Skip to content

ci: let results reach a protected branch, and never lose a long run - #1065

Merged
edkerk merged 2 commits into
developfrom
ci/results-push-and-salvage
Jul 16, 2026
Merged

ci: let results reach a protected branch, and never lose a long run#1065
edkerk merged 2 commits into
developfrom
ci/results-push-and-salvage

Conversation

@edkerk

@edkerk edkerk commented Jul 16, 2026

Copy link
Copy Markdown
Member

Why

Both problems showed up on #1061, the release PR, whose head is develop.

1. The results push is rejected on a protected branch. Every check on #1061 passed. Only Auto-commit results failed:

remote: error: GH006: Protected branch update failed for refs/heads/develop.

develop requires one approving review and has no bypass allowances, so GITHUB_TOKEN cannot push to it. (github-actions[bot] cannot be added to a classic protection bypass list; only installed GitHub Apps appear there.)

2. That failure then skipped everything after it. Steps default to an implicit success(), so on #1061 both Upload full MEMOTE result and Fail if a build gate failed were skipped. The gate verdict never ran, meaning a plumbing failure masks which gate actually went red. The same shape would throw away a multi-hour /run gene-essentiality or /run memote, because their publish steps also sit after the commit.

Changes

Token. actions/checkout persists the credentials the later push uses, so that is where the token belongs, not on the auto-commit step. All three workflows now use:

token: ${{ secrets.CI_PUSH_TOKEN || secrets.GITHUB_TOKEN }}

The fallback means nothing breaks before the secret exists, on forks where secrets are not exposed, or for ordinary topic-branch heads, which GITHUB_TOKEN can already push to.

Guards. The publish and verdict steps are now if: ${{ !cancelled() }} instead of the implicit success(), so they run whether or not the push succeeded, but still not when a run is cancelled:

workflow step
model-qc.yml Post final comment, Upload full MEMOTE result, Fail if a build gate failed
gene-essentiality.yml Post comment
memote-full.yml Upload full MEMOTE result, Update the Model QC comment

Required before this helps

CI_PUSH_TOKEN must exist as a repository secret, holding a PAT from an account with admin rights (enforce_admins is false on develop, so an admin's credentials can push directly). Until then the fallback keeps current behaviour, and the release PR's push keeps failing.

Note the trade-off of a PAT: it is a long-lived credential tied to a person, results commits will be attributed to that account rather than the bot, and it needs rotating. A dedicated GitHub App with contents: write added to the bypass list is the scoped alternative if this becomes permanent.

Two problems surfaced on the release pull request (#1061), whose head is develop:

The results push was rejected (GH006, protected branch update failed). Every check
had passed; only the commit failed. actions/checkout persists the credentials the
push later uses, so the token belongs there: use CI_PUSH_TOKEN when it is set and
fall back to GITHUB_TOKEN, which keeps every ordinary topic-branch head working and
leaves forks unaffected.

That failed push then skipped everything after it, because steps default to an
implicit success(). On #1061 the MEMOTE artifact and the build-gate verdict were
both skipped, so a plumbing failure hid which gate had actually run. The same shape
would silently discard a multi-hour gene-essentiality or full-MEMOTE run, since
their publish steps also sit after the commit.

Guard the publish and verdict steps with !cancelled() instead: they now run whether
or not the push succeeded, but still not on cancellation.
@github-actions

github-actions Bot commented Jul 16, 2026

Copy link
Copy Markdown

Model quality report

⚠️ 6 pre-existing finding(s), no regressions vs develop. Non-blocking.

Each check name links to its explanation in the testResults README.

Model checks

Duplicate keys (model unloadable) and no growth block the merge; every other row is a non-blocking report.

Check Result Δ vs develop
Duplicate !!omap keys 0 0
Growth (biomass producible) 125 0
Reactions with no metabolites 0 0
Model / annotation-table inconsistencies 0 0
Removed reactions or metabolites not deprecated 0 0
Metabolites missing formula 0 0
Metabolites missing charge 0 0
Reaction bound / GPR issues 0 0
Exact-duplicate reaction groups 0 0
Unused metabolites 0 0
Unused genes 0 0
Malformed cross-references 0 0
Cross-refs inconsistent across compartments 3 0 ⚠️

MACAW and mass/charge balance

Check Result Δ vs develop
Reactions flagged by MACAW dead-end test 2510 0 ⚠️
Reactions flagged as MACAW duplicates 377 0 ⚠️
Mass-imbalanced reactions 87 0 ⚠️
Charge-imbalanced reactions 234 0 ⚠️
Structure vs formula/charge inconsistencies 397 0 ⚠️

Model file and metabolic tasks

Check Result
YAML round-trip (cobrapy) pass
YAML round-trip (RAVEN) pass
YAML lint pass
Essential metabolic tasks 57 passed
Verification metabolic tasks 21 passed

MEMOTE

Total score: 63.2% (core subset)   0

Section Score Δ vs base
consistency 42.4% 0
annotation_met 73.0% 0
annotation_rxn 72.7% 0
annotation_gene 46.7% 0
annotation_sbo 81.7% 0
Per-test scores
Section Test Score
Consistency Stoichiometric Consistency 100.0%
Consistency Mass Balance 0.8%
Consistency Charge Balance 2.1%
Consistency Metabolite Connectivity 0.0%
Consistency Unbounded Flux In Default Medium 100.0%
Annotation - Metabolites Presence of Metabolite Annotation 0.0%
Annotation - Metabolites Metabolite Annotations Per Database 62.3%
Annotation - Metabolites Metabolite Annotation Conformity Per Database 45.8%
Annotation - Metabolites Uniform Metabolite Identifier Namespace 0.0%
Annotation - Reactions Presence of Reaction Annotation 0.0%
Annotation - Reactions Reaction Annotations Per Database 75.9%
Annotation - Reactions Reaction Annotation Conformity Per Database 33.3%
Annotation - Reactions Uniform Reaction Identifier Namespace 0.0%
Annotation - Genes Presence of Gene Annotation 0.0%
Annotation - Genes Gene Annotations Per Database 80.0%
Annotation - Genes Gene Annotation Conformity Per Database 80.0%
Annotation - SBO Terms Metabolite General SBO Presence 0.0%
Annotation - SBO Terms Metabolite SBO:0000247 Presence 0.1%
Annotation - SBO Terms Reaction General SBO Presence 0.0%
Annotation - SBO Terms Metabolic Reaction SBO:0000176 Presence 0.0%
Annotation - SBO Terms Transport Reaction SBO:0000185 Presence 0.7%
Annotation - SBO Terms Exchange Reaction SBO:0000627 Presence 0.0%
Annotation - SBO Terms Demand Reaction SBO:0000628 Presence 100.0%
Annotation - SBO Terms Sink Reactions SBO:0000632 Presence 100.0%
Annotation - SBO Terms Gene General SBO Presence 0.0%
Annotation - SBO Terms Gene SBO:0000243 Presence 0.0%
Annotation - SBO Terms Biomass Reactions SBO:0000629 Presence 0.0%

Full suite not run for this commit; comment /run memote to add it.

The score above is the fast core subset. Comment /run memote to run the full suite on this pull request; the score updates here when it finishes.

Gene essentiality (Hart 2015)

Not run automatically (it takes hours). Comment /run gene-essentiality to run it on this pull request; the result posts as its own comment.

❌ = a count rose vs the target branch (regression) · ⚠️ = a pre-existing non-zero finding (non-blocking) · ⏳ = still running. Counts link to the CSV listing the exact entries.

Full workflow run · this comment is edited as results come in

@edkerk
edkerk merged commit 04ef04a into develop Jul 16, 2026
@edkerk
edkerk deleted the ci/results-push-and-salvage branch July 16, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant