Skip to content

fix(ci): a push to main reuses x86-main + determinism only from a real merge-queue run on the same sha (#4748) - #4884

Merged
noahgift merged 9 commits into
mainfrom
fix/t43-push-reuse-x86-det
Oct 6, 2026
Merged

noahgift merged 9 commits into
mainfrom
fix/t43-push-reuse-x86-det

Conversation

@noahgift

@noahgift noahgift commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

A push to main used to run x86-main and determinism in full on the sha the merge queue had just passed. mg-reuse reused only on merge_group. workspace-test already reuses the queue's result on the same sha (T36). This does the same for x86-main and determinism. It reuses them only when the queue run on that sha ran them for real, not when that run itself reused them.

Closes #4748.

What changes

  • scripts/ci_mg_reuse.sh adds decide_push / resolve_push. On a push it reuses (x86=det=1) only when every check below holds:

    • the push is to refs/heads/main;
    • the pushed commit S has one parent, and before is that parent;
    • the newest completed ci.yml merge_group run on S came from gh-readonly-queue/main/pr-N-<parent>;
    • in that run, x86-main, determinism, gate and ci / gate succeeded, and x86-main-advisories was skipped. A skipped advisory job proves x86-main ran for real.

    Every other input, and every failed lookup, gives 0 and runs the jobs. mac is never reused on a push. There are 14 # R-PUSH* refusal markers.

  • .github/workflows/ci.yml: mg-reuse also runs on a push to main. Both MG-REUSE-VERDICT copies accept push:success:1:1:success, and on a push the advisory job must still pass.

  • scripts/check_ci_push_reuse.sh: the existing guard now covers the third subject script. 106 checks pass. Its mutation set kills every # R-* refusal (29/29), checked against an unmutated control copy.

  • Contracts.

    • apr-required-checks-v1.yaml goes to v1.3.0, adds RC-OB-013 and RC-F-013, and rewrites RC-OB-011 and RC-F-011 to name the push row.
    • release-schedule-06x-v1.yaml updates RS0-INV-008.
    • contracts.nt is updated.
  • Roadmap entry: docs/roadmaps/entries/PMAT-4748.yaml.

Evidence

  • I checked the jobs of a real merge-queue run. x86-main, determinism, gate and ci / gate succeeded, and x86-main-advisories was skipped. That is the exact shape the push key requires.
  • bash scripts/ci_mg_reuse.sh --self-test: 78 passed, 0 failed. Seven of those rows are push verdict rows.
  • bash scripts/check_ci_push_reuse.sh: OK.
  • pv validate contracts/apr-required-checks-v1.yaml: 0 errors, 0 warnings.
  • cargo test -p aprender-contracts --lib on 934cdbb: 2290 passed, 0 failed, 5 ignored.
  • cargo fmt --all -- --check and cargo deny check advisories: clean.

Review

This changes what a gate accepts, so it needs a non-author quorum round on the final commit, two non-author reviews, and green CI.

  • Quorum: AGREED 3/3. gemini-3.1-pro-high, claude-sonnet-5-5 and claude-haiku-4-5 all passed on 2abe1d7. The receipt is at docs/audits/quorum-PMAT-4748.json. The only commit after it adds the receipt itself.
  • Earlier rounds. In round 4 the Gemini lane failed because RC-OB-011 was stale. 2abe1d7 fixes that. One earlier round got no verdict from one lane, because that lane hit a transport error.
  • Advisory apr lane: unavailable (executor busy). It is advisory only.

🤖 Generated with Claude Code

noahgift and others added 4 commits October 6, 2026 11:51
…ue's real run on the same sha (T43-push)

A push to main ran x86-main and determinism in full on the very commit the
merge queue had just passed: ci_mg_reuse.sh reused on merge_group only.
workspace-test already reuses the queue's result on the same sha (T36).
This does the same for x86-main and determinism, and only when the queue
run on that sha RAN both jobs, never when it was itself a reuse.

Push key (scripts/ci_mg_reuse.sh decide-push / resolve-push):
  P1 the event is a push to refs/heads/main
  P2 the pushed commit S has exactly one parent B, and before == B
  P3 the newest ci.yml merge_group run on S is completed, its head_branch
     is gh-readonly-queue/main/pr-N-B, and every job read belongs to it
  P4 x86-main, determinism, gate and `ci / gate` succeeded there, and
     x86-main-advisories was SKIPPED, which proves x86-main ran for real
Any failed or partial lookup refuses, and the jobs run in full.
mac-check is never reused on a push. Both verdict blocks (gate and
`ci / gate`) accept push:success:1:1 under the same advisory rule.

Guard: scripts/check_ci_push_reuse.sh grows P1-P17 (decide-push on a
throwaway repo), R1-R5 (resolve-push with a stub gh, call counts) and
X1-X4 (ci.yml wiring, plus the real ci_mg_reuse.sh --self-test, 78 rows).
Its mutation self-test deletes every R-PUSH* marker, after an
unmutated-copy control. Contract apr-required-checks-v1 1.3.0 adds the
t43_push_reuse_key equation, RC-OB-013 and RC-F-013; pv validate and
pv lint are clean, and regen changed contracts.nt only (version triple).

ont-delta: none (prose equation and falsifier added to an existing pattern contract; no shape, kind or binding change)

Refs #4748, #4678

Agent: aprender-wtix-even
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…6-main + determinism reuse

release-schedule-06x-v1 RS0-INV-008 said the push-reuse self-test covers
ci_mg_workspace_result.sh and ci_test_tier.sh; it now also mutates every
R-PUSH refusal in ci_mg_reuse.sh. Found by a review lane.

Refs #4748

Agent: aprender-wtix-even
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ict block already carries

The MG-REUSE-VERDICT block now reuses on push:success:1:1:success
(#4748), and the self-test already runs seven push rows. The statement
still said a flag set off merge_group must fail. It now names
merge_group and push to main as the two events that may reuse, and the
prediction lists the push rows.

Refs #4748

Agent: aprender-wtix-even
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Three non-author lanes (gemini-3.1-pro-high, claude-sonnet-5-5,
claude-haiku-4-5) PASS on 2abe1d7, the head after the RC-OB-011 fix
the round-4 Gemini lane asked for. Lint: receipt complete, same-family
2/2. Operational fields (host names, home paths) redacted.

Refs #4748

Agent: aprender-wtix-even
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift
noahgift enabled auto-merge October 6, 2026 14:19
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

§13.11 rung 1 — quorum shadow verdict

S13-SHADOW pr=4884 head=7cf2d072712f2413a2b96a93ef73382677c917ad verdict=REFUSE class=Q1 arm_rc=1

Shadow mode: this records a verdict and merges nothing. A refusal
to arm is not a block (§13 adds zero rows to §7) — the pull request is
exactly as green as it was.

@noahgift
noahgift disabled auto-merge October 6, 2026 14:43
noahgift and others added 3 commits October 6, 2026 17:12
Agent: aprender-wtix-even
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
x86-main's guard-tree caught it: the PMAT-4748 entry was added without
`make roadmap-aggregate`. Regenerated after merging origin/main.

Refs #4748

Agent: aprender-wtix-even
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…INGS, advisory)

A separate claude-sonnet-5-5 invocation reviewed the diff. Two advisory
findings: a reused push skips x86-main's coverage upload and provenance
step for that main commit, and two refusal branches carry no R-PUSH
marker (later checks still refuse). No correctness defect in P1-P4.
Unsigned; the signature is posted by CI.

Refs #4748

Agent: aprender-wtix-even
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift
noahgift enabled auto-merge October 6, 2026 15:38
@noahgift
noahgift disabled auto-merge October 6, 2026 15:54
The self-test capped each table run at 120 s and read any non-zero rc as a
kill. On a loaded runner the unmutated control copy hit the cap and the
self-test went red with "turns the table red", which named the wrong cause;
the same cap on a mutant would have reported a kill nothing earned.

The cap is now 600 s (PUSH_REUSE_RUN_TIMEOUT), a timeout on the control is
reported as a timeout, and a timeout on a mutant is an ERROR, never a kill,
so the self-test stays red. Proof: cap 5 s -> rc 1 "timed out after 5s";
default -> 29/29 killed, rc 0.

Also stamps predicate.diff_patch_id on the #4884 review receipt (the id
Arm 4 computes for this diff) so the signer can bind it.

Agent: aprender-wtix-even
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift

noahgift commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

quorum-review (AD-04): NOT agreed (auto_merge: checked=true was_armed=false disarmed=false)

{
 "ticket": "PMAT-4748",
 "head": "015ed1c1a0dbd78a440238a8cc744381c2663cc0",
 "width": 3,
 "executor": "agy",
 "agreed": false,
 "auto_merge": {
  "checked": true,
  "was_armed": false,
  "disarmed": false,
  "note": "auto-merge not armed"
 },
 "lanes": [
  {
   "lane": 1,
   "verdict": "PASS",
   "findings": 0
  },
  {
   "lane": 2,
   "verdict": "NO-VERDICT",
   "findings": 0
  },
  {
   "lane": 3,
   "verdict": "PASS",
   "findings": 0
  }
 ]
}

@noahgift

noahgift commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

quorum-review (AD-04): three PASS — agreed (auto_merge: checked=true was_armed=false disarmed=false)

{
 "ticket": "PMAT-4748",
 "head": "015ed1c1a0dbd78a440238a8cc744381c2663cc0",
 "width": 3,
 "executor": "agy",
 "agreed": true,
 "auto_merge": {
  "checked": true,
  "was_armed": false,
  "disarmed": false,
  "note": "auto-merge not armed"
 },
 "lanes": [
  {
   "lane": 1,
   "verdict": "PASS",
   "findings": 0
  },
  {
   "lane": 2,
   "verdict": "PASS",
   "findings": 0
  },
  {
   "lane": 3,
   "verdict": "PASS",
   "findings": 0
  }
 ]
}

Quorum AGREED 3/3 at 015ed1c (claude-sonnet-5, gemini-3.1-pro-high,
claude-haiku-4-5; author claude-opus-5-5), base pinned to the merge-base
sha. Non-author pr-review receipt at the same head, FINDINGS (advisory),
diff_patch_id 0c2abd74.

Agent: aprender-wtix-even
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift
noahgift enabled auto-merge October 6, 2026 17:05
@noahgift
noahgift added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit e95ae82 Oct 6, 2026
18 of 21 checks passed
@noahgift
noahgift deleted the fix/t43-push-reuse-x86-det branch October 6, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0.70.2 T43: merge_group re-runs determinism, mac-check and x86-main on a tree the PR head already passed

1 participant