Skip to content

ci: keep exact-head evidence for every main commit and classify superseded candidates - #2975

Merged
jonathanhaaswriter merged 1 commit into
mainfrom
claude/ci-main-sha-evidence
Sep 1, 2026
Merged

jonathanhaaswriter merged 1 commit into
mainfrom
claude/ci-main-sha-evidence

Conversation

@jonathanhaaswriter

@jonathanhaaswriter jonathanhaaswriter commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Main pushes to CI, CodeQL, Semgrep, Secret Scan, and Leak Check share one concurrency group per ref with cancel-in-progress: false. GitHub keeps one running plus one pending run per group, so every additional queued main run is cancelled behind the next merge. In the week ending 2026-09-01 that produced 172 cancelled main CI runs against 56 successes. Post-Merge Health treats cancelled as failing, so it reported those SHAs unhealthy (119 cancelled, 13 failed, 116 healthy), and the candidate ci-gate refused them (44 Candidate Build failures).

Change

  • Key the five workflows' concurrency groups by github.sha on push, keeping one group per pull request number for PRs. Every merged commit now gets its own terminal CI, CodeQL, Semgrep, Secret Scan, and Leak Check evidence, which is what post-merge-health.yml and the candidate ci-gate already assume.
  • Candidate Build and Rust-only Candidate keep serializing behind one active run. scripts/post_merge_health.py now fetches recent branch push runs and classifies a cancelled run of one of those two workflows as superseded when a newer main commit's run of the same workflow exists. Superseded runs are reported in their own section and do not fail health. A cancelled run of any other workflow, or a cancelled candidate with no newer run, still fails.
  • Document the model in docs/engineering/pr-landing.md.

Validation

  • python3 -m unittest scripts.tests.test_post_merge_health scripts.tests.test_ci_delivery_controls scripts.tests.test_app_ci_workflow (39 tests; six new covering branch-run collection, superseded classification, the non-serialized and no-newer-run negative cases, wait-loop plumbing, and rendering)
  • All workflow files parse.

…seded candidates

Main pushes to CI, CodeQL, Semgrep, Secret Scan, and Leak Check shared one
concurrency group per ref with cancel-in-progress false, so GitHub cancelled
every queued intermediate main run behind the next merge (172 cancelled main
CI runs in the week ending 2026-09-01). Post-Merge Health then reported those
SHAs unhealthy and the candidate ci-gate refused them.

Key those groups by commit SHA on push so each merged commit keeps its own
terminal evidence; pull requests still share one group per PR. The two
candidate workflows keep serializing behind one active run, so teach
post_merge_health.py to classify a cancelled candidate run as superseded when
a newer main commit's run of the same workflow exists, and report it as
informational instead of a failure.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@jonathanhaaswriter
jonathanhaaswriter merged commit f7e7517 into main Sep 1, 2026
68 of 70 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant