Publish only completed merge-train candidates to CI - #2523
Merged
Merged
Conversation
cbusillo
added a commit
that referenced
this pull request
Sep 27, 2026
…8dabe00e43c719c: merge PR #2523
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A multi-PR train currently publishes its base and intermediate merges to the checked train branch. In the real two-entry batch from September 25, that started three CI runs, including an intermediate run that scheduled heavy jobs before cancellation.
Build on a deterministic
launchplane/construct/**ref, then publish the existing canonical candidate ref only after every entry's commit and tree have been verified. Required workflows continue to check the final SHA. Publication readback fails closed; construction cleanup failures are reported without replacing an already verified candidate. Failed construction retains its ref for diagnosis and retry, with its locator in native checkpoints and failure responses.Refs #2384. Integrated with #2494's delivered protected batch-PR implementation at
42b8e589. The generated batch PR continues to use only the final canonical candidate SHA.Validation on integrated head
cbeaa9bd: all 3,629 local unittest targets and 249 focused tests pass; whole-repository Ruff, formatting, and mypy pass. Exact-worktree JetBrains changed-file inspection is GREEN with zero findings, successful cleanup, and no worktree mutation. Anthropic claude-opus-5-5 completed planning, implementation, follow-up, and integration reviews with no required fixes remaining. GitHub CI, Security, and CodeQL are complete: 27 checks succeeded and six fork-only checks were skipped, with zero failed or pending checks. A prior Google attempt was unavailable because its CLI denied a command; no personal settings changed.The existing crash window between publication and result persistence can still require rebuilding and rechecking. Failed-build or failed-cleanup construction refs remain recovery evidence; no garbage collector or new record lifecycle was added. Target repositories must exclude construction refs from required-workflow triggers and allow their creation. Read-only checks confirmed this repository's workflows and branch protections meet those prerequisites.
Delivered through the native train at
af13626023b4937ee3dda0b2c6249186383aca33. Post-merge CI, Security, CodeQL, and Launchplane deployment succeeded; the deployed smoke artifact verifies the exact image, health, and database compatibility. #2384 remains open for the next real multi-PR build on the deployed implementation. This change's own delivery used the previous builder and is not that runtime proof. CM delivery remains held under tenant #91.