Repository navigation
Queue-flake anchor: src/protocol.metadata-redaction.test.ts #20608
Description
Activity
objectstack-fleet commented
on Sep 29, 2026 ContributorMore actionsRoot cause: this is not a flake ·
domain:specseat 2 (session_014EJ1ED8X4MMrT18BhVx4tx), the seat that drives PR #20593 · 2026-09-29T07:19ZBoth queue failures on
src/protocol.metadata-redaction.test.tscome from one real semantic conflict. The second PR is collateral.- The conflict:
- PR feat(lint): os validate refuses an api flow with no per-flow secret #20593 (After #20529, authoring surfaces still teach or pass an
apiflow with no secret:skills/objectstack-automationcalls it optional, andos validatepasses it #20553) addsflow-api-trigger-secret-missingto the runtime metadata publish gate (CLI_AND_RUNTIME). - [security] a flow's inbound-hook secret (
config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552's landingc96beb2707makes definition reads withholdnodes.<i>.config.secret, and restores the stored secret on write. - The gate judges the incoming, redacted body before that restore. So a read→save round trip of a signed
apiflow is refused:flow/inbound_hook failed author-time validation … [flow-api-trigger-secret-missing].
- PR feat(lint): os validate refuses an api flow with no per-flow secret #20593 (After #20529, authoring surfaces still teach or pass an
- PR feat(lint): os validate refuses an api flow with no per-flow secret #20593's queue run
36532203829(groupd7151c1b94= its head onc96beb2707) is the regression's own run. PR feat(lint): os validate refuses an api flow with no per-flow secret #20593's own CI was green only because its base predated [security] a flow's inbound-hook secret (config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552. - PR docs(spec): re-anchor the dead tracker citations in the packages/spec/src remainder to the commits and ADRs that decided them (stage 6) #20606's run
36533810671(groupf1d96c56b3) was built on top ofd7151c1b94, so it inherited the failure. PR docs(spec): re-anchor the dead tracker citations in the packages/spec/src remainder to the commits and ADRs that decided them (stage 6) #20606 is comment-only (dead-citation re-anchoring) and never touchesmetadata-protocol. It is re-queued on a group without PR feat(lint): os validate refuses an api flow with no per-flow secret #20593 (ba4648dadf). - What happens next: PR feat(lint): os validate refuses an api flow with no per-flow secret #20593 is out of the queue. Its dev is reproducing the failure on a merge of
mainand root-causing the gate-versus-restore order. PR feat(lint): os validate refuses an api flow with no per-flow secret #20593 re-enters the queue only whenprotocol.metadata-redaction.test.tspasses on its new head. This anchor can close when that lands; no re-run or quarantine is owed.
Generated by Claude Code
- The conflict:
objectstack-fleet commented
on Sep 29, 2026 ContributorMore actionsBlocked-by: #20553
Triage: route —
tests·priority:p2·domain:spec·pm:blocked. Not a flake: one semantic conflict, whose fix is PR #20593's CLI-only reshipTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-09-29T07:56Z. ⛔ Not a claim, ⛔ not a dispatch.The cause is named (
domain:specseat 2,5885578382).- PR feat(lint): os validate refuses an api flow with no per-flow secret #20593 put
flow-api-trigger-secret-missingon the runtime publish gate. That gate judges the redacted body before [security] a flow's inbound-hook secret (config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552's carry-forward, so [security] a flow's inbound-hook secret (config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552's round-trip pins failed in PR feat(lint): os validate refuses an api flow with no per-flow secret #20593's queue run36532203829. - PR docs(spec): re-anchor the dead tracker citations in the packages/spec/src remainder to the commits and ADRs that decided them (stage 6) #20606's ejection (
36533810671) was built on that group. It is collateral, and docs(spec): re-anchor the dead tracker citations in the packages/spec/src remainder to the commits and ADRs that decided them (stage 6) #20606 has since landed. - It is the Queue-flake anchor: src/data/filter-number-comparand-declared-type.test.ts #20455 shape: a deterministic conflict, not a flake. ⛔ Not quarantined.
Blocked on #20553, whose PR #20593 now ships the rule CLI-only. When #20553 closes with PR #20593 landed green through the queue, the unlock scan closes this anchor with that queue run as evidence. Restoring the runtime surface properly is #20611.
- PR feat(lint): os validate refuses an api flow with no per-flow secret #20593 put
- addedpriority:p2Medium: important, M3Medium: important, M3and removed
on Sep 29, 2026 objectstack-fleet commented
on Sep 29, 2026 ContributorMore actionsTriage: close —
completed. TheBlocked-by: #20553condition is met: PR #20593 landed green through the merge queueTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-09-29T10:14Z. ⛔ Not a claim, ⛔ not a dispatch.This anchor was routed (
5886083783) as one semantic conflict, not a flake, with the rule that the unlock scan closes it once #20553 closes with PR #20593 landed green through the queue. Measured:- After #20529, authoring surfaces still teach or pass an
apiflow with no secret:skills/objectstack-automationcalls it optional, andos validatepasses it #20553 closedcompletedat 2026-09-29T09:18Z, with PR feat(lint): os validate refuses an api flow with no per-flow secret #20593 merged ase651556e2d. The PR shipsflow-api-trigger-secret-missingCLI-only, so the runtime publish gate no longer judges the redacted body. - The queue group is green.
gh-readonly-queue/main/pr-20593-…ate651556e2d:CIrun36546065933issuccess, as are the group's other merge-group checks. - The push to
mainis green. On the same commit, CI run36548294481passed Test Core 1/6–6/6, which includessrc/protocol.metadata-redaction.test.ts. None of the commit's 100 check runs failed (76success, 24skipped).
Restoring the runtime surface properly stays with #20611. If
src/protocol.metadata-redaction.test.tsejects a PR again, the merge-queue-triage workflow re-files a fresh anchor.- After #20529, authoring surfaces still teach or pass an
src/protocol.metadata-redaction.test.tshas ejected 2 pull requests from the mergequeue within a rolling 24 hours — 2 independent hits once
GitHub's speculative stacking is accounted for. This issue is the single place for
that conversation; it is refreshed by the merge-queue-triage workflow on every
further ejection.
This issue is a NAME, not a diagnosis. The workflow that files it reads the
failing test file path out of the job logs and counts PRs; it does not
know whether this is a flake, a load/timing cliff, a semantic conflict between
queued PRs, or a real regression, and it does not act on any of those. No test is
skipped, quarantined or re-queued by it, and no PR is labelled by it — weakening
a gate stays a human act.
What to do with it: read one victim PR's triage comment for the failure REASON
line beside the FAIL line (a timeout and an assertion are the same FAIL line and
opposite diagnoses), decide the cause, and close this issue with the fix or with
the reason it is not one.
Last refreshed by queue build 36533810671 (PR #20606).
Filed by the merge-queue-triage workflow (#4859, aggregation #10128).