Skip to content

Check out the testbed, not the caller, in the reusable workflow - #10

Merged
bdarnell merged 1 commit into
tornadoweb:mainfrom
bdarnell:claude/missing-validate-packages-script-5wyapq
Sep 21, 2026
Merged

bdarnell merged 1 commit into
tornadoweb:mainfrom
bdarnell:claude/missing-validate-packages-script-5wyapq

Conversation

@bdarnell

Copy link
Copy Markdown
Member

tornado's build.yml calls .github/workflows/testbed.yml via workflow_call, and a called workflow runs in the caller's workspace. The three bare actions/checkout steps therefore fetched tornadoweb/tornado, which has no scripts/, and the first step to touch one died:

Run python3 scripts/validate_packages.py
python3: can't open file '/home/runner/work/tornado/tornado/scripts/validate_packages.py': [Errno 2] No such file or directory
Process completed with exit code 2.

Validate package definitions is just where it surfaced first — setup.sh, run_one.sh and report.sh would all have failed the same way.

The fix

All three checkouts now name the harness explicitly:

- name: Check out the testbed
  uses: actions/checkout@v6
  with:
    repository: ${{ job.workflow_repository }}
    ref: ${{ job.workflow_sha }}
    persist-credentials: false

job.workflow_repository / job.workflow_sha are the repository and commit of the workflow file that defines the job — this file. That keeps the scripts in lockstep with the workflow the caller pinned (...@main resolves once, at dispatch) rather than with whatever main happens to be when each job starts.

Behaviour is unchanged for the three paths that already worked, since for a job defined directly in a workflow these resolve to this repository at the run's own commit: workflow_dispatch, the weekly schedule, and pins.yml's local uses: ./.github/workflows/testbed.yml.

The gotcha is recorded in REPORT.md, because the thing that makes it easy to miss is that dispatching the workflow from this repo can never catch it — only tornado's call exercises the broken path.

Notes

  • The four job.workflow_* properties shipped 2026-09-03 and are github.com-only (not GitHub Enterprise Server), which is fine for this workflow. They are the supported replacement for github.job_workflow_sha, which the docs describe but which has never actually been populated.
  • Verified on this branch: zizmor --offline .github/workflows clean, tests/harness_test.sh 45 passed / 0 failed, python3 scripts/validate_packages.py OK on all 9 packages. The failing path itself can only be exercised by a real call from tornado, so it is not covered by anything that runs here.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CU3p31TLwKPXWbijSHip6u

tornado's build.yml calls .github/workflows/testbed.yml via `workflow_call`,
and a called workflow runs in the *caller's* workspace. The three bare
`actions/checkout` steps therefore fetched tornadoweb/tornado, which has no
scripts/, and the first step to touch one died:

    python3: can't open file
    '/home/runner/work/tornado/tornado/scripts/validate_packages.py'

Name the harness explicitly with `job.workflow_repository` and
`job.workflow_sha` — the repository and commit of the workflow file that
defines the job, which is this file. That keeps the scripts in lockstep with
the workflow the caller pinned, and is unchanged behaviour for the three
paths that already worked: workflow_dispatch, the weekly schedule, and
pins.yml's local `uses: ./.github/workflows/testbed.yml`.

Only tornado's call exercised this, so a dispatch from this repo never would
have caught it; note that in REPORT.md's gotchas alongside the fix.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CU3p31TLwKPXWbijSHip6u
@bdarnell
bdarnell merged commit 7ff41b2 into tornadoweb:main Sep 21, 2026
1 check passed
@bdarnell
bdarnell deleted the claude/missing-validate-packages-script-5wyapq branch September 21, 2026 02:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants