ops(queue): enroll Noema in queue-health evidence - #2202
seonghobae wants to merge 2 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head source review on f40638618a4b784d1481ea5969fdd632119d818f: effective delta from stacked parent #2201 is exactly the bounded allowlist entry plus the matching exact-equality contract. The test-first predecessor 94c4eae9c55f238b8bde040113f3f08023586be9 makes the contract/config pair intentionally inconsistent; the current head repairs only that inconsistency. No collector logic, permissions, workflow scheduling, runner selection, cancellation/rerun semantics, or leaf-repository source is changed. Hosted current-head checks remain authoritative; this COMMENT is not approval.
|
@coderabbitai review 현재 exact |
|
Fresh RCA on canonical producer
The job consequently ended FAILURE at This is a real non-passing current-head gate, but it is not a semantic CodeQL finding and not evidence against the two-file Noema-enrollment delta. It is a central dispatch-runtime transport failure after runner admission. Do not reclassify it GREEN or blind-rerun it. The owner path should make the authenticated live metadata read tolerate only bounded transient GitHub API transport/5xx failures while preserving exact live base/head/open-state validation and failing closed after the bounded attempt ceiling. #1929 is the existing terminal-publication owner issue; keep this PR Draft until that lifecycle yields authenticated terminal evidence on the unchanged exact head. |
|
Fresh Noema owner evidence for the queue-health enrollment lane:
No leaf rerun, no-op commit, cancellation, selector change, synthetic status, or gate weakening was used. This is additional per-job admission evidence only; it does not change #2202's existing stack/merge authority. |
|
Fresh Noema queue-health specimen from #721 current exact
This is another positive-unassigned per-job specimen for the Noema enrollment contract. No leaf rerun, no-op commit, cancellation, selector mutation, or synthetic conclusion was used. Preserve per-job materialization/admission timing and the runner-less conditional-skip distinction in the canonical collector. |
|
Precision note on the #721 specimen: the current-head CodeRabbit incremental diff review produced no actionable comments, but its summary reports clone-backed analysis was skipped because repository clone access failed. Do not treat that bot review as replacing Noema's queued hosted |
|
Fresh Noema queue-health evidence from successor PR #721, exact This is a new first-wave specimen after #719 already completed its unchanged-head second-wave admission and normal merge. On #721, application At the same observation, the central No leaf rerun, no-op commit, cancellation, runner-selector change, synthetic status, or gate weakening was performed. Keep the Noema leaf Draft until exact-head hosted evidence becomes terminal; this comment is owner-path evidence only. |
Parent integration: #2201. Canonical queue-health owner: #1150. Incident owner: #712.
Finding
Noema #714 reproduced the organization pre-runner admission class on exact
a1228e72565d4280d01e1f877377ee0d3e107178: application, reviewer, Security scope, and patch-validator jobs first materialized without runner identity or execution steps. The canonical queue-health collector's bounded repository allowlist omittedContextualWisdomLab/noema, so the owner implementation could not observe that leaf canary after integration.The retained unchanged #714 generation then produced the complete same-head transition family without rerun or source mutation. Application
34826581397/ job103920031612remained positively unassigned for 4h 50m 26s, then received GitHub-hosted runner1001975480and completed SUCCESS. Reviewer103920031213, Security scope103920034688, and patch-validator-image103920031946likewise received positive runner identities and completed successfully. Security follow-onsscorecard104006051571andtrivy-fs104006051766, which were previously retained as positively unassigned controls, later assigned to runners1001977687and1001977724and completed SUCCESS on the unchanged head. In the same Security generation, scope-conditionedgitleaks,dependency-review, andosv-scanendedcompleted/skippedwith no runner identity; those are terminal non-execution evidence, not positive assignment and not runner-capacity failures.All four #714 required workflows ultimately reached terminal SUCCESS. #714 was then normal-merged into Noema protected
mainby GitHub-verified merge commit159758c16f92dafb884d176fdbf23cb0f5bd69f7. Noema #717 separately repaired its leaf diagnostic so runner-lesscompleted/skippedjobs arerunner_assignment_not_requiredwhile valid runner identity remainsrunner_assignment_observed, and normal-merged as GitHub-verified067ab5045cc16f4096751a03a5fdd19e13a8aa42; that leaf classification does not replace the organization queue-health owner.Noema #718 supplied a second unchanged-head transition specimen on exact
76896a3d4ffb452280395708c8ab7379b4a48c5b. Application CI34957250689/104342163077, reviewer34957250625/104342623689, patch-validator-image34957250908/104342163552, and Security scope34957250711/104342165441first materialized runner-less withsteps=[], then naturally received GitHub-hosted runners and completed SUCCESS without rerun or source mutation. Security fan-outscorecardandtrivy-fslikewise later received runners and completed SUCCESS on the unchanged exact whilegitleaks,dependency-review, andosv-scanremained conditional skips. All four required workflow generations became terminal GREEN, and #718 normal-merged into protected Noemamainas GitHub-verified8595e83b4b6f52c03ca18a480d86f7bde18a9cd6on 2026-09-15.Current Noema #719 now supplies a third, stronger per-job/fan-out specimen on exact
de91e24fdac66c9963c92ca77971d870a48778e4over protected base8595e83b4b6f52c03ca18a480d86f7bde18a9cd6. Application CI35023070872, reviewer-ci35023070921, and patch-validator-image35023070879are terminal SUCCESS. Security Scan35023070896first admittedDetect changed scopejob104563374280to GitHub-hosted runner1001990594and completed SUCCESS after a multi-hour pre-runner wait. That success then materialized second-wavetrivy-fs104621035044andscorecard104621035128at2026-09-16T00:42:52Z; both remain queued withrunner_id=0, empty runner identity, andsteps=[]on the same unchanged head, whilegitleaks,osv-scan, anddependency-revieware terminal runner-less conditional skips. This proves that one unchanged workflow generation can transition from admitted parent work back into a new positively-unassigned fan-out generation; queue health therefore must be classified and timed per job, not only per workflow run.The owner repair remains stacked on #2201 rather than opening a competing sibling against #1150, preserving the existing DiskSage + LineageWeave enrollment and exact-equality allowlist contract.
RED → minimal repair
Test-first exact
94c4eae9c55f238b8bde040113f3f08023586be9changes onlytests/test_actions_queue_health_contract.pysotest_queue_health_allowlist_is_explicit_and_boundedrequiresContextualWisdomLab/noemawhile the config still omits it. That exact source is deterministically inconsistent by construction; no hosted RED is claimed.Causal successor exact
f40638618a4b784d1481ea5969fdd632119d818fadds only the matching config entry. Effective delta from parent #2201 is exactly two owner paths:config/actions_queue_health_repositories.json: enrollContextualWisdomLab/noema;tests/test_actions_queue_health_contract.py: preserve the explicit/bounded exact-equality contract with Noema included.Collector logic, workflow schedule/triggers, credentials, runner selection, cancellation/rerun behavior, check conclusions, Noema source, and required gates are unchanged.
Current exact gates
On unchanged
f406386...:34850945756is terminal SUCCESS.34850945652is terminal SUCCESS after delayed hosted-runner admission; no source mutation or rerun was needed.34850945674is terminal FAILURE because theactionsandpythoncompatibility jobs ran before an authenticated current-head producer verdict existed and correctly failed closed after observingVERDICT_STATE=pending. This is not a semantic CodeQL finding on the enrollment delta.Dispatch current-head CodeQL scanjob104196652749received GitHub-hosted runner1001981210and completed SUCCESS at2026-09-15T03:39:51Z, creating canonical producer run34925844944.validate-dispatchjob104243619132later received GitHub-hosted runner1001983938at2026-09-15T10:25:10Z. OIDC/OpenCode App token exchange succeeded. The subsequent trusted live-PR metadata bind failed becausegh api repos/ContextualWisdomLab/.github/pulls/2202returned HTTP 502. The job therefore completed FAILURE at10:25:26Z, and downstreamCodeQL dispatch scan104344143885correctly completed SKIPPED.The current blocker is therefore no longer pre-runner admission on this producer. It is a fail-closed central dispatch-runtime transport failure while obtaining authenticated live PR metadata. The 502 is not a semantic CodeQL finding and does not invalidate the two-file enrollment delta, but it is non-passing evidence and must not be reclassified GREEN. Existing terminal-publication owner #1929 records the bounded-retry requirement for transient GitHub API 5xx/transport faults while keeping exact live PR/base/head/open-state validation strict.
Acceptance
This enrollment does not classify the incident as GREEN and does not authorize blind reruns, no-op commits, selector changes, cancellation, predecessor-status transfer, synthetic success, self-approval, bypass, force update, or destructive rebase. Keep Draft until the unchanged exact receives terminal applicable hosted checks and owner review, then integrate through the canonical queue-health stack. After protected integration, the read-only collector must produce a snapshot binding the Noema repository/PR/head/workflow/job identities and preserving the observed same-head unassigned→assigned→terminal and parent-success→fan-out-unassigned transition families without confusing conditional skips with runner allocation.