fix(ci): preserve promotion provenance with full commit statuses - #8
Merged
Merged
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
5 of 12 tasks
3 of 12 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
candidate_digest()usesGET commits/{sha}/status, whose combined response containsSimple Commit Statusobjects withoutcreator, then requirescreator.login == github-actions[bot]. A legitimate publication is consequently rejected.Confirmed against both default-branch revision
07811cd919f6956ba9c6d69a3a1bff4550eb3761and pinned controlleraaea7df12716c386db223ea67a853b6b0efbd45a:a02b1460736e18b6345bb4722c622e55e787371d.55116170875has no creator in the combined response; its full status identifiesgithub-actions[bot](41898282).pull_request_targetworkflow.Scoped repair
/commits/{exact head_sha}/statusesendpoint with explicit 100-entry pagination.No workflow, controller pin, image recipe, dependency, runner configuration or Platform source changes. This PR is independent of CPU-budget PRs #5/#6 and legacy-template PR #7; it does not duplicate the separate Platform selector repair.
Integration and adoption — pending
Companion Platform selector repair: dashpay/platform#5156, targeting
v4.2-dev. It repairs the separate CI selector and deliberately preserves the existing controller pin; the integration requirements below still apply.Do not repin Platform directly to this PR's standalone head
6e2dd7b52ebcb3ce6a1aa070fe2b4cd933b4a57a. It is based on07811cd919f6956ba9c6d69a3a1bff4550eb3761and does not include the legacy Android template aliases from PR #7.Verified Platform
v4.2-devrevisionc795f81ce9balready pins both the reusable workflow andcontrol_revisioninrunner-image-candidate.ymlto PR #7'saaea7df12716c386db223ea67a853b6b0efbd45a. Replacing that pin with this standalone status-fix head would regress legacy-template compatibility.Safe adoption requires an integrated, reviewed controller revision containing both fixes:
control_revisiontogether to that integrated SHA. Preserve equivalent pins in any other affected callers; do not change historical releases or blindly rerun old pinned workflows.These are adoption requirements, not operations performed by this PR. Source repair/review is delivered; integrated-controller adoption and runtime use remain pending. No rebase/stack, merge, Platform pin change, manual CI dispatch, publication, or runner rollout has been performed here.
Regression coverage
Captured public fixtures preserve both real endpoint shapes and the successful publisher response, with documented projections, source URLs and SHA-256 checksums. Synthetic variations cover:
The old lifecycle mock incorrectly fabricated
creatoron a combined status; it now uses the full endpoint's actual list shape.Verification
Candidate status was not created by GitHub Actionsagainst the captured real combined response.sha256:e5ebd957d28d15976320023b76cffa8b982e1d131c572d92eb9c91814dbf807bfor that exact head. This verifies resolution, not an executed promotion.DASH_RELEASE_TEST_IMAGEunset).candidate_digest()is unchanged.No merge, image/package publication, manual CI dispatch, live-runner changes or promotion performed. Normal PR checks are separate from the local evidence above.