Skip to content

ci: serialize hosted build gate - #477

Merged
vicondoa merged 14 commits into
mainfrom
fix/buildbuddy-rustup-bootstrap
Aug 23, 2026
Merged

vicondoa merged 14 commits into
mainfrom
fix/buildbuddy-rustup-bootstrap

Conversation

@vicondoa

@vicondoa vicondoa commented Aug 23, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Serialize the trusted main push workflow's local Layer-1 fan-out with D2B_CHECK_JOBS=1 and D2B_FLAKE_JOBS=1.
  • Resolve pull-request metadata from one live GitHub ref advertisement, check out the advertised synthetic merge SHA, and bind its exact two parents to the current base and event head.
  • Keep the main-controlled pull_request_target entry point, credential-free PR jobs, restricted BuildBuddy push lane, stable aggregate check, and existing remote target set.

Validation

  • make test-policy - pass.
  • Missing pull-ref simulation - fail-closed with exit 76.
  • Live PR ref characterization - current synthetic merge parents matched the advertised main and PR head OIDs.
  • Independent Grok 4.6 high review after each fix - final verdict: pass; earlier P1/P2 findings were fixed and re-reviewed.
  • make check on the prior workflow change reached the changed lanes; known local nested-worktree host-doctor and proof-crate workspace-discovery failures remain unrelated to this workflow-only change.

Trust and security boundaries

  • The workflow remains sourced from protected main for pull_request_target and trusted pushes.
  • Pull-request execution is credential-free and local-only; BuildBuddy credentials remain restricted to the trusted main push remote lane.
  • The resolve step uses a public, fixed-repository git ls-remote snapshot and fails closed on missing or malformed refs.
  • The metadata gate checks immutable trusted, base, head, merge, and tested OIDs, exact synthetic-merge parent order, base ancestry, checkout identity, redaction, and warning failures.
  • The change does not alter remote target sets, cache namespaces, checkout credential persistence, or v3 source.

Post-Deploy Monitoring & Validation

  • Log queries/search terms: workflow run logs for Resolve live pull request merge ref, live pull request refs are unavailable, pull request head changed during workflow dispatch, and live pull request merge ref does not bind.
  • Metrics/dashboards: GitHub Actions required-check conclusion and duration for build / metadata, build / check, and the existing PR checks on pull requests targeting main and v3.
  • Healthy signals: metadata resolves all three refs, checks out the advertised merge SHA, validates two parents, and the stable aggregate check completes without credential exposure.
  • Failure signals and mitigation: any ref-resolution or parent-binding error should fail closed; rerun after GitHub regenerates the synthetic merge ref or push a new PR head if the PR changed. Revert the squash commit if trusted main push seeding or required checks regress.
  • Validation window and owner: first 24 hours after merge; repository maintainers review the required-check runs for PRs targeting main and v3.

Bootstrap note

  • The legacy build / metadata and build / check runs on this PR fail because pull_request_target sources build.yaml@main and the old main workflow trusts the stale event merge SHA. They are not required by main protection and cannot consume this PR's corrected workflow until the guarded squash merge lands. The required contexts eval-shell-tests, eval, and check are green.

Operational residuals

  • The bounds reduce nested hosted-runner concurrency; they do not change the separate generated PR matrix or cap parallelism inside a single Rust or Nix process.
  • PR ci: add trusted BuildBuddy Layer-1 PR gate #473 remains open and is not part of this change.

vicondoa and others added 14 commits August 22, 2026 12:50
Prepare the pinned toolchain and required components before make check fans out its local Layer-1 jobs. This avoids concurrent rustup downloads corrupting the shared runner installation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Scope the workflow contract to the local job and require the workspace checkout and pinned toolchain install in the step preceding make check.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Validate optional reusable workflow identifiers when GitHub provides them, while retaining the caller workflow SHA fallback for same-repository calls.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Require the protected workflow ref and both event-path call sites in the policy contract.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep optional metadata checks inside their helper and bind both event-path calls to the event switch.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Resolve the current main base conflict while retaining the serialized hosted Layer-1 policy and changelog entry.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Request a fresh pull_request_target event after GitHub regenerated the tested merge ref.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@vicondoa
vicondoa merged commit f9b1b20 into main Aug 23, 2026
49 of 51 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant