Skip to content

Improve work-record checks and Actions usage reporting - #129

Merged
woksin merged 6 commits into
mainfrom
ci/remaining-followups
Oct 1, 2026
Merged

woksin merged 6 commits into
mainfrom
ci/remaining-followups

Conversation

@woksin

@woksin woksin commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Changed

Removed

@woksin woksin self-assigned this Oct 1, 2026
@woksin

woksin commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Complete updater suite passed in this session: pi-phase run --kind test --label 'Workflows complete updater suite' --timeout 300 --queue-timeout 600 -- python3 -B .github/scripts/tests/update-packages.test.py, 64 tests in 131.204 seconds, exit 0. One admission attempt; no retries or fallback execution.

Unchanged passing preparation results reused: release-intent suite 10/10; release-notes and AI-subscription suites 81/81; actions-usage-report offline fixtures 13/13; changed YAML actionlint and bootstrap bash syntax checks. git diff --check origin/main...HEAD passed again. Workflows contains no application solution/build gate.

The usage report was verified with offline fixtures, not a complete live organization-wide report. No private token scope change, organization-wide bootstrap run, schedule restoration, secret change, D1–D10 implementation, publication, or merge is included. Keep this branch separate from the SDK package-update fix: the package rollout safety gate intentionally rejects combining package updater changes with bootstrap organization-write changes. CI results still need review before any later merge.

@woksin

woksin commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Addressed the reporting findings with selective job inventory, an eight-worker pool, cached historical workflow blobs, an atomic request budget checked through rate_limit, explicit incomplete coverage, and per-repository error counts. Private visibility includes archived repositories; usage tables do not. Skipped/unassigned jobs are counted separately, while cancelled jobs that received a runner remain included.

Local Tier 1 checks passed: 24 usage specs, 91 Node workflow specs, 5 package-rollout safety specs (native working-diff mode; this PR does not trigger the package-rollout CI lane), 64 package-updater specs, 35 cleanup specs, Node/Bash syntax, diff whitespace, and actionlint for all executable workflows. The all-files actionlint invocation rejects the existing placeholder publish.template.yml; no executable workflow failed. The package suite initially exceeded 120 seconds, then passed in 140 seconds with a 300-second limit. One admission attempt expired before starting.

No workflow was dispatched because it unconditionally creates an issue. Live local no-issue measurements were bounded to 600 seconds: the initial collector returned a partial report at its 480-second collection bound (481.4 seconds elapsed); the cached eight-worker collector returned a partial report in 97.8 seconds when GitHub reported a rate limit. Complete live coverage remains unverified; the final report explicitly identifies the missing data. The workflow timeout is 12 minutes to cover the 480-second internal bound, a final 60-second API request, and checkout/publication overhead. The 14,000-run offline fixture stays within a fresh 5,000-request budget, and tests cover request exhaustion, fresh-budget retry, server-side limits, and bounded concurrency.

Ubuntu runner behavior, repository-secret permissions, and issue publication were not exercised locally. The live request used the local gh identity, not PAT_WORKFLOWS. Persistent collection across hourly windows was not introduced: this follows the requested selective, bounded collection design instead. Public arc discovery covers literal labels in historical workflow definitions and explicitly documents indirect runner selection as unobservable.

No labels changed and no merge performed.

@woksin

woksin commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Round 4 addresses both confirmed findings with the agreed scope cut: no public tree/blob or job requests; private jobs start as each repository listing completes in the shared bounded pool; daily windows and private job candidates are newest-first. Repository-listing stops now have count-free wording distinct from per-run job gaps. Added offline specs for mixed private volume plus 300 public SHAs, no inventory barrier, newest-first budget cuts, and stop-message units.

Local Tier 1 passed (this is a workflows/scripts repository, with no application solution build):

  • python3 -B .github/scripts/tests/actions-usage-report.test.py
  • python3 .github/scripts/tests/bootstrap-package-update-safety.test.py
  • python3 .github/scripts/tests/update-packages.test.py
  • python3 .github/scripts/tests/cleanup-pr-artifacts.test.py
  • node --test .github/scripts/tests/verify-release-notes.spec.mjs
  • node --test .github/scripts/tests/verify-release-intent.spec.mjs
  • node --check .github/scripts/update-ai-profile-subscription.mjs
  • node --test .github/scripts/update-ai-profile-subscription*.spec.mjs
  • git diff --check and the actual inline work-record guard.

All test phases used pi-phase with a 600-second admission limit. The package-update suite initially timed out at 120 seconds while progressing; its full rerun passed in 132.57 seconds with a 300-second limit. Release-note and release-intent phases each had one admission timeout, then passed on their first admission retry. Local Node was 26.8.1 rather than CI's 24.

Live read-only, no-issue collection over 2026-09-24 18:40:28 UTC to 2026-10-01 18:40:28 UTC took 418.19 seconds, within the 600-second phase limit. First private job request started at 5.63 seconds. Collected 16,203 runs and 6,160 private jobs (all attempts) from 56 repositories; all 9 organization private repositories were visible; 3,219 API requests were made. No time/request-budget exhaustion occurred. One Studio run's job inventory failed and appears explicitly under incomplete API coverage, so this is not a full-coverage result. No report issue was created and no live collection was retried.

The live run used local GitHub authentication, not the workflow's PAT_WORKFLOWS secret. GitHub-hosted execution and issue publication were not executed locally; offline workflow/program suites and the read-only live collection were used instead. The release-note body was checked against the full origin/main diff, updated via REST, and retains (part of #128). No merging or label changes.

@woksin
woksin merged commit 2920ea2 into main Oct 1, 2026
2 checks passed
@woksin
woksin deleted the ci/remaining-followups branch October 1, 2026 19:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant