|
27 | 27 | # `enable-coverage-guard` was switched on here in the previous commit; without |
28 | 28 | # this trigger its push-side half would have been dead on arrival. |
29 | 29 | push: |
30 | | - # An ALLOW-LIST of branch prefixes is a gate with a hole in it, and the |
31 | | - # hole is SILENT: a branch matching nothing gets no CI at all, and its last |
32 | | - # visible status is whatever it inherited — indistinguishable, on every |
33 | | - # dashboard, from a branch that passed. |
| 30 | + # DEFAULT BRANCHES ONLY. `pull_request` below carries every other branch. |
34 | 31 | # |
35 | | - # Two live examples, both found 2026-08-14: `perf/**` was uncovered in |
36 | | - # openconnector, where a merge carrying unresolved conflict markers and 84 |
37 | | - # failing tests was pushed and nothing ran; and `feat/**` was uncovered in |
38 | | - # openregister — note the list said `feature/**`, so every branch anyone |
39 | | - # named `feat/...` had been running unchecked. |
| 32 | + # This was an allow-list of branch prefixes, and that was a gate with a |
| 33 | + # SILENT hole: a branch matching nothing got no CI at all, and its last |
| 34 | + # visible status was whatever it inherited — indistinguishable, on every |
| 35 | + # dashboard, from a branch that passed. Two live examples, both found |
| 36 | + # 2026-08-14: `perf/**` was uncovered in openconnector, where a merge |
| 37 | + # carrying unresolved conflict markers and 84 failing tests was pushed and |
| 38 | + # nothing ran; and `feat/**` was uncovered in openregister, because the |
| 39 | + # list said `feature/**`. |
40 | 40 | # |
41 | | - # Prefixes are added rather than replaced with `**` because this workflow is |
42 | | - # expensive (PHPUnit matrix, Newman, Playwright). The fast structural checks |
43 | | - # DO run on `**` — see merge-hygiene.yml, added in the same change. |
| 41 | + # The comment that stood here said adding prefixes was not the durable fix, |
| 42 | + # and that the durable fix was to let the pull_request trigger gate it. |
| 43 | + # THIS IS THAT CHANGE. |
44 | 44 | # |
45 | | - # ⚠️ Adding prefixes is not the durable fix; the next invented one is |
46 | | - # uncovered again. The durable fix is branch protection requiring a PR into |
47 | | - # development, which the pull_request trigger below already gates correctly. |
| 45 | + # What forced it now: a push to a branch with an open PR ran the SAME 34 |
| 46 | + # jobs TWICE on the same commit. `concurrency` cannot dedupe them — the |
| 47 | + # group is suffixed by event name deliberately (.github#540: a |
| 48 | + # default-branch push carries jobs a PR run does not, and a dispatch must |
| 49 | + # not be cancellable by a standing release PR), so the two events sit in |
| 50 | + # different lanes BY DESIGN and both run to completion. Measured fleet-wide |
| 51 | + # 2026-08-25..27, 659 of 2,106 Code Quality runs were that duplicate — 31% |
| 52 | + # of the fleet's most expensive workflow, re-deciding a commit another run |
| 53 | + # was already deciding. The account ceiling is 60 concurrent jobs (Team |
| 54 | + # plan); the fleet was measured at 53 running with 1,528 jobs queued behind |
| 55 | + # them, the oldest run 7 hours old and not yet started. |
| 56 | + # |
| 57 | + # NO BRANCH LOSES ITS FLOOR. merge-hygiene.yml runs on `'**'` — every |
| 58 | + # branch anyone pushes, no prefix list to forget — and it is the check |
| 59 | + # `development` actually requires. That is the smoke alarm; this workflow |
| 60 | + # is the fire brigade and belongs on the PR. Of 668 feature-branch push |
| 61 | + # runs in that window, only NINE were on a branch with no PR run beside |
| 62 | + # them. |
| 63 | + # |
| 64 | + # The default branches STAY: their push runs are not duplicates, they are |
| 65 | + # the only carrier of Coverage Baseline Check, SBOM and Features Extract, |
| 66 | + # none of which run on a pull_request event. |
48 | 67 | branches: |
49 | 68 | - main |
50 | 69 | - beta |
51 | 70 | - development |
52 | | - - feature/** |
53 | | - - feat/** |
54 | | - - bugfix/** |
55 | | - - hotfix/** |
56 | | - - perf/** |
57 | | - - refactor/** |
58 | | - - chore/** |
59 | | - - fix/** |
60 | 71 | pull_request: |
61 | 72 | branches: [main, beta, development] |
62 | 73 | # Same family of defect as the missing `push:` above, one step further along: |
|
0 commit comments