Skip to content

fix(ci): preserve promotion provenance with full commit statuses - #8

Merged
ktechmidas merged 1 commit into
mainfrom
fix/promotion-status-provenance-20260928
Sep 28, 2026
Merged

ktechmidas merged 1 commit into
mainfrom
fix/promotion-status-provenance-20260928

Conversation

@infraclaw-dash

@infraclaw-dash infraclaw-dash commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

candidate_digest() uses GET commits/{sha}/status, whose combined response contains Simple Commit Status objects without creator, then requires creator.login == github-actions[bot]. A legitimate publication is consequently rejected.

Confirmed against both default-branch revision 07811cd919f6956ba9c6d69a3a1bff4550eb3761 and pinned controller aaea7df12716c386db223ea67a853b6b0efbd45a:

  • Platform PR 5151, exact head a02b1460736e18b6345bb4722c622e55e787371d.
  • Candidate status 55116170875 has no creator in the combined response; its full status identifies github-actions[bot] (41898282).
  • Publisher run 36474975257 completed successfully in the trusted pull_request_target workflow.

Scoped repair

  • Read the full /commits/{exact head_sha}/statuses endpoint with explicit 100-entry pagination.
  • Select the newest matching context before checking state, creator or digest. GitHub returns newest-first history, so repeated statuses are expected; never fall back to an older trusted success.
  • Respect GitHub's case-insensitive context identity during selection, then retain the existing exact canonical-context requirement. A newer case variant cannot expose an older canonical success.
  • Stop fetching once the newest candidate is found; exhaust pages when absent and propagate API failures.
  • Preserve the GitHub Actions creator check, including fail-closed handling of missing/null/malformed creators. Preserve immutable-digest, trusted publishing-run URL, workflow/event/conclusion, exact-head and existing promotion/manifest/job checks.

No workflow, controller pin, image recipe, dependency, runner configuration or Platform source changes. This PR is independent of CPU-budget PRs #5/#6 and legacy-template PR #7; it does not duplicate the separate Platform selector repair.

Integration and adoption — pending

Companion Platform selector repair: dashpay/platform#5156, targeting v4.2-dev. It repairs the separate CI selector and deliberately preserves the existing controller pin; the integration requirements below still apply.

Do not repin Platform directly to this PR's standalone head 6e2dd7b52ebcb3ce6a1aa070fe2b4cd933b4a57a. It is based on 07811cd919f6956ba9c6d69a3a1bff4550eb3761 and does not include the legacy Android template aliases from PR #7.

Verified Platform v4.2-dev revision c795f81ce9b already pins both the reusable workflow and control_revision in runner-image-candidate.yml to PR #7's aaea7df12716c386db223ea67a853b6b0efbd45a. Replacing that pin with this standalone status-fix head would regress legacy-template compatibility.

Safe adoption requires an integrated, reviewed controller revision containing both fixes:

  1. Review and merge legacy-template PR fix(ci): preserve legacy full-profile template aliases #7 first (or integrate both under one reviewed merge plan), then merge this PR fix(ci): preserve promotion provenance with full commit statuses #8. Their source changes do not overlap; neither branch needs to be rewritten for this review handoff.
  2. Verify the integrated revision retains legacy-template regression coverage and the status/provenance tests before selecting its exact SHA.
  3. In a separately authorized Platform pin-update review, update both the reusable-workflow SHA and control_revision together to that integrated SHA. Preserve equivalent pins in any other affected callers; do not change historical releases or blindly rerun old pinned workflows.

These are adoption requirements, not operations performed by this PR. Source repair/review is delivered; integrated-controller adoption and runtime use remain pending. No rebase/stack, merge, Platform pin change, manual CI dispatch, publication, or runner rollout has been performed here.

Regression coverage

Captured public fixtures preserve both real endpoint shapes and the successful publisher response, with documented projections, source URLs and SHA-256 checksums. Synthetic variations cover:

  • Successful trusted publication; wrong, absent, null and malformed creators.
  • Newer pending/failed/error/untrusted/invalid statuses overriding older success, including page boundaries and capitalization variants.
  • Repeated successes selecting the newest digest; exact PR context and head isolation.
  • A candidate on a later full page, full-page exhaustion, empty results and no unnecessary later requests.
  • API errors and the retained URL/digest/workflow/event/conclusion gates.

The old lifecycle mock incorrectly fabricated creator on a combined status; it now uses the full endpoint's actual list shape.

Verification

  • Both affected revisions reproduce Candidate status was not created by GitHub Actions against the captured real combined response.
  • Repaired resolver succeeds against live read-only GitHub GETs, returning sha256:e5ebd957d28d15976320023b76cffa8b982e1d131c572d92eb9c91814dbf807b for that exact head. This verifies resolution, not an executed promotion.
  • Focused suite: 13 passed.
  • Full unit suite: 56 run — 55 passed, 1 opt-in Docker lifecycle test skipped (DASH_RELEASE_TEST_IMAGE unset).
  • Lock validation (including ARM64 parity), Python compilation, shell syntax and diff/whitespace checks passed.
  • AST comparison confirms all production code outside candidate_digest() is unchanged.
  • Independent read-only review found no blocking correctness or security findings; the reviewer also passed all 13 candidate-status and 13 lifecycle tests and verified fixture checksums.

No merge, image/package publication, manual CI dispatch, live-runner changes or promotion performed. Normal PR checks are separate from the local evidence above.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 122c9e81-db67-4af4-aa7e-c7f384ab7435


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ktechmidas
ktechmidas merged commit 7d90115 into main Sep 28, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants