Skip to content

fix(ci): drop the 1x1 matrix so the required check name is actually stable - #40

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/38-drop-the-1x1-matrix
Sep 21, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/38-drop-the-1x1-matrix

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Closes #38.

What #39 got wrong

#39 renamed the job to Julia tests and I reported the required check as version-stable. It is not, and I never measured the thing that matters. Measured on #39's own head 776e340d, after it had landed:

what GitHub actually posted Julia tests (1.12.5, ubuntu-24.04)
what the ruleset requires Julia tests

GitHub appends the matrix combination to a job's posted check name whenever the name: does not itself reference the matrix. The old name, Julia ${{ matrix.julia-version }} / ${{ matrix.os }}, suppressed the suffix by accident; replacing it with a static string switched the suffix on. A 1×1 matrix is still a matrix.

So both pins stayed embedded in the check name, the required context Julia tests was never reported at all, and main has been sitting in exactly the deadlock this issue describes — #39 merged only because an admin bypass was available. The bump demonstration in that PR parsed the YAML name: field and called it "the check name"; it could not have caught this.

The control was in the same output all along: Repo hygiene (licence · format · lint · commit), a job with no matrix, posts its name: verbatim.

The fix

The matrix selected exactly one combination and bought nothing, so it is removed rather than worked around:

  • runs-on: ubuntu-24.04 — a literal, because runs-on cannot read env
  • setup-julia version: "1.12.5" — a literal

Each keeps the reasoning that used to sit beside its matrix entry. The ruleset context is unchanged — Julia tests was always the target state; the only thing wrong was what the workflow posted.

Why the guard did not catch it

test_install_pins.jl asserted that no job name interpolates anything — a property of the YAML name: field — while the consumer, the ruleset, matches the rendered check-run name. The guard asked a different question than its consumer, so it passed on a broken fix.

It now asserts both necessary conditions, over every job in the file:

  1. the name interpolates nothing, and
  2. the job has no strategy.matrix.

Run against the previous commit, that assertion fails on test alone — 5 pass / 1 fail — so it discriminates rather than blanket-failing. If a matrix is ever genuinely wanted, the required context must first move to a matrix-free aggregator job, and the comment says so.

CI installs what is pinned made the same claims about the same two values and is repointed at where they now live, locating the setup step by its uses: rather than by index. Mutating either literal fails it (verified: version → 1.12.6, runs-on → ubuntu-latest, one failure each at the right line).

Acceptance criteria

# criterion status
1 version-stable job name the posted check name must read exactly Julia tests — evidence added as a comment below, read off this PR's head, not off the YAML
2 ruleset context updated in the same change already Julia tests; unchanged, and now actually satisfiable
3 bump demonstrated a pin bump changes only the literal; the posted name cannot move, because there is no matrix to append
4 test_install_pins.jl passing 102 / 102

🤖 Generated with Claude Code

https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm

#39 renamed this job to `Julia tests` and claimed the required status check
was therefore version-stable. It was not, and the claim was never measured.

MEASURED on PR #39 head 776e340, after that change had landed:

    Julia tests (1.12.5, ubuntu-24.04)   <- what GitHub actually posted
    Julia tests                          <- what the ruleset requires

GitHub appends the matrix combination to a job's posted check name whenever
the `name:` does not itself reference the matrix. The old interpolating name
suppressed the suffix by accident; replacing it with a static string turned
the suffix on. A 1x1 matrix is still a matrix, so both pins stayed embedded
in the check name and the required context `Julia tests` was never reported
at all -- so `main` has been sitting in precisely the deadlock issue #38
describes, with #39 itself merged only by an admin bypass.

The matrix selected exactly one combination and bought nothing, so it is
removed rather than worked around: `runs-on: ubuntu-24.04` and the
setup-julia `version: "1.12.5"` are literals, each keeping the reasoning
that used to sit beside the matrix entry. The non-matrix `repo-hygiene` job
was the control -- it has always posted its `name:` verbatim.

Why the guard did not catch it: `test_install_pins.jl` asserted that no job
name interpolates anything -- a property of the YAML `name:` field -- while
the consumer, the ruleset, matches the rendered check-run name. The guard
asked a different question than its consumer, so it passed on a broken fix.
It now asserts BOTH necessary conditions, over every job in the file: the
name interpolates nothing AND the job has no `strategy.matrix`. Run against
the previous commit that assertion fails on `test` alone (5 pass / 1 fail),
so it discriminates rather than blanket-failing.

`CI installs what is pinned` made the same claims about the same two values
and has been repointed at where they now live, locating the setup step by
its `uses:` rather than by index. Mutating either literal fails it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 50 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 3c3e04fd-7eab-4acc-bef0-3119af0534f3

📥 Commits

Reviewing files that changed from the base of the PR and between 8a098d2 and 7adaeb7.

📒 Files selected for processing (2)
  • .github/workflows/ci.yml
  • test/unit/test_install_pins.jl

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit 6c29b53 into main Sep 21, 2026
3 of 4 checks passed
@hyperpolymath
hyperpolymath deleted the fix/38-drop-the-1x1-matrix branch September 21, 2026 23:08
hyperpolymath added a commit that referenced this pull request Sep 21, 2026
The third and last class of `ci.yml` reader. Removing the 1x1 matrix in #40
fixed the workflow and #41 fixed the TypeScript coupling test, but five live
documents still describe the julia pin as living in "the CI matrix", which no
longer exists. A pin table that names a source of truth that is not there is
worse than no table: the next person to bump julia goes looking for a matrix,
does not find one, and has no way to tell whether the doc or the workflow is
wrong.

  docs/reproducibility.md:26,60   the pin table and the pin web
  docs/compliance/standards-alignment.md:40   the single-sourcing claim
  docs/audit/type-system-reconnaissance.md:210   what test_install_pins.jl gates
  README.md:546   the CI gate summary

Left alone deliberately: the nine occurrences under `docs/milestones/` and
`docs/milestones/02c-cicd.md`. Those are dated records of what the workflow
was at that milestone, and rewriting history to match today's shape would
destroy the only evidence that the matrix ever existed -- which is exactly the
evidence issue #38 turned on.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
hyperpolymath added a commit that referenced this pull request Sep 21, 2026
The third and last class of `ci.yml` reader. Removing the 1x1 matrix in #40
fixed the workflow and #41 fixed the TypeScript coupling test, but five live
documents still describe the julia pin as living in "the CI matrix", which no
longer exists. A pin table that names a source of truth that is not there is
worse than no table: the next person to bump julia goes looking for a matrix,
does not find one, and has no way to tell whether the doc or the workflow is
wrong.

  docs/reproducibility.md:26,60   the pin table and the pin web
  docs/compliance/standards-alignment.md:40   the single-sourcing claim
  docs/audit/type-system-reconnaissance.md:210   what test_install_pins.jl gates
  README.md:546   the CI gate summary

Left alone deliberately: the nine occurrences under `docs/milestones/` and
`docs/milestones/02c-cicd.md`. Those are dated records of what the workflow
was at that milestone, and rewriting history to match today's shape would
destroy the only evidence that the matrix ever existed -- which is exactly the
evidence issue #38 turned on.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: required status check embeds the Julia version, so a pin bump will deadlock every PR

1 participant