Skip to content

fix(ci): stop enrichment bot commits racing content validation - #92

Merged
bradvin merged 1 commit into
mainfrom
fix/generated-metadata-ci-race
Oct 2, 2026
Merged

bradvin merged 1 commit into
mainfrom
fix/generated-metadata-ci-race

Conversation

@foo-bender

Copy link
Copy Markdown
Collaborator

Summary

  • Remove same-repository enrichment commits/pushes and reduce enrichment contents permission to read. Generated metadata is now a branch-read-only preflight for both same-repository and fork PRs.
  • Reuse the correction-comment/fail path for both origins. A bot-owned marker lets repeated runs update the existing comment rather than post duplicates. Commands include exact changed slugs, actual PR author, trusted-base attribution, and --require-submitters validation; media commands appear only after approval.
  • Document generating internal submitter metadata before opening a PR. Keep trusted-base script execution and attribution, approved-review-only media generation, required validate, and normal fork workflow approvals unchanged.

Why

Confirmed example: Validate Content run 36976264940 failed with tools/openrig.md: submitter must be set in tool-submitters.json while enrichment generated attribution and pushed a bot commit concurrently. The resulting validation needed a maintainer rerun (action_required). Removing branch mutation avoids that race rather than adding credentials, privileged PR-code execution, or automatic approvals.

Verification

Executed locally with Node v24.20.0:

  • RED: node --test --test-reporter=spec test/enrich-preflight.test.mjs test/enrich-workflow-security.test.mjs test/validate-workflow-security.test.mjs — 7 tests, 4 failed as intended, 3 passed before implementation.
  • GREEN (including an additional executable comment-reuse regression): same command — 8 passed, 0 failed.
  • npm test -- --test-reporter=spec — 90 passed, 0 failed/skipped.
  • npm run validate:content -- --require-submitters — passed: 16 categories, 51 tools, 1 redirect/retirement.
  • git diff --check — passed.
  • Existing enrichment/validation security tests, validation/publish workflows, and all scripts are unchanged.

Regression coverage prohibits enrichment git commit/push steps and contents-write permission; checks both PR origins' correction/failure path; executes comment generation and mocked first/create plus repeated/update behavior; preserves trusted-base attribution and approval-gated media.

Known limits / scope

  • This workflow-only PR does not change tools, so the tool-path-filtered enrichment workflow will not exercise the new implementation live here. The privileged workflow uses the base version until this fix is reviewed and merged; executable local regressions cover the changed comment behavior without writing GitHub comments.
  • Fork approval policy remains unchanged. Contributors still must commit generated files; missing metadata intentionally fails rather than being automatically repaired.
  • Existing website-fetch behavior and old contributor PRs are not changed. An existing correction comment is not cleared on success.
  • No settings changes, automatic workflow approvals, added credentials, untrusted PR script execution, merge, or deployment.

@bradvin
bradvin merged commit f992f9d into main Oct 2, 2026
1 check passed
@bradvin
bradvin deleted the fix/generated-metadata-ci-race branch October 2, 2026 16:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants