Files
houseplan-card/.github/workflows/_process-resume.yml
T
Claudeandclaude[bot] 25001ef7ab fix(ci): pipefail before every | tee, API base from GITHUB_API_URL (#751)
No workflow sets `shell:`, and GitHub runs such a step as `bash -e {0}`,
without pipefail: the exit code of `… | tee` is tee's, and a failing left
side passed silently. Three steps were unprotected:
- _process-resume.yml: an exception of process-resume.mjs (gh, API) left the
  step green and the resume event was lost until process-reconcile;
- release-review.yml: a failed `prepare` went on with an incomplete
  GITHUB_OUTPUT and proceed=true;
- validate.yml: a failed `classify-changes.mjs --heavy` left `heavy` empty,
  heavy jobs were skipped and job `changes` stayed green.
Each gets `set -o pipefail` as the first line of `run` (validate.yml's step
becomes a block), following #727 and #472. test/workflow-pipefail.test.mjs
walks every .github/workflows/*.yml: a `| tee` line in `run` must follow
`set -[a-z]*o pipefail` or the step must have `shell: bash`; on the old tree
it names exactly the three places, and the _process-resume and validate
steps run on real bash under `bash -e` with a failing node.

ci-proof.mjs exports githubApiBase(env) (GITHUB_API_URL or
https://api.github.com, no trailing slash); githubCandidateTree,
loadGithubProofContext and release-gate's workflowRunsUrl take `apiBase`
with that default instead of the hardcoded host. night-red.mjs passes the
base directly and drops the fetch wrapper that rewrote the prefix. On
github.com the runner's GITHUB_API_URL is the same host, so behaviour there
does not change; archive_download_url stays as the API returned it.

The `mode` input for ship-review is out of scope (thin file in main, #716).
Thin files are not touched: _process-resume.yml is a body, validate.yml and
release-review.yml are not thin.

Issue: #751
User-Visible: no
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018qZfe7YS4rqEMKoVeS3GKd
2026-10-01 14:31:06 +00:00

65 lines
3.8 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
name: "Продолжение ревью после Validate · тело (#623)"
# #636. Стадия `prepare` конвейера (process.yml) больше не ждёт Validate с
# мутантами на материале внутри job — раннер спал ≈ 28 минут на раунд при
# 10–12 минутах работы модели. Она диспатчит прогон, кладёт запечатанный
# маркер `review-pending-…` и выходит. Этот workflow просыпается на завершение
# любого Validate и, если раунд ждал именно этот прогон (маркер на материале,
# метка S7 стоит, активного прогона конвейера нет), переставляет метку S7 —
# новый прогон `prepare` находит завершённый dispatch и продолжает раунд.
# Ничего не оценивает: зелёный/красный разбирает сам конвейер. Страховка на
# потерянное событие — process-reconcile.yml с тем же маркером.
#
# Для события `workflow_run` GitHub берёт workflow только из ветки по
# умолчанию (main). Там лежит тонкий `process-resume.yml`, который вызывает
# этот файл по ссылке `@dev` (#623); сверка тонких копий — в preflight
# validate.yml.
on:
# #623: тело вызывается тонким файлом `process-resume.yml` из ветки по умолчанию
# по ссылке `@dev`; триггеры, run-name и concurrency живут там.
workflow_call:
permissions:
contents: read
actions: read
jobs:
resume:
name: "Разбудить раунд, ждавший этот Validate"
if: github.event.workflow_run.event == 'workflow_dispatch' && startsWith(github.event.workflow_run.head_branch, 'issue/')
runs-on: ubuntu-24.04
timeout-minutes: 10
concurrency:
group: process-resume-${{ github.event.workflow_run.head_branch }}
cancel-in-progress: false
steps:
# Код берётся из dev, как у reconcile: после штатного слияния действует
# версия, которую проверил CI, а не копия из main.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
ref: dev
fetch-depth: 1
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: 22
# Метка переставляется HP_PROCESS_TOKEN: событие от GITHUB_TOKEN не
# запустило бы process.yml (см. шапку process.yml, п. 1).
- name: Решить по маркеру ожидания и переставить S7
env:
GH_TOKEN: ${{ secrets.HP_PROCESS_TOKEN }}
REPO: ${{ github.repository }}
BRANCH: ${{ github.event.workflow_run.head_branch }}
SHA: ${{ github.event.workflow_run.head_sha }}
EVENT: ${{ github.event.workflow_run.event }}
STATUS: ${{ github.event.workflow_run.status }}
# #751: без pipefail код конвейера — код tee, и исключение скрипта (gh,
# API) проходило зелёным шагом: событие возобновления терялось до
# прохода process-reconcile.
run: |
set -o pipefail
node scripts/process-resume.mjs \
--repo="$REPO" --branch="$BRANCH" --sha="$SHA" \
--event="$EVENT" --status="$STATUS" --apply=true | tee -a "$GITHUB_STEP_SUMMARY"