ci: keep exact-head evidence for every main commit and classify superseded candidates - #2975
Merged
Merged
Conversation
…seded candidates Main pushes to CI, CodeQL, Semgrep, Secret Scan, and Leak Check shared one concurrency group per ref with cancel-in-progress false, so GitHub cancelled every queued intermediate main run behind the next merge (172 cancelled main CI runs in the week ending 2026-09-01). Post-Merge Health then reported those SHAs unhealthy and the candidate ci-gate refused them. Key those groups by commit SHA on push so each merged commit keeps its own terminal evidence; pull requests still share one group per PR. The two candidate workflows keep serializing behind one active run, so teach post_merge_health.py to classify a cancelled candidate run as superseded when a newer main commit's run of the same workflow exists, and report it as informational instead of a failure. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Main pushes to CI, CodeQL, Semgrep, Secret Scan, and Leak Check share one concurrency group per ref with
cancel-in-progress: false. GitHub keeps one running plus one pending run per group, so every additional queued main run is cancelled behind the next merge. In the week ending 2026-09-01 that produced 172 cancelled main CI runs against 56 successes. Post-Merge Health treatscancelledas failing, so it reported those SHAs unhealthy (119 cancelled, 13 failed, 116 healthy), and the candidateci-gaterefused them (44 Candidate Build failures).Change
github.shaon push, keeping one group per pull request number for PRs. Every merged commit now gets its own terminal CI, CodeQL, Semgrep, Secret Scan, and Leak Check evidence, which is whatpost-merge-health.ymland the candidateci-gatealready assume.scripts/post_merge_health.pynow fetches recent branch push runs and classifies a cancelled run of one of those two workflows as superseded when a newer main commit's run of the same workflow exists. Superseded runs are reported in their own section and do not fail health. A cancelled run of any other workflow, or a cancelled candidate with no newer run, still fails.docs/engineering/pr-landing.md.Validation
python3 -m unittest scripts.tests.test_post_merge_health scripts.tests.test_ci_delivery_controls scripts.tests.test_app_ci_workflow(39 tests; six new covering branch-run collection, superseded classification, the non-serialized and no-newer-run negative cases, wait-loop plumbing, and rendering)