[ci] Make typed workflow bridges fail closed - #3592
Conversation
10284fa to
a565eff
Compare
f90984d to
4f0c3e7
Compare
|
Authored by an agent, posting via joshlf's account @codex review |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
a565eff to
7de4caa
Compare
4f0c3e7 to
2a757e8
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## Gquoamyb32c2czjlzvvkel27kkqeg2tid #3592 +/- ##
==================================================================
Coverage 91.85% 91.85%
==================================================================
Files 20 20
Lines 6093 6093
==================================================================
Hits 5597 5597
Misses 496 496 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Codex Review: Didn't find any major issues. Can't wait for the next one! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
06f0401 to
e1c922e
Compare
|
Authored by an agent, posting via joshlf's account @codex review |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
78a1d2e to
e8060ec
Compare
e1c922e to
9fe71b9
Compare
|
Authored by an agent, posting via joshlf's account @codex review |
|
Codex Review: Didn't find any major issues. Keep them coming! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
9fe71b9 to
f2da34c
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. Another round soon, please! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
f2da34c to
ea969d4
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
8e2bc56 to
8824884
Compare
ea969d4 to
6b3a770
Compare
8824884 to
b37f87b
Compare
6b3a770 to
0b31f82
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. Hooray! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
b37f87b to
2c11865
Compare
0b31f82 to
2156849
Compare
2c11865 to
e77f592
Compare
2156849 to
c51f601
Compare
Derive Miri job eligibility from the projected matrix instead of repeating the event policy in workflow YAML. Publish the same gate to the required-check aggregate so policy changes cannot select work that the workflow silently skips. Run the planner with an absolute privileged Bash, neutralized startup controls, and a command-local fixed PATH. Invoke an explicit child Bash so the cargo wrapper cannot select an ambient interpreter. Run typed cells with absolute Docker, a fixed /bin/bash entrypoint, privileged no-startup arguments, and an option terminator. Use absolute jq in the final gate. These bridges now fail if PATH, image startup state, or Bash startup state attempts to replace their commands. This changes transport and eligibility wiring, not selected coverage: pull requests still run 60 build and zero Miri cells. Full events still run 182 build cells and 64 Miri cells. Tests: offline zc tests Tests: ci/check_actions.sh Tests: cargo fmt --check Tests: git diff --check *Authored by an agent, posting via joshlf's account* gherrit-pr-id: Gg5onzlaf6nsoqoubbjg43tdiuxvvjrbc
c51f601 to
c8bd554
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. 🎉 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Derive Miri job eligibility from the projected matrix instead of
repeating the event policy in workflow YAML. Publish the same gate to
the required-check aggregate so policy changes cannot select work that
the workflow silently skips.
Run the planner with an absolute privileged Bash, neutralized
startup controls, and a command-local fixed PATH. Invoke an explicit
child Bash so the cargo wrapper cannot select an ambient interpreter.
Run typed cells with absolute Docker, a fixed /bin/bash entrypoint,
privileged no-startup arguments, and an option terminator. Use absolute
jq in the final gate. These bridges now fail if PATH, image startup
state, or Bash startup state attempts to replace their commands.
This changes transport and eligibility wiring, not selected
coverage: pull requests still run 60 build and zero Miri cells. Full
events still run 182 build cells and 64 Miri cells.
Tests: offline zc tests
Tests: ci/check_actions.sh
Tests: cargo fmt --check
Tests: git diff --check
Authored by an agent, posting via joshlf's account
Latest Update: v29 — Compare vs v28
📚 Full Patch History
Links show the diff between the row version and the column version.
⬇️ Download this PR
Branch
git fetch origin refs/heads/Gg5onzlaf6nsoqoubbjg43tdiuxvvjrbc && git checkout -b pr-Gg5onzlaf6nsoqoubbjg43tdiuxvvjrbc FETCH_HEADCheckout
git fetch origin refs/heads/Gg5onzlaf6nsoqoubbjg43tdiuxvvjrbc && git checkout FETCH_HEADCherry Pick
git fetch origin refs/heads/Gg5onzlaf6nsoqoubbjg43tdiuxvvjrbc && git cherry-pick FETCH_HEADPull
Stacked PRs enabled by GHerrit.