and bounded browser-evidence timeout defect are repaired on canonical single-writer Ready PR #299 / branch fix/stacked-pr-ci-gates-298. Protected shipped truth remains exact main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact #299 head is 1efbd632719b0e54c5a33e3a95224a4bd2f869d3, mechanically mergeable against that unchanged protected base. The effective Inkspan delta remains only .github/workflows/ci.yml plus src/workflowExactHead.test.ts; do not create a competing CI writer.

Repaired Inkspan-owned evidence defects

  1. Canonical CI restricted pull_request to base main, leaving stacked PR heads without the ordinary repository matrix.
  2. Contributor-head checkout lacked an immediate runtime equality proof before setup/repository-code consumption.
  3. Browser evidence had the same 30-minute ceiling as ordinary jobs even though dependency-locked playwright install --with-deps can consume that budget during infrastructure/package-mirror latency.
  4. The predecessor contract test relied on global string counts, so job-local timeout or exact-checkout verification order could move and false-green.

Historical TDD lineage: stacked-trigger RED e75a0035d753d8d58a9c04a8c254bf8914135e24 -> trigger repair 3ea55387d8d7d88a80933b398abda78e42a4496b; runtime-checkout RED 85572a50d79a11c27c9171cc9180d7a53128bea0 -> exact checkout attestation; browser-timeout RED a74e150c06c22e3caee48446d03c3b0726bfc0f5 -> browser-only 60-minute ceiling while build/Office stay at 30.

After #299 moved Ready, CodeRabbit identified the fourth, still-valid false-green weakness on predecessor b7e9bb8156a3e46204523ab37292566811f560f8. Current 1efbd632719b0e54c5a33e3a95224a4bd2f869d3 slices the three repository workflow jobs independently, binds each timeout and checkout contract to its own job, requires exact-head verification immediately after checkout and before pnpm/setup-python consumers, and checks the pull_request YAML trigger structurally without a base-branch filter. CodeRabbit marks that Major thread addressed/resolved.

A later Devin informational observation correctly notes that the repository runtime check compares local HEAD with the same immutable event SHA supplied to checkout. That proves checkout honored the event-bound ref; independent live PR/base resolution remains the separate governance/review step before lifecycle mutation and is not silently claimed by the job assertion.

Exact-current-head evidence

For unchanged exact #299 head 1efbd632719b0e54c5a33e3a95224a4bd2f869d3:

  • repository CI 32635939468: completed / success;
  • build-and-test 97185600342: success, including exact source-head checkout verification, typecheck, exact 100% owned-production coverage, library build, packed-package verification, and demo build;
  • browser 97185600177: success, including exact source-head checkout verification, Playwright dependency/revision installation, and real cross-engine evidence inside the bounded 60-minute ceiling;
  • Office Python 3.11 97185600282, 3.12 97185600292, 3.13 97185600341, 3.14 97185600286: success with exact source-head checkout verification, dependency consistency, 100% docstring/branch coverage, wheel, and packaged schema/license gates;
  • central Security Scan 32635939483: GitHub aggregate status is success, but this is non-passing / false-green supply-chain evidence. Dependency-review job 97185600223 checked out synthetic merge 12668622e38473c14dbb7d22bb9e3e0c05f1ea8a; its exact 3b38ead2d00f44eb578d0689087b9293b3dabe1e...1efbd632719b0e54c5a33e3a95224a4bd2f869d3 support probe returned HTTP 403, emitted Dependency review is unavailable for ContextualWisdomLab/inkspan; skipping dependency-review hard gate., wrote supported=false, skipped the pinned dependency-review action, and still concluded green. Foreign owner: ContextualWisdomLab/.github#810, active repair PR #897;
  • central SAST Semgrep 32635939469: GitHub aggregate status is success and the scan reported no findings, but exact-source evidence is non-passing because job 97185600190 checked out synthetic merge 12668622e38473c14dbb7d22bb9e3e0c05f1ea8a rather than source head 1efbd632719b0e54c5a33e3a95224a4bd2f869d3. Foreign exact-submitted-revision owner: ContextualWisdomLab/.github#1222, active repair PR #941;
  • formal submitted reviews: automated COMMENTED reviews and maintainer thread replies only, qualifying approvals 0;
  • unresolved inline review threads: 0; the three Devin informational observations were verified against this exact head, answered with their intended scope, and resolved without treating them as approval;
  • PR lifecycle: Ready / unmerged; GitHub reports mechanically mergeable.

The repository-local #299 CI repair is technically green, but the complete required evidence set is not. A green aggregate central status cannot substitute for a skipped hard gate or a wrong checkout SHA. OSV/Trivy/Scorecard success is not a semantic substitute for the skipped dependency-review action. Pending, queued, skipped, cancelled, absent, neutral, failed, stale, predecessor, status-only, model-only, wrong-checkout, or synthetic-merge evidence is non-passing.

Foreign owner acceptance and downstream boundary

There is no correct Inkspan-local source workaround for the central dependency-review capability path or the central synthetic-merge checkout. The existing foreign owners have been advanced with the exact affected Inkspan SHAs/runs/jobs; do not add a leaf workaround or create duplicate central writers.

Before #299 can be treated as merge-ready under the evidence contract, the corresponding central repairs must reach protected .github/main, then unchanged or descendant #299 must acquire fresh central evidence that proves:

  • dependency-review support comparison returns a transport-successful HTTP 200, the pinned dependency-review action actually executes and succeeds, and no supported=false/skip path is taken;
  • central Security/SAST jobs bind and attest the exact Inkspan source head/repository identity before repository-code consumption/scanning rather than relying on refs/pull/*/merge checkout evidence.

After #299 eventually integrates, every stacked PR must independently acquire its own exact-current-head repository workflow generation; parent/predecessor evidence cannot substitute. The 60-minute browser bound is a finite infrastructure allowance, not permission to make browser evidence optional or unbounded.

The repair is active-PR truth only. Keep #299 Ready but unmerged while these central exact-evidence blockers and every then-live governance requirement remain unresolved. Before merge, refetch unchanged exact head/live protected base, ancestry/mergeability, live governance, formal reviews/threads, and every applicable repository/central workflow. Do not self-approve, transfer predecessor evidence, weaken gates, move protected main, or fabricate release identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions