Repository navigation
fix(ci): a push to main reuses x86-main + determinism only from a real merge-queue run on the same sha (#4748) - #4884
Merged
Merged
Conversation
…ue's real run on the same sha (T43-push)
A push to main ran x86-main and determinism in full on the very commit the
merge queue had just passed: ci_mg_reuse.sh reused on merge_group only.
workspace-test already reuses the queue's result on the same sha (T36).
This does the same for x86-main and determinism, and only when the queue
run on that sha RAN both jobs, never when it was itself a reuse.
Push key (scripts/ci_mg_reuse.sh decide-push / resolve-push):
P1 the event is a push to refs/heads/main
P2 the pushed commit S has exactly one parent B, and before == B
P3 the newest ci.yml merge_group run on S is completed, its head_branch
is gh-readonly-queue/main/pr-N-B, and every job read belongs to it
P4 x86-main, determinism, gate and `ci / gate` succeeded there, and
x86-main-advisories was SKIPPED, which proves x86-main ran for real
Any failed or partial lookup refuses, and the jobs run in full.
mac-check is never reused on a push. Both verdict blocks (gate and
`ci / gate`) accept push:success:1:1 under the same advisory rule.
Guard: scripts/check_ci_push_reuse.sh grows P1-P17 (decide-push on a
throwaway repo), R1-R5 (resolve-push with a stub gh, call counts) and
X1-X4 (ci.yml wiring, plus the real ci_mg_reuse.sh --self-test, 78 rows).
Its mutation self-test deletes every R-PUSH* marker, after an
unmutated-copy control. Contract apr-required-checks-v1 1.3.0 adds the
t43_push_reuse_key equation, RC-OB-013 and RC-F-013; pv validate and
pv lint are clean, and regen changed contracts.nt only (version triple).
ont-delta: none (prose equation and falsifier added to an existing pattern contract; no shape, kind or binding change)
Refs #4748, #4678
Agent: aprender-wtix-even
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…6-main + determinism reuse release-schedule-06x-v1 RS0-INV-008 said the push-reuse self-test covers ci_mg_workspace_result.sh and ci_test_tier.sh; it now also mutates every R-PUSH refusal in ci_mg_reuse.sh. Found by a review lane. Refs #4748 Agent: aprender-wtix-even Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ict block already carries The MG-REUSE-VERDICT block now reuses on push:success:1:1:success (#4748), and the self-test already runs seven push rows. The statement still said a flag set off merge_group must fail. It now names merge_group and push to main as the two events that may reuse, and the prediction lists the push rows. Refs #4748 Agent: aprender-wtix-even Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Three non-author lanes (gemini-3.1-pro-high, claude-sonnet-5-5, claude-haiku-4-5) PASS on 2abe1d7, the head after the RC-OB-011 fix the round-4 Gemini lane asked for. Lint: receipt complete, same-family 2/2. Operational fields (host names, home paths) redacted. Refs #4748 Agent: aprender-wtix-even Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
noahgift
enabled auto-merge
October 6, 2026 14:19
|
§13.11 rung 1 — quorum shadow verdict Shadow mode: this records a verdict and merges nothing. A refusal |
noahgift
disabled auto-merge
October 6, 2026 14:43
Agent: aprender-wtix-even Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
x86-main's guard-tree caught it: the PMAT-4748 entry was added without `make roadmap-aggregate`. Regenerated after merging origin/main. Refs #4748 Agent: aprender-wtix-even Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…INGS, advisory) A separate claude-sonnet-5-5 invocation reviewed the diff. Two advisory findings: a reused push skips x86-main's coverage upload and provenance step for that main commit, and two refusal branches carry no R-PUSH marker (later checks still refuse). No correctness defect in P1-P4. Unsigned; the signature is posted by CI. Refs #4748 Agent: aprender-wtix-even Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
noahgift
enabled auto-merge
October 6, 2026 15:38
noahgift
disabled auto-merge
October 6, 2026 15:54
The self-test capped each table run at 120 s and read any non-zero rc as a kill. On a loaded runner the unmutated control copy hit the cap and the self-test went red with "turns the table red", which named the wrong cause; the same cap on a mutant would have reported a kill nothing earned. The cap is now 600 s (PUSH_REUSE_RUN_TIMEOUT), a timeout on the control is reported as a timeout, and a timeout on a mutant is an ERROR, never a kill, so the self-test stays red. Proof: cap 5 s -> rc 1 "timed out after 5s"; default -> 29/29 killed, rc 0. Also stamps predicate.diff_patch_id on the #4884 review receipt (the id Arm 4 computes for this diff) so the signer can bind it. Agent: aprender-wtix-even Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
quorum-review (AD-04): NOT agreed (auto_merge: checked=true was_armed=false disarmed=false) {
"ticket": "PMAT-4748",
"head": "015ed1c1a0dbd78a440238a8cc744381c2663cc0",
"width": 3,
"executor": "agy",
"agreed": false,
"auto_merge": {
"checked": true,
"was_armed": false,
"disarmed": false,
"note": "auto-merge not armed"
},
"lanes": [
{
"lane": 1,
"verdict": "PASS",
"findings": 0
},
{
"lane": 2,
"verdict": "NO-VERDICT",
"findings": 0
},
{
"lane": 3,
"verdict": "PASS",
"findings": 0
}
]
} |
Contributor
Author
|
quorum-review (AD-04): three PASS — agreed (auto_merge: checked=true was_armed=false disarmed=false) {
"ticket": "PMAT-4748",
"head": "015ed1c1a0dbd78a440238a8cc744381c2663cc0",
"width": 3,
"executor": "agy",
"agreed": true,
"auto_merge": {
"checked": true,
"was_armed": false,
"disarmed": false,
"note": "auto-merge not armed"
},
"lanes": [
{
"lane": 1,
"verdict": "PASS",
"findings": 0
},
{
"lane": 2,
"verdict": "PASS",
"findings": 0
},
{
"lane": 3,
"verdict": "PASS",
"findings": 0
}
]
} |
Quorum AGREED 3/3 at 015ed1c (claude-sonnet-5, gemini-3.1-pro-high, claude-haiku-4-5; author claude-opus-5-5), base pinned to the merge-base sha. Non-author pr-review receipt at the same head, FINDINGS (advisory), diff_patch_id 0c2abd74. Agent: aprender-wtix-even Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A push to main used to run x86-main and determinism in full on the sha the merge queue had just passed.
mg-reusereused only onmerge_group. workspace-test already reuses the queue's result on the same sha (T36). This does the same for x86-main and determinism. It reuses them only when the queue run on that sha ran them for real, not when that run itself reused them.Closes #4748.
What changes
scripts/ci_mg_reuse.shaddsdecide_push/resolve_push. On a push it reuses (x86=det=1) only when every check below holds:refs/heads/main;beforeis that parent;ci.ymlmerge_grouprun on S came fromgh-readonly-queue/main/pr-N-<parent>;ci / gatesucceeded, and x86-main-advisories was skipped. A skipped advisory job proves x86-main ran for real.Every other input, and every failed lookup, gives 0 and runs the jobs. mac is never reused on a push. There are 14
# R-PUSH*refusal markers..github/workflows/ci.yml:mg-reusealso runs on a push to main. Both MG-REUSE-VERDICT copies acceptpush:success:1:1:success, and on a push the advisory job must still pass.scripts/check_ci_push_reuse.sh: the existing guard now covers the third subject script. 106 checks pass. Its mutation set kills every# R-*refusal (29/29), checked against an unmutated control copy.Contracts.
apr-required-checks-v1.yamlgoes to v1.3.0, adds RC-OB-013 and RC-F-013, and rewrites RC-OB-011 and RC-F-011 to name the push row.release-schedule-06x-v1.yamlupdates RS0-INV-008.contracts.ntis updated.Roadmap entry:
docs/roadmaps/entries/PMAT-4748.yaml.Evidence
ci / gatesucceeded, and x86-main-advisories was skipped. That is the exact shape the push key requires.bash scripts/ci_mg_reuse.sh --self-test: 78 passed, 0 failed. Seven of those rows are push verdict rows.bash scripts/check_ci_push_reuse.sh: OK.pv validate contracts/apr-required-checks-v1.yaml: 0 errors, 0 warnings.cargo test -p aprender-contracts --libon 934cdbb: 2290 passed, 0 failed, 5 ignored.cargo fmt --all -- --checkandcargo deny check advisories: clean.Review
This changes what a gate accepts, so it needs a non-author quorum round on the final commit, two non-author reviews, and green CI.
docs/audits/quorum-PMAT-4748.json. The only commit after it adds the receipt itself.aprlane: unavailable (executor busy). It is advisory only.🤖 Generated with Claude Code