ci(merge-queue): name a no-runner red as infra:no-runner, with a once-per-head re-queue verdict - #21946
Merged
objectstack-fleet[bot] merged 2 commits intoOct 6, 2026
Conversation
…riage comment Claude-Session: https://claude.ai/code/session_01VDtqoecgES7ScQYGbFVDRv Co-authored-by: Claude <noreply@anthropic.com>
…re-queue budget Claude-Session: https://claude.ai/code/session_01VDtqoecgES7ScQYGbFVDRv Co-authored-by: Claude <noreply@anthropic.com>
This was referenced Oct 6, 2026
objectstack-fleet
Bot
deleted the
claude/issue-21933-mq-no-runner-requeue
branch
October 6, 2026 04:44
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #21933 — this PR delivers the classification, the comment, and the once-per-head re-queue verdict. It does not deliver the automatic re-queue act: the workflow holds no credential that can enqueue a pull request (see "Blocker" below). The card should stay open for that half.
What changed
.github/workflows/merge-queue-triage.ymlgains limb ③:infra:no-runnerwhen it endedcancelledwith an emptyrunner_nameand no steps. A cancelled job the record does not decide (it did get a runner) is checked for the platform's "The job was not acquired by Runner" check-run annotation. No log text is read. The build isinfra:no-runneronly when that explains every red. Every other red job must be an aggregate gate whose failed steps are allVerify … results, and whose own shard family (NAME (k/n)) has a no-runner member. Anything else makes the buildfailure, read as before: a real failing step, a cancelled job that had a runner, an aggregate from a different family, or an annotation that could not be read.infra:no-runnerbuild, the script reads the PR's current head throughpulls.get. The comment carries a durable per-head marker: a hidden HTML comment namedmerge-queue-infra:no-runnerwith the PR number, head sha and run id. The nextinfra:no-runnerred on the same head finds that marker. Its verdict is then "hand to a person, do not re-queue", and it names the earlier queue build. Afailurebuild never gets a verdict and never writes the marker. If the head or the PR's comments cannot be read, the verdict isunknown, neveronce.分类:infra:no-runneror分类:failure. Forinfra:no-runnerit lists the no-runner jobs, the aggregates they explain, and the verdict. For a mixed build it still lists the no-runner jobs, and it names the red those jobs cannot explain.⛔ The attestation rule is unchanged: a shard that never ran still does not count as passing (#6082). The comment says so too. Nothing here changes whether a build is green. The idempotency read of the PR's comments now paginates, because the per-head markers live in those comments.
Permission change, declared: the job gains
checks: read(read only) for the annotation leg. No other grant changes. The harness now pins that the job holds nocontents:grant.Blocker — the re-queue act
The workflow's verdict cannot be carried out by the workflow.
enablePullRequestAutoMergethrough the fleet App token.fleet-write.ymldocuments that this needscontents: write, which is "ONE consumer". This workflow'sGITHUB_TOKENholdsactions: read,pull-requests: write,issues: writeand nowchecks: read.contents: writetoGITHUB_TOKENand callingenqueuePullRequest/enablePullRequestAutoMergewould widen this job's permissions. Even then, the merge group would be created byGITHUB_TOKEN, and GitHub does not start workflow runs for events thatGITHUB_TOKENcauses. It is not established that CI would ever build such a merge group, and this PR does not measure it.So the comment says the workflow will not re-queue, and asks a person to re-queue once. The harness makes an enqueue call an unmodelled API that fails the battery (mutation M28). Wiring the act needs a decision: either a second consumer of the fleet App token with
contents: write, or a measuredGITHUB_TOKENpath.Done-when, clause by clause
failure, with no verdict and no marker.scripts/fixtures/merge-queue-triage/are trimmed real records, with provenance in the README:run-37374282440.jobs.json,run-37371558473.jobs.jsonandcheck-run-111979038621.annotations.json.Validation (at 499d0ae)
node scripts/check-merge-queue-triage-outcome.mjs→OK (133 assertions over 34 scenarios …). The base had 90 assertions over 24 scenarios.node scripts/check-merge-queue-triage-outcome.mjs --self-test→181 assertions, 32 mutations of the shipped script each driven to red.node scripts/pm/dispatch-gates.mjs --commandsderived 51 commands. 50 ran with exit 0, includingpnpm check:workflow-status-functions,check:nul-bytes,check:required-contextsandcheck:shard-attestation. Reconciliation--ran: 51 accounted, 0 UNRUN.pnpm check:pm-dispatch-gates. Its--self-testhalf alone exceeded the 10-minute foreground cap (exit 124). Its log showed 1785 pass marks and 1 fail mark. The fail mark is onpackages/qa/dogfood/test/per-file-cwd.setup.ts, a path this diff does not touch. Declared to CI.eslint --no-inline-config --format json scripts/check-merge-queue-triage-outcome.mjs→ 1 file, 0 errors, 0 warnings. The repo config enables no type-aware linting (noparserOptions.project), so this diff cannot move the verdict on any untouched file. The workflow YAML is not an eslint target.Acceptance notes
workflows: [CI]only. Run 37371558492 is the Governed Surface Guard workflow, and its no-runner red is never triaged. The same holds for the sibling guard runs that ejected fix(plugin-auth)!: implicit account linking requires the standard local-ownership condition; unlink is honoured #21872 that afternoon. Out of this card's file surface; noted here only.cancelled(notfailure) still gets no comment. That is the existing eviction rule, unchanged.Generated by Claude Code