Repository navigation
test: pin the concurrency and cancel-in-progress contract on the PR lane - #1002
Merged
Merged
Conversation
Both pull_request-triggered workflows (ci.yml, codeql.yml) declare a per-PR concurrency group with cancel-in-progress: true, and nothing in the suite requires either property. Without the block, every superseded push runs to completion and reports onto the same commit status as the run that matters. Without per-PR keying, a constant group turns cancel-in-progress from superseding this PR's own stale run into cancelling somebody else's PR. tests/ci-concurrency.test.mjs asserts the group exists, cancels, and is keyed on github.event.pull_request.number, github.head_ref or github.ref. deploy-gh-pages.yml's deliberate constant "pages" group is recorded in SERIALISED_WORKFLOWS with its reason, following the retiring-baseline convention of KNOWN_PERSISTING_CHECKOUTS and KNOWN_UNBOUNDED_JOBS in tests/ci-supply-chain.test.mjs; a companion test deletes the entry once the workflow satisfies both halves. Every guard takes the parsed workflows as an argument so its failure branch runs against a fixture. Closes #1001 Signed-off-by: quality <quality@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "quality" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will automatically remove the |
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Test Improvement
Adds
tests/ci-concurrency.test.mjs, pinning the concurrency contract thatkeeps the
pull_requestlane from racing itself. No production code and noworkflow file is touched — the test reads
.github/workflows/*.ymland writesnothing there.
Both PR-triggered workflows already satisfy the contract; nothing asserted it:
.github/workflows/ci.yml:14-18— per-PR group,cancel-in-progress: true.github/workflows/codeql.yml:39-41— sameSix guards over the parsed workflows:
pull_requestdetection is not vacuous (an empty set would pass everything below)concurrencygroupcancel-in-progress: truegithub.event.pull_request.number,github.head_reforgithub.refinside a${{ ... }}expressionSERIALISED_WORKFLOWSwith its reasondeploy-gh-pages.ymlis the single allowlist entry: it uses the constantpagesgroup withcancel-in-progress: falseon purpose, because cancelling adeploy halfway can leave Pages serving a partially uploaded artifact. The
allowlist follows the retiring-baseline convention already established by
KNOWN_PERSISTING_CHECKOUTSandKNOWN_UNBOUNDED_JOBSintests/ci-supply-chain.test.mjs.Why a constant group is treated as a violation
concurrency: ciis one key for the whole repository. Paired withcancel-in-progress: trueit stops superseding this PR's stale run andstarts cancelling other people's PRs. The per-PR keying is what makes the
cancellation safe, so both are asserted.
Verification
Each scanner takes the parsed workflows as an argument rather than closing over
the repository's own, so its failure branch is driven by a fixture — a guard
whose failure path never runs is a guard nobody has checked.
Also mutation-tested against the real
.github/workflows/ci.yml(revertedafter; the committed diff is the test file only):
cancel-in-progress: true→falseconcurrency:block deletedCoverage,
npm run test:unit:coverage:check(TZ=UTC) at this head, exit 0:npx prettier --checkpasses on the new file.Disjointness
Claims
tests/ci-concurrency.test.mjsonly — a new file touched by no otheropen PR. #1000 pins
continue-on-erroron ci.yml's gating jobs; #991 and #989are in
tests/tools/e2e-coverage-report.mjsand its CLI; #996 is the unitreporter's source-file set; #998 is the adr/ contract; #994 is
SECURITY.md.No overlap in files or assertions.
Related Issue
Closes #1001
Filed by quality agent (hold-gated mode). Human review required.
— hive: agent=quality backend=copilot model=claude-opus-5 copilot=1.0.88