No workflow sets `shell:`, and GitHub runs such a step as `bash -e {0}`,
without pipefail: the exit code of `… | tee` is tee's, and a failing left
side passed silently. Three steps were unprotected:
- _process-resume.yml: an exception of process-resume.mjs (gh, API) left the
step green and the resume event was lost until process-reconcile;
- release-review.yml: a failed `prepare` went on with an incomplete
GITHUB_OUTPUT and proceed=true;
- validate.yml: a failed `classify-changes.mjs --heavy` left `heavy` empty,
heavy jobs were skipped and job `changes` stayed green.
Each gets `set -o pipefail` as the first line of `run` (validate.yml's step
becomes a block), following #727 and #472. test/workflow-pipefail.test.mjs
walks every .github/workflows/*.yml: a `| tee` line in `run` must follow
`set -[a-z]*o pipefail` or the step must have `shell: bash`; on the old tree
it names exactly the three places, and the _process-resume and validate
steps run on real bash under `bash -e` with a failing node.
ci-proof.mjs exports githubApiBase(env) (GITHUB_API_URL or
https://api.github.com, no trailing slash); githubCandidateTree,
loadGithubProofContext and release-gate's workflowRunsUrl take `apiBase`
with that default instead of the hardcoded host. night-red.mjs passes the
base directly and drops the fetch wrapper that rewrote the prefix. On
github.com the runner's GITHUB_API_URL is the same host, so behaviour there
does not change; archive_download_url stays as the API returned it.
The `mode` input for ship-review is out of scope (thin file in main, #716).
Thin files are not touched: _process-resume.yml is a body, validate.yml and
release-review.yml are not thin.
Issue: #751
User-Visible: no
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018qZfe7YS4rqEMKoVeS3GKd
A red nightly Validate was a signal "to the author of the latest dev
commits" that nobody received: the red run was visible only in Actions,
and nobody computed who the author was.
- scripts/night-red.mjs: acts only on conclusion=failure of the red run
(cancelled, timed_out and the rest are a summary line). The last green
night is the newest of the last 50 Validate workflow_dispatch runs on
dev that completed successfully, was created before the red run, sits
on an ancestor of the red SHA and has a green ci-proof under the
release policy, so a light green run (stale) never counts. Suspects
are the Issue: trailers of `git rev-list --no-merges G..R` commits that
touch a class A/B file and carry no Release: trailer: docs-only and
beta-candidate commits do not count, a branch merged by a merge commit
brings its second-parent commits, a commit without a trailer is a
"no task" summary line, an empty range means a likely flake. One
comment per task names both runs, up to ten of its commits and the
failed jobs, says "suspect, not guilty" and ends with the marker
hp:night-red green=<G> red=<R> commits=<all sha12>. No comment goes to
a closed task or to a task whose marker with the same green already
lists all its current range commits: one comment per series of red
nights until the task commits again; a green night starts a new series.
Failures become a ::warning:: and a summary line, exit code 0.
- _nightly.yml: dispatch also outputs run_id; a new job night_red runs
after it only when dispatch failed with a known run, continue-on-error,
permissions actions: read and contents: read (the union with the other
jobs is unchanged, thin files in main are untouched), checks out dev
with full history without blobs, reads Actions with github.token and
writes issues with HP_PROCESS_TOKEN. The header names the addressee.
- PROCESS.md §10.4: the "Красная ночь" paragraph next to the nightly
ship review.
Tests run the scripted rules on real git in temporary repositories with
real ci-proof fixtures, and the workflow step on real bash with a local
Actions API server and a fake gh.
Issue: #736
User-Visible: no
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018qZfe7YS4rqEMKoVeS3GKd