Repository navigation
ci: don't cancel in-flight main-branch runs on a new push - #56
Open
polylane[bot] wants to merge 1 commit into
Open
polylane[bot] wants to merge 1 commit into
polylane[bot] wants to merge 1 commit into
Conversation
Co-authored-by: polylane[bot] <277585245+polylane[bot]@users.noreply.github.com>
Author
|
Note Production impact unlikely. Documentation, test, or CI-only change; nothing that runs in production is affected. Polylane analysed Did this help? React 👍 or 👎 so the next review is sharper. |
Author
|
This pull request is waiting on a decision: merge it if the change is still wanted, or close it if the fix is no longer needed. Either one settles it. It was opened on 2026-09-23 and has had no new activity for a week. If nothing happens on it within a week, Polylane closes it and keeps the branch, so reopening it brings the change back exactly as it stands. @MrgSub, the change touches what you own, so the review is with you. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes: comet and executor ship with no delivery gate: comet allows direct pushes to main, executor has no ruleset and has never run CI
Every merge to comet's main branch shared one CI concurrency group with the next merge, so a newer push cancelled the run in flight and the commit that actually shipped was left without a completed verification. Superseded runs are now cancelled only on pull requests, so a main-branch run always finishes. Pull-request CI behaves as before.
What caused this
Affected:
int_0c7912e40001wiz7sd656fidWhy this fix
comet's CI put every run for a ref into one concurrency group (
ci-${{ github.head_ref || github.ref }}) withcancel-in-progress: true. A push to main joined the same group as the run before it, so GitHub cancelled the run in flight. Of the last 50ciruns, 11 were cancelled and 7 of those were pushes to main, each immediately followed by a newer main push: runs 34449456597 and 34449467024 were cancelled at 2026-09-10T07:20:20Z and 07:20:28Z, then 34449558843 finished green at 07:21:37Z.This matters because a release is a version bump landing on main:
tag-release.ymltagsvfrom that commit and dispatches the release build, so the commit that publishes tarballs, Debian packages, AppImages and the macOS dmg is exactly the one whose verification was cancelled.Making
cancel-in-progressdepend on the event (github.event_name == 'pull_request') keeps superseded pull-request runs cancellable while letting a main-branch run finish. It is safe for the shared runner pool: only a run that has not started is replaced, never one in flight.This does not close the gap the issue is about. comet's ruleset 21962857 still enforces only
deletionandnon_fast_forward, has nopull_requestrule and emptyref_nameconditions, so unreviewed direct pushes to main remain allowed; executor has no ruleset at all and its workflows have never run. Those, plus secret scanning and Dependabot security updates, are GitHub organisation settings rather than repository code, and are recorded in the escalation attached to this issue.Out of scope
Causal chain
1 file changed (+4/-1)
.github/workflows/ci.yml: modified, +4/-1Generated by Polylane. You can ask follow-ups by mentioning @polylane in a comment.