feat: add read-only Actions queue health evidence - #1150
seonghobae wants to merge 79 commits into
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📝 WalkthroughWalkthrough시간별 GitHub Actions 큐 상태 수집 기능을 추가했습니다. 허용 저장소의 실행과 작업을 읽기 전용으로 조회하고, 실행 상태와 queue-age SLO를 분류합니다. 결과를 JSON·HTML 아티팩트로 저장하며, 워크플로 계약과 처리 경로를 테스트합니다. ChangesActions Queue Health
Estimated code review effort: 4 (Complex) | ~45 minutes Merge Risk: 🟡 Moderate · up to The new scheduled read-only queue-health collector can remain stuck on an unresponsive GitHub API call and occupy the workflow for up to its platform limit, delaying later runs; bounded API and job timeouts should be added before merge, with several smaller validation and robustness follow-ups remaining. Sequence Diagram(s)sequenceDiagram
participant Scheduler as GitHub Actions scheduler
participant Workflow as actions-queue-health.yml
participant Script as actions_queue_health.py
participant GitHub as GitHub API
participant Artifact as Actions artifacts
Scheduler->>Workflow: 매시간 collect 작업 실행
Workflow->>Script: allowlist와 토큰으로 수집 시작
Script->>GitHub: 저장소·PR·실행·작업 읽기 요청
GitHub-->>Script: 큐 및 runner 상태 반환
Script-->>Workflow: JSON·HTML 보고서 생성
Workflow->>Artifact: 실행별 보고서 업로드
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Current-main successor for #1142: head |
|
Current-head review request for PR #1150:
Please provide a fresh independent review for this exact head. Protected current-head checks and qualifying approval remain required before merge. |
|
Current-head verification for |
|
@opencode-agent Review exact current head |
c3697b6 to
f92f08e
Compare
|
@opencode-agent Review exact current head f92f08e against main@2cce96f8. Rebased the read-only Actions queue-health evidence onto current main; allowlisted repositories, bounded pagination/identity retries, named read credentials, and no write/dispatch/merge permissions are preserved. Verified: 76 queue-health/commercial-readiness tests, actionlint, compileall, interrogate, ruff, and git diff --check passed. |
|
Exact-head ecosystem review requested. Verify the current source and checks only; preserve protected gates and read-only credential boundaries. @opencode-agent review |
|
@opencode-agent Review the current exact head of the read-only Actions queue-health successor. Verify complete bounded pagination, exact pull-request/head identity, transient incomplete-response retry, runner-assignment and queue-age classification, deterministic JSON/accessible HTML, and the absence of cancellation, dispatch, branch, merge, or credential-expansion authority. Reacquire exact-head quality, security, CodeQL, SAST, dependency/SBOM, and formal review evidence. Do not alter the branch. |
|
Current exact head The read-only queue-health collector bounds Actions workflow-run responses to 50 records per page, rejects path-traversal repository segments, retries one transient incomplete PR identity response after a bounded delay, records repository-scoped collection failures as explicit incomplete evidence, rejects duplicate repositories, applies a 30-second API subprocess timeout, and has a 30-minute workflow ceiling. It never cancels runs, changes branches, dispatches workflows, or mutates merge state. Systematic RED → GREEN:
Exact-head hosted evidence:
The eight security/SBOM/CodeQL runs and a qualifying exact-head formal Reviews API verdict remain non-passing prerequisites. |
|
Exact current head evidence for
Please review and evaluate Checks against this exact SHA only. No self-approval or predecessor-head evidence transfer. |
|
Final exact current head is now |
|
Correction to my immediately preceding comment: the exact final HEAD is |
|
@opencode-agent Please perform the independent review on exact current head |
|
Fresh superseding leaf canary after the Gyeot migration branch advanced by ordinary descendants: |
|
DiskSage is now a live canary for this owner lane and was missing from the current allowlist. I opened stacked Draft #2196 exact Current DiskSage evidence includes #405 Test This child is not a competing collector writer and does not change workflow/collector logic, cancel/rerun jobs, or synthesize status. Please adopt it by ordinary/non-force succession when this owner next reconciles protected |
Ordinary non-force reconciliation of protected main@91be6442906c7b6b4f600272c953699708394327 into the canonical queue-health owner. The six Pingora/OpenCode mainline paths do not overlap the 13 queue-health owner paths; predecessor evidence does not transfer and the resulting exact head must reacquire gates.
|
Fresh owner-sweep found a real sibling-overwrite hazard: #2196 (DiskSage) and #2200 (LineageWeave) both modify |
|
Fresh TEPP canary for the queue-health owner: |
|
Pingora queue-health enrollment handoff (read-only owner path; no Fresh exact evidence on
These are exact-head queue specimens, not source success and not permission for leaf-level rerun/cancel, no-op freshness commits, runner-selector churn, or synthesized GREEN. Preserve identity at least as |
|
Queue-health evidence from an unenrolled repository, in the resolved form of the materialized-pre-runner class.
What the portal adds is not another stuck snapshot. Every report on this lane so far captures the class while it is still stuck ( All four are the
Exact job identities for the two most recent:
This bears on the RED/GREEN closure criterion in the PR body. RED is currently defined to include "an exact-current materialized required job with no runner assignment, checkout identity, or steps." During its dwell each of the four jobs above read exactly that way — Dwell length does not separate them either. The four waits are 4h 21m, 6h 01m, 4h 08m and 5h 20m: they scatter between four and six hours and do not converge, so no duration threshold learned from this repository would be sound. If the collector is to call RED at read time, the discriminator has to be something other than "materialized and no runner yet" or "queued longer than N" — otherwise recovering waits of this length will be classified RED, and the criterion will report incidents that resolve themselves. Two further observations from the same window, offered as observation only:
Requested handling, matching the pattern used for DiskSage and Pingora: keep any portal enrollment as a bounded child in this Enrollment here would be observability only. It does not transfer or synthesize GREEN for the portal's 36 open PRs, whose blocker is an inherited CVE on its protected Disclosure on head freshness: Generated by Claude Code |
… not in it The stall section has been carrying its four measurements as an unexplained observation. It does not have to. ContextualWisdomLab/.github#1150 is an open owner lane for read-only Actions queue-health evidence, and one of the incident classes it classifies is a job that materializes with no runner assignment — which is exactly what all four portal instances are. The portal is not in that lane's allowlist; it names seven repositories and this is not one. Enrollment there is done as a bounded child PR carrying one allowlist entry and its contract test, so the note says plainly not to build polling or classification here instead, and that enrollment would be observability only — it moves no PR toward GREEN. The measurements were reported to that lane. What was worth reporting was less the numbers than what they do to its closure criterion: RED there includes a materialized job with no runner assignment, checkout identity or steps, and during their waits all four read exactly that way before recovering on their own to SUCCESS. A single point-in-time read cannot separate that from a real incident, and neither can dwell length, which scatters from 4h08m to 6h01m with no threshold to learn. Nothing changes operationally here. An empty check list is still a wait, and there is still nothing to fix in this repository. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QpbqAeggRho3fQA1gn34UY
|
Fresh cross-repository canary from the TEPP provenance owner path: Current exact-head runs are Repository Quality The current #1150 allowlist does not include TEPP #527 remains independently queued on exact |
|
Fresh enrollment child created for the TEPP provenance canary path: #2212 The child preserves a realistic ordinary-history RED Canary evidence is #2212 stays Draft; enrollment is not GREEN and does not authorize leaf reruns/no-op commits/runner churn/cancellation/gate weakening. Normal parent integration plus a collector observation bound to current repo/PR/head/workflow/job identity is still required. |
|
Correction to the dwell range I reported above — a fifth portal instance resolved and it falls below the lower bound I quoted.
So the interval is 3h 16m – 6h 01m across five instances, not the 4h 08m – 6h 01m I stated. I have no way to edit the earlier comment, so please read the range there as superseded by this one. The direction matters more than the number. Going from four samples to five did not narrow the interval — it widened it at the bottom. If the collector were to adopt any queued-duration threshold, this repository would have supplied a lower bound that the very next observation violated. That is a stronger version of the point in the previous comment: the discriminator between a real incident and a recovering wait should not be dwell length at all. Same disclosures as before. No rerun, no-op commit, runner-selector change, cancellation, or status synthesis; this was the ordinary Generated by Claude Code |
|
Fresh exact-current leaf specimen for the queue-health owner; no leaf rerun/cancel/source mutation performed.
This is an exact instance of #1150's pre-checkout admission class: a required current-head job exists, but there is no runner assignment, checkout identity, or executed step. Treat the leaf source/test state separately from this control-plane state; do not blind-rerun the leaf or synthesize success. Owner acceptance remains: preserve repository/PR/head/run-attempt/job identity and queue age in collector evidence; classify |
|
Valid current-source finding on exact
This matters because #712 now has an independently observed specimen of Recommended test-first owner repair, without changing workflow triggers, runner selectors, cancellation/rerun behavior, credentials, or leaf repositories:
The sibling enrollment #2211 also just produced useful same-head evidence: SAST I am not writing onto this canonical owner branch from the OriginWeave lane; this comment is the repair handoff so the single writer can add the RED/GREEN on the owner tree. |
seonghobae
left a comment
There was a problem hiding this comment.
Fresh downstream queue-health specimen for the existing owner contract; no leaf rerun or source churn performed.
Consumer: ContextualWisdomLab/html4tree#703@57303f781c14887b472c609a4814278d1e8bb041, required CodeQL PR run 34916152101.
Observed job sequence on the unchanged head:
Detect CodeQL languagesjob104214085539: runner assigned, checkout executed, SUCCESS.CodeQL compatibility analysis (actions)104264425770: runner assigned; current-head verdict polling completed; enforcement step FAILED.CodeQL compatibility analysis (java-kotlin)104264425989: same pattern, FAILED.Dispatch current-head CodeQL scan104339783808: still QUEUED withrunner_id=0, empty runner identity,steps=[]; materialized at2026-09-15T10:10:27Z.
The parent run remains queued even though earlier jobs executed. This is not evidence that #703's Kotlin change failed CodeQL; the dispatch job has not obtained a runner or checkout. Keep this in the existing pre-runner/current-head-verdict incident class and fail closed. GREEN remains a real runner assignment + exact-head dispatch/scan + terminal verdict on the unchanged leaf head. Do not blind-rerun #703, add a no-op commit, weaken the required check, or transfer the already-successful CI/SAST/Security results into CodeQL.
|
Canonical owner repair child opened: #2213 ( Parent is this exact owner head Fresh compare is ahead 2 / behind 0 with only |
|
#2213 current exact is now Re-review found no different causal defect: failure diagnostics survive collection, only zero-step/no-runner failed jobs become |
|
Fresh TEPP Ready-state canary on unchanged exact head: |
|
Fresh queue-health canaries extend the same pre-checkout class without touching leaf workflows:
|
|
Fresh child-owner settlement specimen on #2213 exact |
|
Fresh TEPP canary after successor consolidation: |
Canonical read-only Actions queue-health owner lane and current-main successor for #1142. It classifies organization Actions admission states without cancelling/rerunning observed workflows, mutating leaf branches, synthesizing success, weakening required checks, or merging repositories under observation.
Current protected-base reconciliation — 2026-09-14
Protected
.github/mainis exact91be6442906c7b6b4f600272c953699708394327. Fresh comparison from prior #1150 exactfbcf718f69a39b4d80dcc3f9d03a04b121d4a171to protected main showed the branches diverged only because main had one new Pingora/OpenCode merge touching six paths; none overlap the 13 queue-health owner paths.The owner was therefore reconciled again without force. Current exact
42bb922f03bf75aed1bc1931d9fbaf04a5433e20is a two-parent descendant offbcf718...and protectedmain@91be644.... Its tree preserves the #1150 owner paths and overlays the six current protected-main blobs. Comparison againstmain@91be644...is ahead-only/behind 0; the effective queue-health delta remains the same bounded owner implementation/config/docs/tests. Predecessor checks/review do not transfer.Current exact hosted generation remains nonterminal. SAST
34831634664and Agent Review Runtime Quality CI34831634694are now terminal SUCCESS on unchanged exact head42bb922f...; Python Security34831634654, Security Scan34831634718, and CodeQL PR34831634674remain queued/nonterminal. These successes are owner-head evidence only and do not transfer to enrollment children such as #2200.Owner-side incident contract
Independent ContextualWisdomLab repositories reproduce distinct pre-source-execution states:
startup_failurebefore any job exists;The collector keeps those states distinct and fail closed. Ordinary head-bound evidence uses bounded supported workflow-run queries and local classification.
pull_request_targetcancellation candidates are accepted only after linked current-open-PR number/head identity is proven. PR identity is re-read after terminal/job evidence; transient incomplete reads receive bounded retry while persistent incompleteness or identity drift remains a hard evidence failure.DiskSage enrollment child
Fresh DiskSage evidence now reproduces this incident class, but #1150's explicit bounded repository allowlist did not include
ContextualWisdomLab/disksage. Child #2196 owns only that enrollment delta and its exact-equality contract test. After this parent reconciliation, #2196 was itself non-force restacked as exact401a6ea6def79ecfa79072c8fa5ddf548cc9243d, ahead-only of this owner with exactly two effective changed paths. It remains Draft/nonterminal and must not be treated as incident GREEN.RED / GREEN closure criterion
RED is either an exact-current required workflow terminating before jobs exist or an exact-current materialized required job with no runner assignment, checkout identity, or steps. GREEN requires unchanged exact owner/leaf heads to obtain actual runner assignment, checkout identity and terminal required conclusions under the current ruleset while the collector continues to distinguish pre-job and pre-checkout cases fail closed.
Merge only when this unchanged exact head has terminal applicable protected checks, all valid findings are resolved, and live review policy is satisfied. Queued, pending, cancelled, startup-failure and predecessor results are incomplete evidence. No self-approval, administrator bypass, force update, destructive rebase, no-op freshness commit, blind rerun, runner-selector churn, cancellation campaign, gate weakening or synthetic success is authorized.