Finding
.github/workflows/reusable-pkg-cadence.yml classifies a package's update
interval with:
new_interval = entry.get('interval') or bootstrap_interval(name)
but every entry reaches that line through one of the two setdefault calls at
lines 154 and 158:
churn.setdefault(name, {'changes': 0, 'window_start': TODAY, 'interval': 'monthly'})
Those run for every package in the image before classification, so
entry.get('interval') is always the truthy string 'monthly' and the
right-hand side never evaluates. bootstrap_interval() and its WEEKLY_PAT,
QUARTERLY_PAT and YEARLY_PAT regexes are unreachable dead code.
Effect. On a first run — and for the whole four-week wait before churn data
is trusted — every package is classified monthly. tailscale, bootc,
distrobox and uupd land in the same layers as fonts and firmware, which is
the exact grouping the workflow's own header comment says it exists to prevent:
weekly packages land in their own layers so a typical update only pulls the
layers that actually changed
This has been shipping on the Sunday pkg-cadence.yml schedule against
bluefin:stable and bluefin:lts.
How it was found. Executing the extracted heredoc against fixture inputs.
The first version of the tests in #561 asserted the documented heuristics and
returned monthly for all 12 pattern-matched packages; those tests now pin the
shipped behaviour instead, with a comment naming this issue's defect, so the
suite goes red the moment the fix below lands and must be updated with it.
Recommendation
Delete the 'interval' key from both setdefault defaults, so a package that
has no recorded interval falls through to bootstrap_interval().
Replace line 154 and line 158 — both are byte-identical:
churn.setdefault(name, {'changes': 0, 'window_start': TODAY, 'interval': 'monthly'})
with:
churn.setdefault(name, {'changes': 0, 'window_start': TODAY})
(Leading whitespace is 14 spaces, matching the surrounding heredoc body.)
No other line changes. entry.get('interval') then returns None for a package
seen for the first time, bootstrap_interval(name) runs, and the derived value
is written back into entry['interval'] on the same pass, so the heuristic is
consulted exactly once per package and the recorded value wins thereafter.
This is verified, not assumed: test_explicitly_empty_recorded_interval_falls_back_to_the_heuristic
in #561 feeds churn entries whose interval is falsy and asserts
tailscale → weekly, google-noto-sans-fonts → yearly,
linux-firmware → quarterly — the fallback path the fix restores.
This needs a human (or an ISSUES_PRS_MERGE agent)
The fix is inside .github/workflows/. This agent's GitHub App token is minted
at the contributor tier, which does not carry the workflows permission, so
any push whose diff touches that directory is rejected by GitHub server-side.
No pull request this agent can open could contain the change — that is a
capability ceiling, not a judgement about the fix. The replacement text above is
exact so applying it is mechanical.
The test-side work is separate and is being opened as a PR against #561.
Priority
- Impact: high (mis-groups OCI layers for every consumer image during bootstrap)
- Effort: low (two identical lines)
Filed by quality agent (hold-gated mode)
— hive: agent=quality backend=copilot model=claude-opus-5
Finding
.github/workflows/reusable-pkg-cadence.ymlclassifies a package's updateinterval with:
but every entry reaches that line through one of the two
setdefaultcalls atlines 154 and 158:
Those run for every package in the image before classification, so
entry.get('interval')is always the truthy string'monthly'and theright-hand side never evaluates.
bootstrap_interval()and itsWEEKLY_PAT,QUARTERLY_PATandYEARLY_PATregexes are unreachable dead code.Effect. On a first run — and for the whole four-week wait before churn data
is trusted — every package is classified
monthly.tailscale,bootc,distroboxanduupdland in the same layers as fonts and firmware, which isthe exact grouping the workflow's own header comment says it exists to prevent:
This has been shipping on the Sunday
pkg-cadence.ymlschedule againstbluefin:stableandbluefin:lts.How it was found. Executing the extracted heredoc against fixture inputs.
The first version of the tests in #561 asserted the documented heuristics and
returned
monthlyfor all 12 pattern-matched packages; those tests now pin theshipped behaviour instead, with a comment naming this issue's defect, so the
suite goes red the moment the fix below lands and must be updated with it.
Recommendation
Delete the
'interval'key from bothsetdefaultdefaults, so a package thathas no recorded interval falls through to
bootstrap_interval().Replace line 154 and line 158 — both are byte-identical:
with:
(Leading whitespace is 14 spaces, matching the surrounding heredoc body.)
No other line changes.
entry.get('interval')then returnsNonefor a packageseen for the first time,
bootstrap_interval(name)runs, and the derived valueis written back into
entry['interval']on the same pass, so the heuristic isconsulted exactly once per package and the recorded value wins thereafter.
This is verified, not assumed:
test_explicitly_empty_recorded_interval_falls_back_to_the_heuristicin #561 feeds churn entries whose
intervalis falsy and assertstailscale → weekly,google-noto-sans-fonts → yearly,linux-firmware → quarterly— the fallback path the fix restores.This needs a human (or an ISSUES_PRS_MERGE agent)
The fix is inside
.github/workflows/. This agent's GitHub App token is mintedat the
contributortier, which does not carry theworkflowspermission, soany push whose diff touches that directory is rejected by GitHub server-side.
No pull request this agent can open could contain the change — that is a
capability ceiling, not a judgement about the fix. The replacement text above is
exact so applying it is mechanical.
The test-side work is separate and is being opened as a PR against #561.
Priority
Filed by quality agent (hold-gated mode)
— hive: agent=quality backend=copilot model=claude-opus-5