Check out the testbed, not the caller, in the reusable workflow - #10
Merged
bdarnell merged 1 commit intoSep 21, 2026
Conversation
tornado's build.yml calls .github/workflows/testbed.yml via `workflow_call`,
and a called workflow runs in the *caller's* workspace. The three bare
`actions/checkout` steps therefore fetched tornadoweb/tornado, which has no
scripts/, and the first step to touch one died:
python3: can't open file
'/home/runner/work/tornado/tornado/scripts/validate_packages.py'
Name the harness explicitly with `job.workflow_repository` and
`job.workflow_sha` — the repository and commit of the workflow file that
defines the job, which is this file. That keeps the scripts in lockstep with
the workflow the caller pinned, and is unchanged behaviour for the three
paths that already worked: workflow_dispatch, the weekly schedule, and
pins.yml's local `uses: ./.github/workflows/testbed.yml`.
Only tornado's call exercised this, so a dispatch from this repo never would
have caught it; note that in REPORT.md's gotchas alongside the fix.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CU3p31TLwKPXWbijSHip6u
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
tornado's
build.ymlcalls.github/workflows/testbed.ymlviaworkflow_call, and a called workflow runs in the caller's workspace. The three bareactions/checkoutsteps therefore fetchedtornadoweb/tornado, which has noscripts/, and the first step to touch one died:Validate package definitionsis just where it surfaced first —setup.sh,run_one.shandreport.shwould all have failed the same way.The fix
All three checkouts now name the harness explicitly:
job.workflow_repository/job.workflow_shaare the repository and commit of the workflow file that defines the job — this file. That keeps the scripts in lockstep with the workflow the caller pinned (...@mainresolves once, at dispatch) rather than with whatevermainhappens to be when each job starts.Behaviour is unchanged for the three paths that already worked, since for a job defined directly in a workflow these resolve to this repository at the run's own commit:
workflow_dispatch, the weeklyschedule, andpins.yml's localuses: ./.github/workflows/testbed.yml.The gotcha is recorded in
REPORT.md, because the thing that makes it easy to miss is that dispatching the workflow from this repo can never catch it — only tornado's call exercises the broken path.Notes
job.workflow_*properties shipped 2026-09-03 and are github.com-only (not GitHub Enterprise Server), which is fine for this workflow. They are the supported replacement forgithub.job_workflow_sha, which the docs describe but which has never actually been populated.zizmor --offline .github/workflowsclean,tests/harness_test.sh45 passed / 0 failed,python3 scripts/validate_packages.pyOK on all 9 packages. The failing path itself can only be exercised by a real call from tornado, so it is not covered by anything that runs here.🤖 Generated with Claude Code
https://claude.ai/code/session_01CU3p31TLwKPXWbijSHip6u