Skip to content

fix(ci): include ordinary PR Dylint in the local gate - #1646

Merged
zackees merged 5 commits into
mainfrom
feat/local-dylint-pr-parity
Oct 4, 2026
Merged

zackees merged 5 commits into
mainfrom
feat/local-dylint-pr-parity

Conversation

@zackees

@zackees zackees commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

The local gate previously passed the Ubuntu pair without running the independent PR Dylint workflow. It now runs that pair and its verifier prerequisite, then replays the entire existing dylint.yml with ordinary PR/minimal context and no job filter. The proof requires all three Dylint jobs and each named policy, library and workspace step to complete successfully; missing, skipped, duplicate or filtered evidence fails closed.

Both existing workflows remain unchanged. The library UI fixtures retain their existing source-change condition, and manual/full cross-target selection remains distinct from the ordinary PR selection. Board and other native-host checks remain remote. The gate runs as a Python module so shared proof helpers resolve consistently.

Validation: the complete declared local gate passed after incorporating main's version bump, on tree 11880321d07c88b62fe67844f2fbd1c628d3ded9 (851 seconds, ordinary concurrent correctness run). It ran the required Ubuntu verifier/check/Python graph and the entire ordinary-PR Dylint workflow. The remote branch independently incorporated the same main commit, producing exactly the same tree and parents. Normal checker invocations reused the verified 3,370-input lane in under one second and stamped final head c95e9f8e1aec61c68ae09f226b0203fb6ac5d554. A normal merge preserves the remote update, and the branch was pushed without force. Explicit PR-context verification accepts the final tree-bound Local-Gate trailer. Earlier 31 helper/status tests, configured Ruff C901/RUF100, formatting and source review passed. This demonstrates unchanged-input proof reuse; overlapping correctness timings are not a controlled speedup comparison.

Part of #1643. Controlled cold/warm timing, ancestor payload reuse and PR-to-main handoff remain tracked there; overlapping correctness runs are not speedup evidence.

Local-Gate: v1 tree=aebcfef9d595e273c142d53ca14e6688fe40987f secs=1165 lanes=linux-minimal:run
Ci-Attestation: {"at":1791114387,"gate":"general/all/ubuntu-ci-guards","host":"linux-x86_64","key":"4bd7a724c2cef980000e2be6b5c0f160f2f55a3306a830698e8e40750918224f","lane":"linux-minimal","parents":["d45e41461998a0f3b67d03749abd787a361b5a1c"],"secs":1165,"stamp":"f74692c4142f0068121e8895c1926b63","tree":"aebcfef9d595e273c142d53ca14e6688fe40987f","v":1,"via":"run"}
Ci-Attestation: {"at":1791114387,"gate":"rust/x86_64-unknown-linux-gnu/workspace-clippy","host":"linux-x86_64","key":"4bd7a724c2cef980000e2be6b5c0f160f2f55a3306a830698e8e40750918224f","lane":"linux-minimal","parents":["d45e41461998a0f3b67d03749abd787a361b5a1c"],"secs":1165,"stamp":"f83ee00d3d73c6c81eef0c45739277fe","tree":"aebcfef9d595e273c142d53ca14e6688fe40987f","v":1,"via":"run"}
Ci-Attestation: {"at":1791114387,"gate":"rust/x86_64-unknown-linux-gnu/workspace-test","host":"linux-x86_64","key":"4bd7a724c2cef980000e2be6b5c0f160f2f55a3306a830698e8e40750918224f","lane":"linux-minimal","parents":["d45e41461998a0f3b67d03749abd787a361b5a1c"],"secs":1165,"stamp":"4600c01451447abb9f18b480ea12f738","tree":"aebcfef9d595e273c142d53ca14e6688fe40987f","v":1,"via":"run"}
Ci-Attestation: {"at":1791114387,"gate":"rust/x86_64-unknown-linux-gnu/python-facade-test","host":"linux-x86_64","key":"4bd7a724c2cef980000e2be6b5c0f160f2f55a3306a830698e8e40750918224f","lane":"linux-minimal","parents":["d45e41461998a0f3b67d03749abd787a361b5a1c"],"secs":1165,"stamp":"fdd82404b27a71afa895ca2f5c6383db","tree":"aebcfef9d595e273c142d53ca14e6688fe40987f","v":1,"via":"run"}
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: FastLED/fbuild/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ec6c2a9b-04a3-4115-98d3-5677c757dda4
📥 Commits

Reviewing files that changed from the base of the PR and between f1fced4 and 32747fd.

📒 Files selected for processing (6)
  • ci/README.md
  • ci/local_dylint_gate.py
  • ci/local_gate.py
  • ci/test_local_dylint_gate.py
  • ci/test_local_gate.py
  • local-gate.toml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The local gate now verifies the required Ubuntu jobs and an ordinary pull-request Dylint run. The Dylint proof check requires successful, completed evidence for each configured step. The README and gate commands describe the workflow selections and usage.

Changes

Local CI gate

Layer / File(s) Summary
Ubuntu run selection and proof
ci/local_gate.py, ci/test_local_gate.py
Ubuntu verification uses a run selection and requires exactly the configured jobs, including verify. Tests cover the required job set and job outcomes.
Dylint run and step verification
ci/local_dylint_gate.py, ci/test_local_dylint_gate.py
The gate submits a minimal pull-request Dylint run and checks required steps for completed, successful evidence. Tests reject invalid run selections and missing, failed, unfinished, or duplicate step evidence.
Gate integration and usage
ci/local_gate.py, local-gate.toml, ci/README.md
The main gate runs Dylint after Ubuntu verification and checks that the commit and worktree remain unchanged. The commands use module invocation, and the README describes workflow selection and Dylint proof checks.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant LocalGate as local_gate.main
  participant DylintGate as run_dylint
  participant DylintWorkflow as Dylint workflow
  participant ProofCheck as verify_dylint
  LocalGate->>DylintGate: workspace and SHA
  DylintGate->>DylintWorkflow: submit minimal pull-request run
  DylintWorkflow-->>DylintGate: completed run proof
  DylintGate->>ProofCheck: verify run proof
Loading

Merge Risk: ⚪ Minimal · up to 099d6

The local gate adds Ubuntu prerequisite checks and ordinary-PR Dylint proof without an identified merge-blocking issue. It is ready for normal merge checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 32747

The gate strengthens verification and rejects incomplete evidence. No concrete new security defect was established, but the added workflow’s effective credential and cache access, execution isolation, and interrupted-run cleanup remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The added execution surface is the invoking local runner and the workspace, toolchain, and cache resources available to it. Broader developer-host, shared-cache, or credential exposure cannot be bounded from the caller and workflow alone; no new organization-wide or production-service authority was established.

Trust Boundaries and Controls

  • observed — The gate validates runner-reported source and selection metadata; this does not establish runner isolation or proof authenticity against a compromised runner. Existing Ubuntu checkout and repository-code execution also precede this PR, so Dylint’s lack of an explicit persist-credentials: false setting alone does not prove newly introduced credential exposure.

Resilience and Maintainability Implications

  • inferred — Submission, waiting, parsing, or verification failure cannot reach the gate’s final success message. Interruption may still leave submitted work running, and concurrent invocations may interact through runner-managed caches or concurrency groups; those lifecycle effects remain unresolved rather than verified defects.

Hardening Proposals

  • proposed — Document or enforce the local runner’s credential injection, cache namespace, container isolation, and cancellation guarantees before treating ordinary-PR replay as an isolated execution boundary.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 18 functions across 4 files. (2 skipped: 2… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: adding ordinary PR Dylint checks to the local CI gate.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 18 functions across 4 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Local-Gate: v1 tree=11880321d07c88b62fe67844f2fbd1c628d3ded9 secs=0 lanes=linux-minimal:reused@00242c012f03
Ci-Attestation: {"at":1791117011,"gate":"general/all/ubuntu-ci-guards","host":"linux-x86_64","key":"00242c012f03191cde54b3cf7efcc3a5342fb5b8107dbdbedcc37ad466d4ff35","lane":"linux-minimal","parents":["32747fdc34153f80bc75398f9ffa8557cd5cab57","f1fced41720840b45b878823274c5cea35112c1b"],"secs":null,"stamp":"fdbf3697f3c814e6091176c82c1808ec","tree":"11880321d07c88b62fe67844f2fbd1c628d3ded9","v":1,"via":"reused"}
Ci-Attestation: {"at":1791117011,"gate":"rust/x86_64-unknown-linux-gnu/workspace-clippy","host":"linux-x86_64","key":"00242c012f03191cde54b3cf7efcc3a5342fb5b8107dbdbedcc37ad466d4ff35","lane":"linux-minimal","parents":["32747fdc34153f80bc75398f9ffa8557cd5cab57","f1fced41720840b45b878823274c5cea35112c1b"],"secs":null,"stamp":"937afca2dd8c7517ecba5081148310b9","tree":"11880321d07c88b62fe67844f2fbd1c628d3ded9","v":1,"via":"reused"}
Ci-Attestation: {"at":1791117011,"gate":"rust/x86_64-unknown-linux-gnu/workspace-test","host":"linux-x86_64","key":"00242c012f03191cde54b3cf7efcc3a5342fb5b8107dbdbedcc37ad466d4ff35","lane":"linux-minimal","parents":["32747fdc34153f80bc75398f9ffa8557cd5cab57","f1fced41720840b45b878823274c5cea35112c1b"],"secs":null,"stamp":"7070a044dfeb94f9242542571895949a","tree":"11880321d07c88b62fe67844f2fbd1c628d3ded9","v":1,"via":"reused"}
Ci-Attestation: {"at":1791117011,"gate":"rust/x86_64-unknown-linux-gnu/python-facade-test","host":"linux-x86_64","key":"00242c012f03191cde54b3cf7efcc3a5342fb5b8107dbdbedcc37ad466d4ff35","lane":"linux-minimal","parents":["32747fdc34153f80bc75398f9ffa8557cd5cab57","f1fced41720840b45b878823274c5cea35112c1b"],"secs":null,"stamp":"d6e2461c060777c176329bd421c1ce02","tree":"11880321d07c88b62fe67844f2fbd1c628d3ded9","v":1,"via":"reused"}
…o feat/local-dylint-pr-parity-remote-integrated

Local-Gate: v1 tree=11880321d07c88b62fe67844f2fbd1c628d3ded9 secs=0 lanes=linux-minimal:reused@00242c012f03
Ci-Attestation: {"at":1791117067,"gate":"general/all/ubuntu-ci-guards","host":"linux-x86_64","key":"00242c012f03191cde54b3cf7efcc3a5342fb5b8107dbdbedcc37ad466d4ff35","lane":"linux-minimal","parents":["9afd0a7c816c671222e7bc30e30bb8bb44d9676f","099d6ef51b0de3c978035b897b73dbcc2c921cfa"],"secs":null,"stamp":"daeec34a54f548b5123d3c633e46103c","tree":"11880321d07c88b62fe67844f2fbd1c628d3ded9","v":1,"via":"reused"}
Ci-Attestation: {"at":1791117067,"gate":"rust/x86_64-unknown-linux-gnu/workspace-clippy","host":"linux-x86_64","key":"00242c012f03191cde54b3cf7efcc3a5342fb5b8107dbdbedcc37ad466d4ff35","lane":"linux-minimal","parents":["9afd0a7c816c671222e7bc30e30bb8bb44d9676f","099d6ef51b0de3c978035b897b73dbcc2c921cfa"],"secs":null,"stamp":"684608051601a22984c733fbec40c456","tree":"11880321d07c88b62fe67844f2fbd1c628d3ded9","v":1,"via":"reused"}
Ci-Attestation: {"at":1791117067,"gate":"rust/x86_64-unknown-linux-gnu/workspace-test","host":"linux-x86_64","key":"00242c012f03191cde54b3cf7efcc3a5342fb5b8107dbdbedcc37ad466d4ff35","lane":"linux-minimal","parents":["9afd0a7c816c671222e7bc30e30bb8bb44d9676f","099d6ef51b0de3c978035b897b73dbcc2c921cfa"],"secs":null,"stamp":"4513b24e1e2edbbe52c059ec415294ab","tree":"11880321d07c88b62fe67844f2fbd1c628d3ded9","v":1,"via":"reused"}
Ci-Attestation: {"at":1791117067,"gate":"rust/x86_64-unknown-linux-gnu/python-facade-test","host":"linux-x86_64","key":"00242c012f03191cde54b3cf7efcc3a5342fb5b8107dbdbedcc37ad466d4ff35","lane":"linux-minimal","parents":["9afd0a7c816c671222e7bc30e30bb8bb44d9676f","099d6ef51b0de3c978035b897b73dbcc2c921cfa"],"secs":null,"stamp":"ec7d8aff05b05670831f05b5df36b9a4","tree":"11880321d07c88b62fe67844f2fbd1c628d3ded9","v":1,"via":"reused"}
@zackees
zackees merged commit 35f1b22 into main Oct 4, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Triage

Development

Successfully merging this pull request may close these issues.

1 participant