Skip to content

ci: don't cancel in-flight main-branch runs on a new push - #56

Open
polylane[bot] wants to merge 1 commit into
mainfrom
polylane/autofix/np5hrfsjesdb
Open

polylane[bot] wants to merge 1 commit into
mainfrom
polylane/autofix/np5hrfsjesdb

Conversation

@polylane

@polylane polylane Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Fixes: comet and executor ship with no delivery gate: comet allows direct pushes to main, executor has no ruleset and has never run CI

Every merge to comet's main branch shared one CI concurrency group with the next merge, so a newer push cancelled the run in flight and the commit that actually shipped was left without a completed verification. Superseded runs are now cancelled only on pull requests, so a main-branch run always finishes. Pull-request CI behaves as before.

flowchart LR
  P1["push main A"] -->|"queues"| G["concurrency group ci-main"]
  P2["push main B"] -->|"queues"| G
  G -->|"before: cancel-in-progress true"| C["match A cancelled"]
  G -->|"after: cancel-in-progress pull_request only"| C2["match A runs to completion"]
  G --> C3["match B runs"]
Loading

What caused this

Affected: int_0c7912e40001wiz7sd656fid

Why this fix

comet's CI put every run for a ref into one concurrency group (ci-${{ github.head_ref || github.ref }}) with cancel-in-progress: true. A push to main joined the same group as the run before it, so GitHub cancelled the run in flight. Of the last 50 ci runs, 11 were cancelled and 7 of those were pushes to main, each immediately followed by a newer main push: runs 34449456597 and 34449467024 were cancelled at 2026-09-10T07:20:20Z and 07:20:28Z, then 34449558843 finished green at 07:21:37Z.

This matters because a release is a version bump landing on main: tag-release.yml tags v from that commit and dispatches the release build, so the commit that publishes tarballs, Debian packages, AppImages and the macOS dmg is exactly the one whose verification was cancelled.

Making cancel-in-progress depend on the event (github.event_name == 'pull_request') keeps superseded pull-request runs cancellable while letting a main-branch run finish. It is safe for the shared runner pool: only a run that has not started is replaced, never one in flight.

This does not close the gap the issue is about. comet's ruleset 21962857 still enforces only deletion and non_fast_forward, has no pull_request rule and empty ref_name conditions, so unreviewed direct pushes to main remain allowed; executor has no ruleset at all and its workflows have never run. Those, plus secret scanning and Dependabot security updates, are GitHub organisation settings rather than repository code, and are recorded in the escalation attached to this issue.

Out of scope
  • Mail-0/executor's identical concurrency expression: its nine workflows have never produced a run (executor is a fork of UsefulSoftwareCo/executor with 0 runs against the upstream's 16,839), so the same edit there would be unverifiable; it should land together with enabling Actions on the fork.
  • The delivery gate itself, secret scanning and Dependabot security updates: GitHub repository and organisation settings, tracked as a separate escalation, not repository code.
Causal chain
  • Signal (metric): comet ci workflow runs with conclusion=cancelled on push to main
  • Surfacing site: Mail-0/comet at GitHub Actions: .github/workflows/ci.yml#concurrency
  • Mechanism: concurrency.group ci-${{ github.head_ref || github.ref }} plus cancel-in-progress: true puts a push-to-main run in the same group as the previous main run, so GitHub cancels the run in flight; 7 of the last 50 ci runs were push-to-main cancellations, each superseded within seconds by a newer main push.
  • Producer: Mail-0/comet .github/workflows/ci.yml
  • What happens to the failed unit today: ci.yml triggers on pull_request and push to main; cancel-in-progress currently true for every event.
  • Producer evidence:
    • Mail-0/comet .github/workflows/ci.yml lines 10-13: group ci-${{ github.head_ref || github.ref }}, cancel-in-progress: true
    • GitHub Actions runs 34449456597 (2026-09-10T07:20:20Z, cancelled) and 34449467024 (07:20:28Z, cancelled) both push/main, then 34449558843 green at 07:21:37Z
    • GitHub Actions runs 34442362726, 34412268463, 34325102239, 34316553658, 34104447787 all push/main cancelled
1 file changed (+4/-1)
  • .github/workflows/ci.yml: modified, +4/-1

View thread View autofix


Generated by Polylane. You can ask follow-ups by mentioning @polylane in a comment.

Co-authored-by: polylane[bot] <277585245+polylane[bot]@users.noreply.github.com>
@polylane polylane Bot added polylane severity:medium Polylane autofix severity: medium labels Sep 23, 2026
@polylane
polylane Bot requested a review from MrgSub September 23, 2026 06:26
@polylane

polylane Bot commented Sep 23, 2026

Copy link
Copy Markdown
Author

Note

Production impact unlikely.

Documentation, test, or CI-only change; nothing that runs in production is affected.

View in Polylane Disable reviews

Polylane analysed 4160206 for production impact. You can ask follow-ups by mentioning @polylane in a comment.

Did this help? React 👍 or 👎 so the next review is sharper.

@polylane

polylane Bot commented Oct 6, 2026

Copy link
Copy Markdown
Author

This pull request is waiting on a decision: merge it if the change is still wanted, or close it if the fix is no longer needed. Either one settles it.

It was opened on 2026-09-23 and has had no new activity for a week. If nothing happens on it within a week, Polylane closes it and keeps the branch, so reopening it brings the change back exactly as it stands.

@MrgSub, the change touches what you own, so the review is with you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

polylane severity:medium Polylane autofix severity: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant