fix: validate runner candidates using full commit statuses - #5156
ktechmidas merged 1 commit into
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: dashpay/platform/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe runner-image selector now paginates commit statuses, selects the newest matching context, and validates successful candidates against publisher-run details. Tests cover status ordering and pagination, candidate validation, retries, runner labels, and ARM64 selection. ChangesRunner-image status selection
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The selector change has no identified merge-blocking issue; it is ready for normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The revised selection path retains the publisher and image checks, and no new bypass was established. Some integration and security coverage remains unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 2 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🕓 Queued for automated review — 5th in line, estimated start in ~25 min (commit 217167d)
|
Issue being fixed or feature implemented
PR #5151 cannot select its successfully published runner image. The Kotlin selector job fails with
Candidate status must come from the trusted publisher; the Rust and NPM selectors fail identically. The candidate publisher completed successfully.The selector reads GitHub's combined
/commits/{head}/statusresponse, whose individual status objects omitcreator, then requirescreator.login == github-actions[bot]. The full/commits/{head}/statusesresponse includes that provenance. The old tests incorrectly manufactured the missing field in the combined response.What was done?
a02b1460736e18b6345bb4722c622e55e787371d, status55116170875, publisher run36474975257. The combined status genuinely lackscreator; the full status identifiesgithub-actions[bot](ID41898282).Companion controller promotion fix: dashpay/dash-selfhosted-image#8.
Integration / adoption
This PR targets the current
v4.2-devbranch. Its selector fix must be included when refreshing thev4.2-dev→v4.3-devmerge PR #5151; rerunning #5151's unchanged head will still execute the old selector.The controller pin remains
aaea7df12716c386db223ea67a853b6b0efbd45a. Do not replace it with the standalone controller #8 head: that head does not include the separate legacy-template compatibility repair in controller #7. After review/merge, the controller pin should advance to a revision containing both repairs. This PR changes no workflow permissions, image manifest, recipe, live runner, or controller pin.How Has This Been Tested?
python3 -m unittest discover -s .github/scripts/tests -p 'test_runner_image.py' -v— 27 passed.python3 -m unittest discover -s .github/scripts/tests -v— 33 passed, including release-boundary tests.git diff --check— passed.Normal PR CI remains separate from the local evidence above. No manual workflow dispatch, runner rollout, image publication, or merge was performed.
Breaking Changes
None. CI selection repair only; no application, dependency, consensus, or protocol changes.
Checklist:
structure.rs, regeneratedgrovedb-structure.json, and checked the structure viewer link posted on this pull requestFor repository code-owners and collaborators only
Summary by CodeRabbit
PR Hygiene ·
217167d/skip-botsproceeds without the ones not yet reported.github/scripts/runner-image.py,.github/scripts/tests/fixtures/candidate-status-pr5151.json,.github/scripts/tests/test_runner_image.py) — QuantumExplorer or shumkovWhen every box is checked the
PR Hygienecheck passes and this can merge.