Skip to content

automation: rebase edera/4.22 onto upstream staging-4.22 nightly - #46

Merged
kaniini merged 2 commits into
edera/4.22from
automation/nightly-upstream-rebase
Oct 7, 2026
Merged

kaniini merged 2 commits into
edera/4.22from
automation/nightly-upstream-rebase

Conversation

@kaniini

@kaniini kaniini commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Adds a nightly workflow in which Claude rebases edera/4.22 onto xen-project staging-4.22, then lands the result automatically if it is clean or opens a pull request for review if it is not.

How a night runs

  1. prepare — fetches upstream. Stops if edera/4.22 already contains staging-4.22, or if an open rebase PR already covers the same pair of tips, so quiet nights never start the model.
  2. rebase — Claude follows .automation/skills/upstream-rebase/SKILL.md: replay, resolve conflicts, fix build breaks in the commit at fault, build, audit any new XSAs (including whether each fix survived the replay), write a report. This job holds a read-only token and cannot push; the branch leaves it as a git bundle.
  3. verify + build — judged independently, from the commit the run started from:
    • verify-upstream-rebase.sh: on the upstream tip, linear, no commit lost or gained (a changed patch-id is accepted only where the commit's own +/- lines are identical and just the hunk context moved), and the tree changed by exactly the upstream delta.
    • x86, arm64 defconfig, arm64 + PCI_PASSTHROUGH.
  4. publish
    • Clean (checker passes, all builds pass): force-push edera/4.22 with --force-with-lease pinned to the starting tip; old tip kept as backup/edera-4.22-pre-rebase-….
    • Not clean: push rebase/edera-4.22/<date>-<old>-<upstream> and open a PR with the report and checker output. Approving it lands it via upstream-rebase-land.yml (the merge button would graft a second copy of the series). Older rebase PRs are closed as superseded.
    • No result: one standing issue, commented on each failed night.

Any conflict Claude resolves shows up as drift, so those nights always go to a human.

Safety

  • The model never holds a write token. github_token is passed explicitly so the action does not mint its own.
  • PR-triggered workflows (including the land workflow and the review checks) run the PR branch's own .github/ with repository secrets. publish therefore refuses to push anything, as edera/4.22 or as a PR, whose .github/, .automation/ or .review/ changes differ from upstream's changes to those paths.
  • The land workflow requires the approval to be for the current head and the approver to have write access, and takes the expected edera/4.22 tip from the branch name, which cannot be edited on an open PR. If edera/4.22 moved, it pushes nothing.

Testing

  • The checker passes the two real staging-4.22 rebases from 2026-09-03 and 2026-09-08, and on the latter reports the MEMF_zero commit as context-only, matching the manual audit at the time.
  • .github/scripts/tests/verify-upstream-rebase.test.sh (8 cases, run by upstream-rebase-selftest.yml) builds a throwaway repo and checks that honest replays pass and that edited (with a repeated subject), dropped, added and merge commits and a stale base are refused. Mutation-checked: reintroducing an earlier checker bug makes it fail.
  • The automation-path guard passes both real rebases and refuses one with an injected workflow file.
  • actionlint and shellcheck clean.
  • Not yet run in Actions; it needs the configuration below first.

Configuration needed before it can run

  • A GitHub App installed on this repo with contents, pull-requests and workflows write, allowed to bypass the edera/4.22 rules: vars.REBASE_APP_CLIENT_ID, secrets.REBASE_APP_PRIVATE_KEY. GITHUB_TOKEN cannot push commits that touch .github/workflows/, and PRs it opens do not trigger the review checks.
  • Claude API federation: vars.REBASE_FEDERATION_RULE_ID, REBASE_ORGANIZATION_ID, REBASE_SERVICE_ACCOUNT_ID, REBASE_WORKSPACE_ID, each falling back to the PR_REVIEW_* variable. The rule must accept a scheduled run's OIDC subject, which a rule written for pull_request events will not.

Add a scheduled workflow in which Claude rebases the downstream series
onto xen-project staging-4.22, following
.automation/skills/upstream-rebase/SKILL.md: it replays the series,
resolves conflicts, fixes what the replay broke, builds, audits any XSAs
upstream brought in, and writes a report.

The model's own account of its result decides nothing. It runs with a
read-only token and cannot push; its branch leaves the job as a git
bundle and is judged independently:

- verify-upstream-rebase.sh proves the series sits on the upstream tip,
  is linear, lost or gained no commit (a changed patch-id is accepted
  only where the commit's own +/- lines are identical), and changed the
  tree by exactly the upstream delta;
- x86, arm64 defconfig and arm64 with PCI passthrough are built.

If all pass, edera/4.22 is force-pushed with a lease pinned to the tip
the rebase started from, and the old tip is kept as a backup branch.
Otherwise the result is opened as a pull request carrying the report,
and approving it lands it (upstream-rebase-land.yml). A night with no
result opens an issue.

Pull-request-triggered workflows run the branch's own .github/ with
repository secrets, so a result whose .github/, .automation/ or .review/
changes differ from upstream's is never pushed anywhere.

Nights with nothing new upstream stop before the model starts.

Needs a GitHub App (vars.REBASE_APP_CLIENT_ID,
secrets.REBASE_APP_PRIVATE_KEY) with contents, pull-requests and
workflows write and a bypass on the edera/4.22 rules, and a federation
rule that accepts a scheduled run (REBASE_* variables, falling back to
PR_REVIEW_*).
bleggett
bleggett previously approved these changes Oct 6, 2026

@github-actions github-actions Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR Review

Reviewed at d21f92c.

This check did not finish, so it has nothing to say about the diff. The run log has the reason.

Test Coverage

Reviewed at d21f92c.

This check did not finish, so it has nothing to say about the diff. The run log has the reason.

azenla
azenla previously approved these changes Oct 6, 2026
Comment thread .github/workflows/upstream-rebase.yml Outdated
- name: Normalize identifiers
id: ids
env:
RULE: ${{ vars.REBASE_FEDERATION_RULE_ID || vars.PR_REVIEW_FEDERATION_RULE_ID }}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just a note, this will never be PR_REVIEW_FEDERATION_RULE_ID, since REBASE_FEDERATION_RULE_ID is set it will always take precedence. It's not harmful since this workflow isn't triggered on pull_request_review anyways. Just wanted to note that though

tycho
tycho previously approved these changes Oct 7, 2026
Co-authored-by: James Petersen <jpetersenames@gmail.com>
Signed-off-by: Ariadne Conill <ariadne@ariadne.space>
@kaniini
kaniini dismissed stale reviews from tycho, azenla, and bleggett via d21f92c October 7, 2026 17:05
@kaniini
kaniini merged commit 9bac195 into edera/4.22 Oct 7, 2026
4 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants