Skip to content

ops(queue): enroll Noema in queue-health evidence - #2202

Draft
seonghobae wants to merge 2 commits into
codex/queue-health-preserve-disksage-lineageweavefrom
codex/noema-queue-health-enrollment
Draft

seonghobae wants to merge 2 commits into
codex/queue-health-preserve-disksage-lineageweavefrom
codex/noema-queue-health-enrollment

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Parent integration: #2201. Canonical queue-health owner: #1150. Incident owner: #712.

Finding

Noema #714 reproduced the organization pre-runner admission class on exact a1228e72565d4280d01e1f877377ee0d3e107178: application, reviewer, Security scope, and patch-validator jobs first materialized without runner identity or execution steps. The canonical queue-health collector's bounded repository allowlist omitted ContextualWisdomLab/noema, so the owner implementation could not observe that leaf canary after integration.

The retained unchanged #714 generation then produced the complete same-head transition family without rerun or source mutation. Application 34826581397 / job 103920031612 remained positively unassigned for 4h 50m 26s, then received GitHub-hosted runner 1001975480 and completed SUCCESS. Reviewer 103920031213, Security scope 103920034688, and patch-validator-image 103920031946 likewise received positive runner identities and completed successfully. Security follow-ons scorecard 104006051571 and trivy-fs 104006051766, which were previously retained as positively unassigned controls, later assigned to runners 1001977687 and 1001977724 and completed SUCCESS on the unchanged head. In the same Security generation, scope-conditioned gitleaks, dependency-review, and osv-scan ended completed/skipped with no runner identity; those are terminal non-execution evidence, not positive assignment and not runner-capacity failures.

All four #714 required workflows ultimately reached terminal SUCCESS. #714 was then normal-merged into Noema protected main by GitHub-verified merge commit 159758c16f92dafb884d176fdbf23cb0f5bd69f7. Noema #717 separately repaired its leaf diagnostic so runner-less completed/skipped jobs are runner_assignment_not_required while valid runner identity remains runner_assignment_observed, and normal-merged as GitHub-verified 067ab5045cc16f4096751a03a5fdd19e13a8aa42; that leaf classification does not replace the organization queue-health owner.

Noema #718 supplied a second unchanged-head transition specimen on exact 76896a3d4ffb452280395708c8ab7379b4a48c5b. Application CI 34957250689 / 104342163077, reviewer 34957250625 / 104342623689, patch-validator-image 34957250908 / 104342163552, and Security scope 34957250711 / 104342165441 first materialized runner-less with steps=[], then naturally received GitHub-hosted runners and completed SUCCESS without rerun or source mutation. Security fan-out scorecard and trivy-fs likewise later received runners and completed SUCCESS on the unchanged exact while gitleaks, dependency-review, and osv-scan remained conditional skips. All four required workflow generations became terminal GREEN, and #718 normal-merged into protected Noema main as GitHub-verified 8595e83b4b6f52c03ca18a480d86f7bde18a9cd6 on 2026-09-15.

Current Noema #719 now supplies a third, stronger per-job/fan-out specimen on exact de91e24fdac66c9963c92ca77971d870a48778e4 over protected base 8595e83b4b6f52c03ca18a480d86f7bde18a9cd6. Application CI 35023070872, reviewer-ci 35023070921, and patch-validator-image 35023070879 are terminal SUCCESS. Security Scan 35023070896 first admitted Detect changed scope job 104563374280 to GitHub-hosted runner 1001990594 and completed SUCCESS after a multi-hour pre-runner wait. That success then materialized second-wave trivy-fs 104621035044 and scorecard 104621035128 at 2026-09-16T00:42:52Z; both remain queued with runner_id=0, empty runner identity, and steps=[] on the same unchanged head, while gitleaks, osv-scan, and dependency-review are terminal runner-less conditional skips. This proves that one unchanged workflow generation can transition from admitted parent work back into a new positively-unassigned fan-out generation; queue health therefore must be classified and timed per job, not only per workflow run.

The owner repair remains stacked on #2201 rather than opening a competing sibling against #1150, preserving the existing DiskSage + LineageWeave enrollment and exact-equality allowlist contract.

RED → minimal repair

Test-first exact 94c4eae9c55f238b8bde040113f3f08023586be9 changes only tests/test_actions_queue_health_contract.py so test_queue_health_allowlist_is_explicit_and_bounded requires ContextualWisdomLab/noema while the config still omits it. That exact source is deterministically inconsistent by construction; no hosted RED is claimed.

Causal successor exact f40638618a4b784d1481ea5969fdd632119d818f adds only the matching config entry. Effective delta from parent #2201 is exactly two owner paths:

  • config/actions_queue_health_repositories.json: enroll ContextualWisdomLab/noema;
  • tests/test_actions_queue_health_contract.py: preserve the explicit/bounded exact-equality contract with Noema included.

Collector logic, workflow schedule/triggers, credentials, runner selection, cancellation/rerun behavior, check conclusions, Noema source, and required gates are unchanged.

Current exact gates

On unchanged f406386...:

  • SAST Semgrep 34850945756 is terminal SUCCESS.
  • Security Scan 34850945652 is terminal SUCCESS after delayed hosted-runner admission; no source mutation or rerun was needed.
  • CodeQL PR 34850945674 is terminal FAILURE because the actions and python compatibility jobs ran before an authenticated current-head producer verdict existed and correctly failed closed after observing VERDICT_STATE=pending. This is not a semantic CodeQL finding on the enrollment delta.
  • Follow-on Dispatch current-head CodeQL scan job 104196652749 received GitHub-hosted runner 1001981210 and completed SUCCESS at 2026-09-15T03:39:51Z, creating canonical producer run 34925844944.
  • Producer validate-dispatch job 104243619132 later received GitHub-hosted runner 1001983938 at 2026-09-15T10:25:10Z. OIDC/OpenCode App token exchange succeeded. The subsequent trusted live-PR metadata bind failed because gh api repos/ContextualWisdomLab/.github/pulls/2202 returned HTTP 502. The job therefore completed FAILURE at 10:25:26Z, and downstream CodeQL dispatch scan 104344143885 correctly completed SKIPPED.

The current blocker is therefore no longer pre-runner admission on this producer. It is a fail-closed central dispatch-runtime transport failure while obtaining authenticated live PR metadata. The 502 is not a semantic CodeQL finding and does not invalidate the two-file enrollment delta, but it is non-passing evidence and must not be reclassified GREEN. Existing terminal-publication owner #1929 records the bounded-retry requirement for transient GitHub API 5xx/transport faults while keeping exact live PR/base/head/open-state validation strict.

Acceptance

This enrollment does not classify the incident as GREEN and does not authorize blind reruns, no-op commits, selector changes, cancellation, predecessor-status transfer, synthetic success, self-approval, bypass, force update, or destructive rebase. Keep Draft until the unchanged exact receives terminal applicable hosted checks and owner review, then integrate through the canonical queue-health stack. After protected integration, the read-only collector must produce a snapshot binding the Noema repository/PR/head/workflow/job identities and preserving the observed same-head unassigned→assigned→terminal and parent-success→fan-out-unassigned transition families without confusing conditional skips with runner allocation.

@coderabbitai

coderabbitai Bot commented Sep 14, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head source review on f40638618a4b784d1481ea5969fdd632119d818f: effective delta from stacked parent #2201 is exactly the bounded allowlist entry plus the matching exact-equality contract. The test-first predecessor 94c4eae9c55f238b8bde040113f3f08023586be9 makes the contract/config pair intentionally inconsistent; the current head repairs only that inconsistency. No collector logic, permissions, workflow scheduling, runner selection, cancellation/rerun semantics, or leaf-repository source is changed. Hosted current-head checks remain authoritative; this COMMENT is not approval.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

현재 exact f40638618a4b784d1481ea5969fdd632119d818f 기준으로 stacked parent #2201 대비 두 owner-path delta만 검토해 주세요. 특히 allowlist exact-equality contract가 Noema enrollment만 추가하고 collector logic, scheduling, credentials, runner selection, rerun/cancellation semantics를 넓히지 않는지 확인 바랍니다. COMMENT-only/independent review로 사용하며, 이 요청은 hosted gate나 merge authority를 대체하지 않습니다.

Copy link
Copy Markdown
Contributor Author

Fresh RCA on canonical producer 34925844944 changes the current gate description.

validate-dispatch job 104243619132 is no longer queued. It received GitHub-hosted runner 1001983938 at 2026-09-15T10:25:10Z and reached the trusted metadata-binding step. OIDC/OpenCode App token exchange completed successfully. The first live-PR read then failed at:

gh api repos/${TARGET_REPOSITORY}/pulls/${PR_NUMBER}gh: Server Error (HTTP 502)

The job consequently ended FAILURE at 10:25:26Z; downstream CodeQL dispatch scan 104344143885 was correctly skipped. The supplied identity remained the expected .github#2202, base codex/queue-health-preserve-disksage-lineageweave@9a30272..., head codex/noema-queue-health-enrollment@f406386....

This is a real non-passing current-head gate, but it is not a semantic CodeQL finding and not evidence against the two-file Noema-enrollment delta. It is a central dispatch-runtime transport failure after runner admission. Do not reclassify it GREEN or blind-rerun it. The owner path should make the authenticated live metadata read tolerate only bounded transient GitHub API transport/5xx failures while preserving exact live base/head/open-state validation and failing closed after the bounded attempt ceiling. #1929 is the existing terminal-publication owner issue; keep this PR Draft until that lifecycle yields authenticated terminal evidence on the unchanged exact head.

Copy link
Copy Markdown
Contributor Author

Fresh Noema owner evidence for the queue-health enrollment lane:

No leaf rerun, no-op commit, cancellation, selector change, synthetic status, or gate weakening was used. This is additional per-job admission evidence only; it does not change #2202's existing stack/merge authority.

Copy link
Copy Markdown
Contributor Author

Fresh Noema queue-health specimen from #721 current exact a382639dc63c94944e4101280c0ad09b1e3e85a1:

  • application 35066553760/104698027457, reviewer-ci 35066553643/104698027941, Security scope 35066553829/104698028507, and patch-validator-image 35066553826/104698028469 all materialized at 2026-09-16T07:02:42Z07:02:43Z and remain queued with runner_id=0, empty runner identity, and steps=[] nearly two hours later on the unchanged exact head;
  • Security gitleaks 104698029558 is completed/skipped without runner identity, so it remains an applicability/non-execution control rather than positive admission evidence;
  • the same fix(review): defer R coverage on any declared dependency, not only Suggests #721 exact has now completed current-head CodeRabbit review with no actionable comments, so the leaf blocker is specifically hosted runner admission rather than unresolved review/source findings;
  • fresh .github aggregate at this observation is 185 queued / 3 in progress.

This is another positive-unassigned per-job specimen for the Noema enrollment contract. No leaf rerun, no-op commit, cancellation, selector mutation, or synthetic conclusion was used. Preserve per-job materialization/admission timing and the runner-less conditional-skip distinction in the canonical collector.

Copy link
Copy Markdown
Contributor Author

Precision note on the #721 specimen: the current-head CodeRabbit incremental diff review produced no actionable comments, but its summary reports clone-backed analysis was skipped because repository clone access failed. Do not treat that bot review as replacing Noema's queued hosted reviewer-ci; merge authority still requires the exact-head hosted gates. The positive-unassigned runner-admission evidence above is unchanged.

Copy link
Copy Markdown
Contributor Author

Fresh Noema queue-health evidence from successor PR #721, exact a2304a9f10cd04a8a6a2c805c255fd758600c6bc over protected Noema base 4433c3009d4c6bc900bf5c8346f75b07185ff985.

This is a new first-wave specimen after #719 already completed its unchanged-head second-wave admission and normal merge. On #721, application 35077338242/104732775259, reviewer-ci 35077338292/104732775865, Security scope 35077338214/104732775734, and patch-validator-image 35077338199/104732778801 all materialized at 2026-09-16T09:04:42Z09:04:43Z and remain queued with runner_id=0, empty runner identity, and steps=[] on the unchanged exact. Security gitleaks 104732777592 is a runner-less completed/skipped applicability result and is not counted as positive assignment or capacity failure.

At the same observation, the central .github repository reports 191 queued workflow runs and 5 in progress. This again supports per-job materialization/admission timing rather than workflow-run-only classification: the leaf exact is stable, no source/runtime selector mutation has occurred, and all four required entry jobs are positively unassigned while the organization backlog remains high.

No leaf rerun, no-op commit, cancellation, runner-selector change, synthetic status, or gate weakening was performed. Keep the Noema leaf Draft until exact-head hosted evidence becomes terminal; this comment is owner-path evidence only.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant