diff --git a/.github/workflows/mail-smoke.yml b/.github/workflows/mail-smoke.yml index 6a3a3fdc9..3f952ffa1 100644 --- a/.github/workflows/mail-smoke.yml +++ b/.github/workflows/mail-smoke.yml @@ -6,6 +6,15 @@ on: permissions: contents: read +concurrency: + # One live mailbox/DAV smoke at a time. Keep pending requests up to GitHub's + # concurrency-group limit (currently 100); requests beyond that bound may be + # canceled. This workflow holds seeded credentials and talks to + # customer-adjacent servers, and it is not a merge/release/deploy path. + group: mail-smoke-${{ github.repository }} + cancel-in-progress: false + queue: max + jobs: smoke: runs-on: [self-hosted, mail-egress] diff --git a/backend/tests/test_mail_smoke_concurrency.py b/backend/tests/test_mail_smoke_concurrency.py new file mode 100644 index 000000000..84e8caa58 --- /dev/null +++ b/backend/tests/test_mail_smoke_concurrency.py @@ -0,0 +1,20 @@ +"""Regression tests for Internal Mail Smoke concurrency semantics.""" + +from pathlib import Path + + +REPO_ROOT = Path(__file__).resolve().parents[2] + + +def test_mail_smoke_concurrency_uses_bounded_pending_queue() -> None: + """Require bounded queuing instead of single-pending replacement.""" + workflow = (REPO_ROOT / ".github/workflows/mail-smoke.yml").read_text( + encoding="utf-8" + ) + workflow_header = workflow.split("jobs:", 1)[0] + + assert "concurrency:" in workflow_header + assert "group: mail-smoke-${{ github.repository }}" in workflow_header + assert "cancel-in-progress: false" in workflow_header + assert "queue: max" in workflow_header + assert "cancel-in-progress: true" not in workflow_header diff --git a/backend/tests/test_release_governance.py b/backend/tests/test_release_governance.py index a23c70746..ecad3ad3d 100644 --- a/backend/tests/test_release_governance.py +++ b/backend/tests/test_release_governance.py @@ -400,6 +400,10 @@ def test_stepsecurity_remediation_adds_pinned_audit_hardening() -> None: assert harden_runner_ref in mail_smoke_workflow assert "egress-policy: block" in mail_smoke_workflow assert "allowed-endpoints:" in mail_smoke_workflow + assert "concurrency:" in mail_smoke_workflow + assert "mail-smoke-${{ github.repository }}" in mail_smoke_workflow + assert "cancel-in-progress: false" in mail_smoke_workflow + assert "cancel-in-progress: true" not in mail_smoke_workflow.split("jobs:", 1)[0] dependency_review_workflow = read_repo_text( ".github/workflows/dependency-review.yml"