Repository navigation
fix(ci): run exact-head gates on stacked pull requests #298
Description
Activity
seonghobae commented
on Aug 20, 2026 ContributorAuthorMore actionsFresh stacked-consumer reproduction for the existing #298/#299 owner path (2026-08-20 UTC):
- Draft test(diagnostics): add hostile-input and browser assurance #285 remains stacked on
feat/writing-diagnostics-package@cb49b1a6d646b5ba15f6aa88e568adf323fe05fc; current exact head is599d2eb86bf60750a26dcfa6b0d69facc1588cc4. - That head contains the release-workflow RED→GREEN repair
f9ab67c...→599d2eb...:src/releaseWorkflowSyntax.test.tsnow requires a finite 60-minutebrowser-release-evidenceceiling, and.github/workflows/release.ymlchanges the same Playwright/system-dependency job from 30 to 60 minutes after the real docs(adr): define revision-bound host-owned writing diagnostics #248/job95570983695mirror-latency reproduction already captured here. - The current exact-head PR-workflow query for
599d2eb...returns zero pull-request workflow generations, while combined status exposes CodeRabbit only. This is therefore a second concrete consumer of the protected-main stacked-base trigger defect; predecessor test(diagnostics): add hostile-input and browser assurance #285 workflow evidence must not be transferred. - Canonical CI repair fix(ci): run exact-head gates on stacked pull requests #299 is still unchanged exact head
b7e9bb8156a3e46204523ab37292566811f560f8, basemain@3b38ead2d00f44eb578d0689087b9293b3dabe1e, Draft, mechanically mergeable, and retains the two-file ownership boundary (.github/workflows/ci.yml,src/workflowExactHead.test.ts). Its exact-head CI/Security/SAST GREEN evidence remains the owner proof.
Acceptance remains unchanged: after #299 eventually integrates under #118/live review governance, #285 and every other stacked PR must independently acquire a fresh exact-current-head repository workflow generation; no parent/predecessor/status/model evidence may substitute. Do not patch #285 CI triggers locally or create a competing CI writer.
- Draft test(diagnostics): add hostile-input and browser assurance #285 remains stacked on
seonghobae commented
on Aug 22, 2026 ContributorAuthorMore actionsFresh stacked-consumer reproduction on the existing #298/#299 owner path:
- Draft test(input): add multilingual browser input baseline #380 is unchanged at exact child head
4d8ee51012a650fbafa0e6188173c4ca328b416e, stacked on canonical parent/basefix/atomic-controlled-sync-200@343d4132574f4cb20eb561928df034154609bab7(fix(data-integrity): keep controlled value sync atomic #201), and GitHub reports it mechanically mergeable. - The exact-current-head workflow query for
4d8ee51012a650fbafa0e6188173c4ca328b416ereturns zero repository workflow generations. Parent/predecessor workflow evidence is therefore non-transferable and this head has no passing CI/Security/SAST evidence. - The child-owned delta remains test/harness-only; patching CI triggers in test(input): add multilingual browser input baseline #380 would create a competing workflow writer rather than repair the causal boundary.
- Canonical CI owner fix(ci): run exact-head gates on stacked pull requests #299 is unchanged at exact head
b7e9bb8156a3e46204523ab37292566811f560f8against protectedmain@3b38ead2d00f44eb578d0689087b9293b3dabe1e, Draft and mechanically mergeable, with the ownership boundary still limited to.github/workflows/ci.ymlandsrc/workflowExactHead.test.ts.
RCA remains falsifiable and unchanged: protected-main CI currently scopes PR execution such that stacked child heads can receive no repository generation; #299 removes that base restriction and independently attests the checked-out exact head. After #299 integrates under #118/live governance, #380 must itself acquire fresh exact-head CI, Security Scan, and SAST generations before any downstream evidence is accepted. No child-local trigger patch, retry of a nonexistent run, or predecessor/parent/status/model evidence should substitute.
- Draft test(input): add multilingual browser input baseline #380 is unchanged at exact child head
- addedarea: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenanceDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behavior
on Aug 22, 2026 - removedarea: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolation
on Aug 23, 2026
Current authoritative state
The stacked-PR/exact-checkout CI evidence defects and bounded browser-evidence timeout defect are repaired on canonical single-writer Ready PR #299 / branch
fix/stacked-pr-ci-gates-298. Protected shipped truth remains exactmain@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact #299 head is1efbd632719b0e54c5a33e3a95224a4bd2f869d3, mechanically mergeable against that unchanged protected base. The effective Inkspan delta remains only.github/workflows/ci.ymlplussrc/workflowExactHead.test.ts; do not create a competing CI writer.Repaired Inkspan-owned evidence defects
pull_requestto basemain, leaving stacked PR heads without the ordinary repository matrix.playwright install --with-depscan consume that budget during infrastructure/package-mirror latency.Historical TDD lineage: stacked-trigger RED
e75a0035d753d8d58a9c04a8c254bf8914135e24-> trigger repair3ea55387d8d7d88a80933b398abda78e42a4496b; runtime-checkout RED85572a50d79a11c27c9171cc9180d7a53128bea0-> exact checkout attestation; browser-timeout REDa74e150c06c22e3caee48446d03c3b0726bfc0f5-> browser-only 60-minute ceiling while build/Office stay at 30.After #299 moved Ready, CodeRabbit identified the fourth, still-valid false-green weakness on predecessor
b7e9bb8156a3e46204523ab37292566811f560f8. Current1efbd632719b0e54c5a33e3a95224a4bd2f869d3slices the three repository workflow jobs independently, binds each timeout and checkout contract to its own job, requires exact-head verification immediately after checkout and before pnpm/setup-python consumers, and checks thepull_requestYAML trigger structurally without a base-branch filter. CodeRabbit marks that Major thread addressed/resolved.A later Devin informational observation correctly notes that the repository runtime check compares local
HEADwith the same immutable event SHA supplied to checkout. That proves checkout honored the event-bound ref; independent live PR/base resolution remains the separate governance/review step before lifecycle mutation and is not silently claimed by the job assertion.Exact-current-head evidence
For unchanged exact #299 head
1efbd632719b0e54c5a33e3a95224a4bd2f869d3:32635939468: completed / success;97185600342: success, including exact source-head checkout verification, typecheck, exact 100% owned-production coverage, library build, packed-package verification, and demo build;97185600177: success, including exact source-head checkout verification, Playwright dependency/revision installation, and real cross-engine evidence inside the bounded 60-minute ceiling;97185600282, 3.1297185600292, 3.1397185600341, 3.1497185600286: success with exact source-head checkout verification, dependency consistency, 100% docstring/branch coverage, wheel, and packaged schema/license gates;32635939483: GitHub aggregate status is success, but this is non-passing / false-green supply-chain evidence. Dependency-review job97185600223checked out synthetic merge12668622e38473c14dbb7d22bb9e3e0c05f1ea8a; its exact3b38ead2d00f44eb578d0689087b9293b3dabe1e...1efbd632719b0e54c5a33e3a95224a4bd2f869d3support probe returned HTTP403, emittedDependency review is unavailable for ContextualWisdomLab/inkspan; skipping dependency-review hard gate., wrotesupported=false, skipped the pinned dependency-review action, and still concluded green. Foreign owner:ContextualWisdomLab/.github#810, active repair PR #897;32635939469: GitHub aggregate status is success and the scan reported no findings, but exact-source evidence is non-passing because job97185600190checked out synthetic merge12668622e38473c14dbb7d22bb9e3e0c05f1ea8arather than source head1efbd632719b0e54c5a33e3a95224a4bd2f869d3. Foreign exact-submitted-revision owner:ContextualWisdomLab/.github#1222, active repair PR #941;COMMENTEDreviews and maintainer thread replies only, qualifying approvals 0;The repository-local #299 CI repair is technically green, but the complete required evidence set is not. A green aggregate central status cannot substitute for a skipped hard gate or a wrong checkout SHA. OSV/Trivy/Scorecard success is not a semantic substitute for the skipped dependency-review action. Pending, queued, skipped, cancelled, absent, neutral, failed, stale, predecessor, status-only, model-only, wrong-checkout, or synthetic-merge evidence is non-passing.
Foreign owner acceptance and downstream boundary
There is no correct Inkspan-local source workaround for the central dependency-review capability path or the central synthetic-merge checkout. The existing foreign owners have been advanced with the exact affected Inkspan SHAs/runs/jobs; do not add a leaf workaround or create duplicate central writers.
Before #299 can be treated as merge-ready under the evidence contract, the corresponding central repairs must reach protected
.github/main, then unchanged or descendant #299 must acquire fresh central evidence that proves:supported=false/skip path is taken;refs/pull/*/mergecheckout evidence.After #299 eventually integrates, every stacked PR must independently acquire its own exact-current-head repository workflow generation; parent/predecessor evidence cannot substitute. The 60-minute browser bound is a finite infrastructure allowance, not permission to make browser evidence optional or unbounded.
The repair is active-PR truth only. Keep #299 Ready but unmerged while these central exact-evidence blockers and every then-live governance requirement remain unresolved. Before merge, refetch unchanged exact head/live protected base, ancestry/mergeability, live governance, formal reviews/threads, and every applicable repository/central workflow. Do not self-approve, transfer predecessor evidence, weaken gates, move protected main, or fabricate release identity.