Skip to content

workflow_yaml_check accepts jobs: [] though it claims to require a jobs mapping #1285

Description

@InauguralPhysicist

PR #1284 at df74ef1 was reviewed against git diff origin/main...HEAD.

Two coverage gaps block the supplied review bar:

  1. The sole roadmap caller now depends on the labels audit succeeding. .github/workflows/issue-triage.yml:241 has no step if, so GitHub applies success(). If any open issue lacks labels, the earlier labels audit exits 1 and the roadmap contract, selftest and live arms are skipped, including on a PR editing ROADMAP.md or either gate. The old suite ran these gates independently; after this PR it cannot provide that coverage. Run the roadmap step with a status condition such as ${{ !cancelled() }}, or put the two audits in independent jobs. Keep their failures advisory. The ordinary PR run did succeed: https://github.com/InauguralSystems/EigenScript/actions/runs/35922007325 . This finding concerns the first-step-failure path, not an observed failure of that run. GitHub's default status condition: https://docs.github.com/en/actions/reference/workflows-and-actions/expressions#status-check-functions .

  2. tests/run_all_tests.sh:7081-7084 checks only the selftest exit status. The deleted caller also pinned its counts. In a disposable copy, add return 0 immediately after selftest() { in tools/workflow_yaml_check.sh; execute the actual extracted [99zd] section, including the runner's bash accounting wrapper. It prints RESULTS: TOTAL=1 PASS=1 FAIL=0 although --selftest emits nothing. Likewise, add return 0 at the start of st_case() and the section passes over SELFTEST: 0 case(s) run, 0 passed, 0 failed, 0 skipped. Disabling only selftest loader runs produces 8 case(s) run, 6 passed, 0 failed, 2 skipped on a host where import yaml succeeds, and the section still passes. Restore the small caller-owned summary check: eight total, eight passed/zero skipped with PyYAML, six passed/two skipped without it. Control is green; whole-gate exit-0, exit-1, disabled live loader, and malformed workflow plants are all red.

Dangling claims to repair with the above:

  • issue-triage.yml:226-233 still says the dev image carries gh, Linux gcc exports its token, and contrasts this job with the former suite caller.
  • docs/CI.md:337-340 and tools/workflow_yaml_check.sh:53-54,77-81 claim selftest/contract pins that the new caller does not enforce.
  • tools/gh_probe.sh:32 refers to deleted CI.md text, “What the caller can and cannot prove”.
  • CHANGELOG.md:1441 says “see below” for the new change, which is above at line 1389.

Validation (one heavy command at a time; no full-suite rerun):

  • make: exit 0, EigenScript 0.43.0 built. Binary: 952K
  • make precheck: 19 passed, 0 failed, 0 skipped in 89s
  • section_plan.sh --skip-audit: 25 emitting lines (floor 20), 25 routed skips (floor 25), 25 reviewed reasons, unaccounted=0
  • child_exit_check.sh: 122 child sites (floor 122), no bypasses, 8 environment-selectable children
  • docs_claims_check.sh: NUMBERS 36 (history-deferred=0), PATHS 248, FLAGS 43, MAKE TARGETS 36, NAMES 463 (families 12), DOC ENROLMENT 12
  • ci_tier_check.sh: 22 jobs (16 required, 6 workers), 19 required names, 25 jobs on required paths
  • yaml.safe_load of all 9 workflow files: exit 0, no output
  • Both lowered floors are exact: child sites 126 -> 122 (-4); docs/CI.md paths 68 -> 65 (-3).
  • The live Protection ruleset lists exactly the 19 required checks in .github/required-checks.txt and excludes issue-triage.

Out of scope (pre-existing): workflow_yaml_check.sh:227 checks only whether jobs exists, not whether it is a mapping. A file containing name: lane, on: workflow_dispatch, jobs: [] is accepted with workflow-yaml: OK (examined=1 file(s), 1 name(s), loader=pyyaml), despite the tool header claiming a jobs mapping. This is not introduced by #1284.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:ciSubsystem: cifound-by:criticInstrument that surfaced it: criticgood first issueGood for newcomerskind:gate-defectA gate, check or claim that measures less than it says

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions