Skip to content

fix(actions): recover current startup failures - #1846

Merged
seonghobae merged 1 commit into
mainfrom
codex/fix-current-startup-failures
Sep 4, 2026
Merged

seonghobae merged 1 commit into
mainfrom
codex/fix-current-startup-failures

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • recover exact-current-head non-CodeQL startup_failure runs with one guarded same-tree head refresh, because GitHub rejects rerunning pre-job failures
  • admit Strix events against live PR metadata before a shared workflow-repository-PR provider queue
  • unify pull_request_target and repository_dispatch Strix evidence for one PR with cancel-in-progress: true, while preserving push/schedule runs
  • document the 74-repository census and live API evidence

Root-cause evidence

  • No new org-visible startup_failure was created after central 07db37e; the retired CodeQL case is explicitly excluded.
  • Six non-CodeQL startup failures remain on unchanged heads in EgressWeave ⚡ Bolt: PR 스케줄러의 N+1 API 호출 병렬화로 성능 개선 #214 and ContextualWisdomLab.github.io Fix OpenCode prompt template shell expansion #194.
  • POST /actions/runs/32985871408/rerun returns 403 This workflow run cannot be retried.
  • The old Strix group included github.event_name, splitting native and dispatched evidence for the same repository/PR, and used cancel-in-progress: false.
  • GitHub does not guarantee concurrency ordering, so exact live-head admission precedes the job-level shared queue; a stale event never reaches cancellation.

Verification

  • python -m pytest -q tests/test_required_workflow_queue_contract.py tests/test_pr_review_merge_scheduler.py tests/test_codeql_pr_workflow_contract.py tests/test_codeql_scan_dispatch_workflow_contract.py tests/test_code_scanning_required_workflow_contract.py tests/test_central_required_workflow_ruleset_audit.py — 418 passed
  • actionlint -no-color .github/workflows/strix.yml
  • bash -n scripts/ci/test_strix_quick_gate.sh
  • git diff --check
  • bash scripts/ci/test_strix_quick_gate.sh passed on base ed6d2b53; after base moved to d6c636a9, the harness has unrelated OpenCode expectation failures introduced by fix(actions): admit live review heads before cancellation #1845. This PR does not alter those OpenCode/Noema files or assertions.

Scope guard

scripts/ci/contextual_orchestrator_review_sidecar.sh and its direct contract test are intentionally untouched. No product code changes.

Summary by CodeRabbit

  • 버그 수정

    • 오래된 이벤트와 잘못된 PR 메타데이터로 인해 보안 스캔이 실행되는 문제를 방지했습니다.
    • 동일 PR에서 최신 커밋에 해당하는 스캔만 실행되도록 개선했습니다.
    • 동일 PR의 중복 스캔이 발생하면 이전 실행을 자동으로 취소합니다.
    • Actions 시작 실패가 감지되면 현재 커밋을 안전하게 갱신해 복구를 시도합니다.
  • 검증

    • PR 및 저장소 이벤트의 대상과 커밋 일치 여부 검증을 강화했습니다.
    • 스캔 동시성 및 시작 실패 복구 시나리오에 대한 자동 검사를 추가했습니다.

@seonghobae
seonghobae merged commit b15cb99 into main Sep 4, 2026
5 of 18 checks passed
@seonghobae
seonghobae deleted the codex/fix-current-startup-failures branch September 4, 2026 10:31
@coderabbitai

coderabbitai Bot commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: b96da1ab-7b09-4bd4-b1e1-a74fefa4e69d

📥 Commits

Reviewing files that changed from the base of the PR and between d6c636a and ee7b128.

📒 Files selected for processing (6)
  • .github/workflows/strix.yml
  • docs/doctoring/startup-failure-and-strix-concurrency-20260904.md
  • scripts/ci/pr_review_merge_scheduler_core.py
  • scripts/ci/test_strix_quick_gate.sh
  • tests/test_pr_review_merge_scheduler.py
  • tests/test_required_workflow_queue_contract.py

📝 Walkthrough

Walkthrough

Startup-failure 실행을 현재 PR 헤드 기준으로 복구하고, Strix 이벤트를 라이브 PR 메타데이터와 대조하도록 변경했습니다. 승인된 PR은 단일 동시성 그룹에서 처리하며 이전 스캔을 취소합니다.

Changes

Startup-failure 복구

Layer / File(s) Summary
Restamp 공통 경로 추출
scripts/ci/pr_review_merge_scheduler_core.py
Restamp 동작을 매개변수화한 restamp_pr_head로 추출했습니다. 기존 last-push 경로와 새 startup-failure 경로가 공통 함수를 사용합니다.
현재 헤드 startup-failure 복구
scripts/ci/pr_review_merge_scheduler_core.py, tests/test_pr_review_merge_scheduler.py, docs/doctoring/startup-failure-and-strix-concurrency-20260904.md
현재 head_sha의 workflow별 최신 실행만 검사합니다. 조건을 만족하는 startup_failure 실행은 guarded same-tree restamp으로 복구합니다. 이미 복구된 헤드는 다시 처리하지 않습니다. inspect_pr는 복구된 실행을 check_rerun 결정으로 보고합니다. 관련 테스트와 운영 문서를 추가했습니다.

Strix 헤드 승인 및 동시성

Layer / File(s) Summary
라이브 PR 헤드 승인
.github/workflows/strix.yml, docs/doctoring/startup-failure-and-strix-concurrency-20260904.md
admit-current-head 작업이 PR 및 repository-dispatch 이벤트의 저장소, PR 번호, base/head SHA를 라이브 PR 정보와 비교합니다. 오래된 이벤트는 승인하지 않습니다.
승인된 PR 스캔 동시성
.github/workflows/strix.yml, scripts/ci/test_strix_quick_gate.sh, tests/test_required_workflow_queue_contract.py
strix가 changed-scope와 admit-current-head에 의존하도록 변경했습니다. 승인된 저장소와 PR 번호를 동시성 키로 사용하고 동일 PR의 이전 실행을 취소합니다. 계약 테스트와 빠른 게이트를 새 동작에 맞게 갱신했습니다.

Estimated code review effort: 4 (Complex) | ~45 minutes

Suggested reviewers: claude

Sequence Diagram(s)

sequenceDiagram
  participant inspect_pr
  participant recover_current_head_startup_failures
  participant GitHub_Actions_API
  participant restamp_pr_head_after_startup_failure
  inspect_pr->>recover_current_head_startup_failures: 현재 PR 헤드 복구 검사
  recover_current_head_startup_failures->>GitHub_Actions_API: head_sha 기준 workflow runs 조회
  GitHub_Actions_API-->>recover_current_head_startup_failures: 최신 startup_failure 실행 반환
  recover_current_head_startup_failures->>restamp_pr_head_after_startup_failure: guarded same-tree restamp
  restamp_pr_head_after_startup_failure-->>inspect_pr: 복구된 실행 ID 반환
Loading
sequenceDiagram
  participant Strix_event
  participant admit_current_head
  participant GitHub_PR_API
  participant strix
  Strix_event->>admit_current_head: 이벤트 메타데이터 전달
  admit_current_head->>GitHub_PR_API: 라이브 PR 정보 조회
  GitHub_PR_API-->>admit_current_head: 현재 상태와 base/head 반환
  admit_current_head-->>strix: 승인된 저장소와 PR 번호 전달
  strix->>strix: 동일 PR 동시성 그룹에서 이전 실행 취소
Loading
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/fix-current-startup-failures

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

seonghobae added a commit that referenced this pull request Sep 5, 2026
…UB_ACTIONS-agnostic

recover_current_head_startup_failures() only runs inside inspect_pr()
when os.environ["GITHUB_ACTIONS"] == "true" (#1846), so it silently
never fired in a developer's local shell -- but GitHub Actions sets
that variable for the entire job, including the pytest process that
runs this very test file. 14 pre-existing tests (12 sharing the
cancel_stale_pr_runs stub, 2 closing empty PRs) call inspect()/inspect_pr()
with dry_run=False and never anticipated this side effect, so in CI they
hit the real recovery path: one cluster used the fixture's placeholder
headRefOid="head" and blew up in validate_git_sha, the other supplied a
real sha but its narrow `run` stub didn't accept the recovery path's
extra kwargs. Stub recover_current_head_startup_failures to a no-op
`[]` in each, matching the existing pattern already used by
test_inspect_pr_recovers_startup_failure_before_other_actions for the
one test that intentionally exercises this integration.

Reproduced and verified with GITHUB_ACTIONS=true set locally under both
Python 3.12 and the CI-pinned 3.14: full suite 2833 passed, 1 skipped,
21 subtests, 100% coverage on the previously-failing job's tracked
modules.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
seonghobae added a commit that referenced this pull request Sep 5, 2026
…UB_ACTIONS-agnostic (#1896)

recover_current_head_startup_failures() only runs inside inspect_pr()
when os.environ["GITHUB_ACTIONS"] == "true" (#1846), so it silently
never fired in a developer's local shell -- but GitHub Actions sets
that variable for the entire job, including the pytest process that
runs this very test file. 14 pre-existing tests (12 sharing the
cancel_stale_pr_runs stub, 2 closing empty PRs) call inspect()/inspect_pr()
with dry_run=False and never anticipated this side effect, so in CI they
hit the real recovery path: one cluster used the fixture's placeholder
headRefOid="head" and blew up in validate_git_sha, the other supplied a
real sha but its narrow `run` stub didn't accept the recovery path's
extra kwargs. Stub recover_current_head_startup_failures to a no-op
`[]` in each, matching the existing pattern already used by
test_inspect_pr_recovers_startup_failure_before_other_actions for the
one test that intentionally exercises this integration.

Reproduced and verified with GITHUB_ACTIONS=true set locally under both
Python 3.12 and the CI-pinned 3.14: full suite 2833 passed, 1 skipped,
21 subtests, 100% coverage on the previously-failing job's tracked
modules.

Co-authored-by: Claude Sonnet 5 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant