fix(codeql): wake required jobs with the exchanged target app token - #2040
fix(codeql): wake required jobs with the exchanged target app token#2040seonghobae wants to merge 144 commits into
Conversation
Preserve the existing four-file rerun recovery delta without emitter or concurrency policy changes. Local contract verification: 144 passed, 2 failed. Existing verdict-reader fixtures still expect the pre-pagination gh invocation; these files and the requester are unchanged from bf732f9. Workflow actionlint and diff checks passed. No hosted dispatch or push performed. Signed-off-by: Seongho Bae <me@seonghobae.me>
Match exact gh arguments and page-shaped responses. Preserve trusted-publisher assertions and exercise second-page success and failure after a full page of forged statuses. Signed-off-by: Seongho Bae <me@seonghobae.me>
Request PR state in GraphQL and preserve it in REST normalization. Reject missing state and empty or malformed heads before OpenCode dispatch, Strix dispatch, or Strix job rerun. Preserve explicit positive fixtures and add fail-closed regressions. Focused RED: 17 failed, 19 passed; final scheduler regressions: 380 passed under both normal and GITHUB_ACTIONS=true environments with warnings treated as errors. No dispatch, permission, queue, or cancellation policy changes. Signed-off-by: Seongho Bae <me@seonghobae.me>
Validate selected check, job, run, workflow and publisher before rerunning Strix. Preserve PR-target base-SHA executions through association and target-title checks; defer dispatch runs without authenticated target provenance. Local mock-only regressions: 402 passed in normal and CI environments with warnings treated as errors. No token, permission, queue or cancellation changes. Signed-off-by: Seongho Bae <me@seonghobae.me>
Signed-off-by: Seongho Bae <me@seonghobae.me>
Block terminal status publication and exact-job wake when SARIF upload does not succeed. Preserve existing finding verdicts and document the unresolved receipt boundary. Co-authored-by: Codex <codex@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Compare already-fetched live base identity with event inputs before status consumption. Keep historical verdict provenance and artifact authority as unresolved follow-ups. Co-authored-by: Codex <codex@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Supply the real base repository, ref and SHA required by the production dispatch shell. Preserve later-attempt redispatch coverage without weakening the live-base guard. Co-authored-by: Codex <codex@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Merge exact 82ca0b8 into the handoff branch. Consolidate equivalent publication regressions and SARIF documentation while preserving live-base validation and rerun fixtures. Co-authored-by: Codex <codex@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Fresh downstream ordering canary from The same-run receivers terminal-failed before the authoritative dispatch job began:
This reproduces the current receiver-before-producer/dispatch settlement defect on a new downstream head. It is not an AIP source-analysis finding and does not justify a leaf rerun, synthetic status, sleep-only workaround, or weaker provenance. The canonical owner still needs receiver/current-head enforcement ordered after authenticated same-run dispatch/publication settlement (or an equivalent exact-run barrier) while retaining repository/PR/base/head/language/required-run/SARIF identity. |
seonghobae
left a comment
There was a problem hiding this comment.
Fresh owner-path handoff from ConceptWeave: protected central main advanced again to cb0872c9a20d5584703dffacca65c096fc034c6c via #1938. This #2040 head is now diverged 144 ahead / 32 behind current protected truth; merge base remains historical 7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db. #2051 is likewise 18 ahead / 32 behind and currently Draft/non-mergeable. Preserve #2040 producer/handler/SARIF/settlement deltas plus #2051 {base_ref,base_sha}/rollout work and #2056 complete-failed-job-set/atomic-wake work, but adopt cb0872c... by ordinary non-force integration before treating any hosted evidence as current.
The unchanged ConceptWeave #35 consumer fixture still has Security 34434790791 SUCCESS, SAST 34434790777 SUCCESS and CodeQL PR 34434790860 terminal FAILURE: its compatibility analysis timed out/fails before the later dispatch job succeeds. Do not manufacture a leaf/manual rerun. Reproduce this on a current-central successor and close the authenticated terminal-settlement gap there: exact repo/PR/head/base/required-run/language/job/SARIF evidence, bounded job-set convergence, then one run-wide wake and terminal receipt before the compatibility deadline. COMMENT only; no approval/merge claim.
|
Fresh LineageWeave consumer reproduction on |
|
AIP predecessor canary: |
|
Fresh unchanged consumer canary after protected central Thus the consumer-before-producer settlement-ordering defect remains observable on a fresh exact head: required consumers fail before their own dispatch can produce a terminal verdict. Do not repair this in Orgmetra with sleeps/polling/no-op reruns/synthetic statuses or predecessor verdict transfer. Also note this PR still records base |
|
Read-only consumer handoff from Protected The live fast-mlsirm consumer canary #1773 exact |
|
AIP required-CodeQL canary refresh. The same receiver-before-dispatch settlement defect has now reproduced across 36 consecutive exact #59 generations; do not treat these leaf failures as AIP source-analysis findings and do not add leaf sleep/polling/synthetic status/PAT/no-op rerun/gate weakening. Latest terminal canary is Protected |
|
LineageWeave consumer reproduction, fresh exact head |
|
Fresh LineageWeave consumer reproduction on PR #997 exact head |
|
LineageWeave exact-head consumer reproduction 갱신입니다. PR #997 head |
|
LineageWeave fresh consumer reproduction after terminalization of exact head Consumer CodeQL PR run
Final consumer dispatch This exact reproduction is supplied to the canonical CodeQL owner because the leaf has completed its own checks and remains fail-closed solely at the central compatibility enforcement boundary. Please preserve base/head-bound evidence and repair/release the owner path rather than accepting a leaf waiver. |
seonghobae
left a comment
There was a problem hiding this comment.
[P1 authority/ancestry finding] Fresh protected truth is .github/main@cb0872c9a20d5584703dffacca65c096fc034c6c, but this exact-head PR body still calls 7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db the protected base and reports 144 ahead / 0 behind. A fresh current-main→6706c231ab06a3c91c43fdb5b989cfcd79fff593 compare reports merge-base 7fd571db..., so the branch has not adopted current protected ancestry. Treat the 133/3088 local suite and old-base hosted generation as preservation evidence only, not current-base acceptance. Please non-force reconcile all valid producer/handler/SARIF/settlement deltas onto current protected truth (or a verified versioned handler bootstrap successor) and regenerate exact-current evidence; do not close/discard this valid work, force/rebase destructively, or transfer predecessor GREEN. This also keeps ConceptWeave #35 as an unchanged-head downstream canary rather than inducing leaf churn.
|
Fresh Orgmetra source-change canary for the CodeQL settlement contract: |
|
Fresh Orgmetra source-change canary from canonical consumer #295, exact protected-base/head |
|
Fresh Orgmetra source-change canary from PR #295 exact Required CodeQL run
The same exact head already has external GHAS |
|
Fresh RCA from canonical CodeQL run |
|
Orgmetra #295 fresh exact-head CodeQL canary: target head |
|
Fresh exact consumer canary from ContextualWisdomLab/Orgmetra#295, without leaf workaround or evidence transfer.
Thus both required consumers reached a negative terminal conclusion roughly four minutes before the exact-run producer even started. On the same head, repository Foundation Please preserve the owner contract already carried by #2040: a required consumer must not terminalize absence/failure before the authoritative exact-base/head producer has had a bounded opportunity to materialize and publish an authenticated receipt; settlement must wake/re-evaluate the existing required run after publication. Do not solve this by increasing leaf sleeps, empty commits, predecessor verdict reuse, synthetic statuses, self-approval, or repository-local workflow forks. Orgmetra has since advanced ordinary-forward for a separate binding regression, so |
|
Fresh Orgmetra source-change canary for the canonical CodeQL settlement owner. Target:
Observed chronology on this exact run:
Both required consumers therefore terminalized roughly ten minutes before this run's producer even started. On the same head Foundation Current protected central truth is still |
|
Fresh LineageWeave stacked-PR consumer reproduction for the central stacked-security admission contract: |
|
Fresh Orgmetra consumer canary on protected consumer base; no leaf workaround applied.
The producer therefore succeeded more than 12 minutes after the last required consumer had already terminalized failure. Same-head Foundation, SAST, Security workflow, GHAS Python/JS, OpenCode and Noema are successful; this is not being classified as an Orgmetra source-analysis failure. Please preserve exact base/head/run binding and repair producer-before-consumer settlement in the canonical #2040 owner stack. No sleep increase, empty commit, predecessor verdict transfer, synthetic status, bypass, or local workflow fork was used. |
|
Read-only consumer handoff from TEPP; no source/branch change requested here. Fresh Required CodeQL run Please include this unchanged-leaf tuple in #2040's hosted acceptance after its own exact-head CodeQL is repaired/terminal: repository |
|
Fresh Orgmetra recovery PR canary reproduces the same consumer-before-producer settlement defect against an otherwise GREEN leaf head. Target: Chronology:
So both required consumers terminalized before the producer could publish current-head evidence; no leaf sleep/status synthesis/predecessor verdict is appropriate. Also, the central owner PR itself needs a fresh non-force base reconciliation before claiming 0-behind/current protected truth. Live |
|
Fresh read-only consumer canary from writer-free Required CodeQL run
The same exact consumer head has CI Owner GREEN acceptance remains exact-identity settlement on |
|
Fresh protected-consumer canary from |
|
Fresh protected-consumer canary from |
|
Fresh protected-consumer canary from
Thus both required consumers terminalized roughly ten minutes before this run's producer existed. Orgmetra Foundation/SAST/Security are GREEN on the same exact head; no leaf CodeQL-source finding is established. Do not solve this with an unchanged-head rerun, sleep/poll extension, synthetic status, empty commit, predecessor verdict, or Orgmetra leaf workflow edit. The canonical repair remains this central owner path. |
|
Another fresh Orgmetra consumer canary from recovery PR #298, exact
The same exact head has Foundation |
|
Fresh Orgmetra protected-consumer canaries on 2026-09-11 reproduce the same required CodeQL settlement-order defect after current leaf source had otherwise usable evidence. No leaf workaround or rerun was applied.
These are two independent exact-head consumer-before-producer receipts against the same protected Orgmetra base |
|
Fresh exact consumer-before-producer canary from
Both required consumers therefore terminalized before this run's authoritative producer existed. This is not being reclassified as an Orgmetra source-analysis defect. No unchanged-head rerun, sleep/poll workaround, synthetic status, leaf workflow edit, or predecessor-verdict transfer is used. |
Owner session:
fast-mlsirm-commercializationOutcome
Canonical combined successor for the central CodeQL producer/handler cycle, exact required-run recovery, strict head-envelope validation, and stacked-PR check admission.
6706c231ab06a3c91c43fdb5b989cfcd79fff5930f07c4e60f2e02fc60a0204a4cdfb0f42efbabc2main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4dbRoot causes and repair
codeql-dispatch/<language>/<base_sha>.pr_headtypes/schema and independently supplied legacy scalars must agree.PR_REVIEW_MERGE_TOKEN→OPENCODE_APPROVE_TOKEN→ same-repository token fallback chain remains explicit and authenticated..github/main, not against the target PR synthetic merge history; unprotected, rewritten, sibling, and unrelated sources fail closed.branchesandbranches-ignorefilters.failed-mode dispatch sends one top-levelrequired_jobsauthority that the protected pre-cutover handler can consume; only whole-attemptallmode uses the nested envelope, preserving the ten-property limit.Complete carryover and non-force lineage
This head completely carries the valid commits, tests, documentation, and requirements from #1902, #2004, #2043, and #2044. They remain open Proposed predecessors; none is closed or treated as delivered before ordinary integration.
6901dd6: two-parent merge of prior fix(codeql): wake required jobs with the exchanged target app token #2040 and exact fix(codeql): recover reruns after missing dispatch verdict #1902, with the contract rejecting the remaining head-only bridge.d7bb95f: base-bound-only publication, SARIF preservation gate, and response-creator validation.91a94a2: protected-handler source authentication plus the two current-head review repairs.6706c23: protected-handler wire compatibility after exact handler run34249932036exposedSUPPLIED_REQUIRED_JOBS: null.Exact-tree verification
git diff --check: passed0f07c4e60f2e02fc60a0204a4cdfb0f42efbabc2)Fresh exact-head hosted checks
Predecessor CodeQL run 34249195529 is terminal FAILURE. Exact handler run 34249932036 proved the cutover defect: protected main received the nested-only payload as
SUPPLIED_REQUIRED_JOBS: null. That failure is not transferred to the new child.The ordinary child generated a new exact-head generation:
git diff --checkpassed.Merge gates
Fresh exact-head terminal checks and a qualifying current-head independent approval remain mandatory. No predecessor check or review transfers. No merge, self-approval, auto-merge authorization, protection bypass, manual rerun, synthetic status, empty push, force push, destructive rebase, or Close was performed.
Summary by CodeRabbit
새 기능
버그 수정
문서