Skip to content

[ci] Audit typed jobs into the required check - #3595

Open
joshlf wants to merge 1 commit into
Gqs4rhblhbsqga3glvc6tfjnakpdspo3bfrom
Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf
Open

[ci] Audit typed jobs into the required check#3595
joshlf wants to merge 1 commit into
Gqs4rhblhbsqga3glvc6tfjnakpdspo3bfrom
Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf

Conversation

@joshlf

@joshlf joshlf commented Aug 25, 2026

Copy link
Copy Markdown
Member

Audit the all-jobs-succeed behavior established by the typed plan and
semver integration. Require its exact top-level shape, externally
configured display name, empty permissions, hosted runner, always-run
condition, and minimum direct path from plan_ci, build_test, miri,
semver, and the job dependency audit.

Audit the exact ordered cancellation guard and require all five planner
outputs to be present before final aggregation. Treat Miri and semver as
the only optional jobs: each may be skipped exactly when its checked
enable output is false and must succeed when enabled. Match the total
skipped dependency count to those disabled jobs so no unrelated skip can
pass. Reject extra privileged steps, and require exact environments,
custom Bash, and the absolute jq run block.

On Linux, execute that exact Bash and jq program against a truth table
covering both optional jobs enabled and disabled. Reject enabled skips,
disabled successes, unrelated skips, failures, cancellations, malformed
results JSON, and invalid gates so the source audit and runtime meaning
cannot drift independently.

Normalize the aggregate YAML indentation and document that its display
name must stay coordinated with the external branch-protection or
ruleset setting.

Tests: offline zc tests
Tests: zc clippy with warnings denied
Tests: ci/check_actions.sh
Tests: cargo.sh ci audit
Tests: ci/check_fmt.sh
Tests: git diff --check

Authored by an agent, posting via joshlf's account


Latest Update: v29 — Compare vs v28

📚 Full Patch History

Links show the diff between the row version and the column version.

Version v28 v27 v26 v25 v24 v23 v22 v21 v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v29 v28 v27 v26 v25 v24 v23 v22 v21 v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v28 v27 v26 v25 v24 v23 v22 v21 v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v27 v26 v25 v24 v23 v22 v21 v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v26 v25 v24 v23 v22 v21 v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v25 v24 v23 v22 v21 v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v24 v23 v22 v21 v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v23 v22 v21 v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v22 v21 v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v21 v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v20 v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v19 v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v18 v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v17 v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v16 v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v15 v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v14 v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v13 v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v12 v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v11 v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v10 v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v9 v8 v7 v6 v5 v4 v3 v2 v1 Base
v8 v7 v6 v5 v4 v3 v2 v1 Base
v7 v6 v5 v4 v3 v2 v1 Base
v6 v5 v4 v3 v2 v1 Base
v5 v4 v3 v2 v1 Base
v4 v3 v2 v1 Base
v3 v2 v1 Base
v2 v1 Base
v1 Base
⬇️ Download this PR

Branch

git fetch origin refs/heads/Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf && git checkout -b pr-Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf FETCH_HEAD

Checkout

git fetch origin refs/heads/Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf && git checkout FETCH_HEAD

Cherry Pick

git fetch origin refs/heads/Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf && git cherry-pick FETCH_HEAD

Pull

git pull origin refs/heads/Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf

Stacked PRs enabled by GHerrit.

joshlf commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

Authored by an agent, posting via joshlf's account

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Hooray!

Reviewed commit: b221e68a61

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@joshlf
joshlf force-pushed the Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf branch from e2e5b8b to 96d41c3 Compare August 26, 2026 20:11
@joshlf
joshlf force-pushed the Gqs4rhblhbsqga3glvc6tfjnakpdspo3b branch from 6a81fe4 to 5c8b678 Compare August 26, 2026 20:11
@joshlf

joshlf commented Aug 26, 2026

Copy link
Copy Markdown
Member Author

Authored by an agent, posting via joshlf's account

@codex review

Please review the current head, 96d41c3b7deb554c0c64edab17a1fb8cabacd694.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

Reviewed commit: 96d41c3b7d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@joshlf
joshlf force-pushed the Gqs4rhblhbsqga3glvc6tfjnakpdspo3b branch from 5c8b678 to ec0310e Compare August 26, 2026 22:09
@joshlf
joshlf force-pushed the Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf branch 2 times, most recently from 18f1d3f to ad789f3 Compare August 26, 2026 22:35
@joshlf

joshlf commented Aug 26, 2026

Copy link
Copy Markdown
Member Author

Authored by an agent, posting via joshlf's account

@codex review

Please review the current head, ad789f3b277a26ae43c22dfd02adba10f16e970a.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Hooray!

Reviewed commit: ad789f3b27

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@joshlf
joshlf force-pushed the Gqs4rhblhbsqga3glvc6tfjnakpdspo3b branch from 30dcd81 to b8fe2df Compare August 26, 2026 23:31
@joshlf
joshlf force-pushed the Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf branch 2 times, most recently from 336e4ee to bb95028 Compare August 27, 2026 01:18
@joshlf
joshlf force-pushed the Gqs4rhblhbsqga3glvc6tfjnakpdspo3b branch 2 times, most recently from a083de6 to da22c8c Compare August 27, 2026 10:15
@joshlf
joshlf force-pushed the Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf branch from bb95028 to c32e32b Compare August 27, 2026 10:15
@joshlf

joshlf commented Aug 27, 2026

Copy link
Copy Markdown
Member Author

Authored by an agent, posting via joshlf's account

@codex review

Please review the current head, c32e32bafacd280c93b99a67cc8f6e1d33987ab8.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Chef's kiss.

Reviewed commit: c32e32bafa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@joshlf
joshlf force-pushed the Gqs4rhblhbsqga3glvc6tfjnakpdspo3b branch from da22c8c to 6f9c0bc Compare August 27, 2026 10:56
@joshlf
joshlf force-pushed the Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf branch from c32e32b to 18987e0 Compare August 27, 2026 10:56
@joshlf
joshlf force-pushed the Gqs4rhblhbsqga3glvc6tfjnakpdspo3b branch from 6f9c0bc to 545c5e9 Compare August 27, 2026 12:04
@joshlf
joshlf force-pushed the Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf branch from 18987e0 to 40e01ca Compare August 27, 2026 12:04
@joshlf

joshlf commented Aug 27, 2026

Copy link
Copy Markdown
Member Author

Authored by an agent, posting via joshlf's account

@codex review

Please review the current head, 40e01caf6fd3ca39e022f7ff0cf26ab33a2d266c.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Delightful!

Reviewed commit: 40e01caf6f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Audit the all-jobs-succeed behavior established by the typed plan and
semver integration. Require its exact top-level shape, externally
configured display name, empty permissions, hosted runner, always-run
condition, and minimum direct path from plan_ci, build_test, miri,
semver, and the job dependency audit.

Audit the exact ordered cancellation guard and require all five planner
outputs to be present before final aggregation. Treat Miri and semver as
the only optional jobs: each may be skipped exactly when its checked
enable output is false and must succeed when enabled. Match the total
skipped dependency count to those disabled jobs so no unrelated skip can
pass. Reject extra privileged steps, and require exact environments,
custom Bash, and the absolute jq run block.

On Linux, execute that exact Bash and jq program against a truth table
covering both optional jobs enabled and disabled. Reject enabled skips,
disabled successes, unrelated skips, failures, cancellations, malformed
results JSON, and invalid gates so the source audit and runtime meaning
cannot drift independently.

Normalize the aggregate YAML indentation and document that its display
name must stay coordinated with the external branch-protection or
ruleset setting.

Tests: offline zc tests
Tests: zc clippy with warnings denied
Tests: ci/check_actions.sh
Tests: cargo.sh ci audit
Tests: ci/check_fmt.sh
Tests: git diff --check

*Authored by an agent, posting via joshlf's account*

gherrit-pr-id: Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf
@joshlf
joshlf force-pushed the Gqs4rhblhbsqga3glvc6tfjnakpdspo3b branch from 545c5e9 to 985bbcd Compare August 27, 2026 12:26
@joshlf
joshlf force-pushed the Gnouzrlnq3bnxeg72jfe7d3xq6jymqqcf branch from 40e01ca to 3d017fb Compare August 27, 2026 12:26
@joshlf

joshlf commented Aug 27, 2026

Copy link
Copy Markdown
Member Author

Authored by an agent, posting via joshlf's account

@codex review

Please review the current head, 3d017fb7f862c0c8c4bdcdad4cc8f077fa67f6dd.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Chef's kiss.

Reviewed commit: 3d017fb7f8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants