Skip to content

ci: consolidate required checks - #67

Merged
bateau84 merged 8 commits into
mainfrom
ci/consolidate-required-checks
Oct 7, 2026
Merged

bateau84 merged 8 commits into
mainfrom
ci/consolidate-required-checks

Conversation

@bateau84

@bateau84 bateau84 commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Summary

Consolidates PR CI after merged #45 without changing runtime/evidence semantics.

Workflow cleanup

  • keeps .github/workflows/ci.yml and .github/workflows/publish.yml;
  • removes .github/workflows/native-observer-integration.yml;
  • removes .github/workflows/runtime-evidence-acceptance.yml;
  • keeps stable PR job names test and runtime-integration.

test

Runs on every PR and keeps fast/general checks only:

  • Python compile checks;
  • full unit-test discovery;
  • fake Copilot image + GitHub Action token/sanitization smoke test.

It no longer builds the real OpenCode or Copilot runtime images.

runtime-integration

The job exists on every PR. It decides applicability internally, so documentation-only/unrelated PRs still receive a successful runtime-integration check instead of a missing required check.

For runtime-relevant changes it:

  1. builds the stock OpenCode image once;
  2. asserts OpenCode remains 2.0.23 and checks the pinned model-variant interface;
  3. runs the provider-free native observer probe;
  4. runs the stock Code Mode capability probe;
  5. runs the full provider-free runtime-evidence acceptance suite;
  6. runs the OpenCode plugin activation preflight;
  7. runs the config-root plugin dependency-resolution preflight;
  8. builds/checks the real Copilot image only when shared/Copilot runtime inputs changed;
  9. uploads the consolidated integration reports.

This removes the prior three-way rebuild of the same stock OpenCode image on runtime PRs.

Dead code cleanup

Confirmed loaded_skills_from_export and assistant_from_export have no production/runtime/runner/documented caller on current main; their only remaining references were their own definitions and the two obsolete Session-export unit tests.

Removed:

  • loaded_skills_from_export;
  • assistant_from_export;
  • test_failed_exported_skill_call_is_not_reported_as_loaded;
  • test_session_export_preserves_tool_inputs_as_actions.

Observable timing compatibility fields were left untouched because they are output data and were not proven dead.

Required-check recommendation

After this PR is merged, the repository ruleset should require exactly:

  • test
  • runtime-integration

Keep strict/up-to-date required status checks enabled.

Publish images must not be required.

The ruleset is not changed in this PR: the available repository tools do not expose ruleset mutation, and enabling the new required check before the workflow lands on main could block other PRs that cannot yet produce it.

Follow-up in GitHub UI after merge:

Settings → Rules → Rulesets → <active main ruleset> → Require status checks to pass

Keep test, add runtime-integration, keep strict/up-to-date enabled, and do not add Publish images.

Validation

Final head: a5bb16e9bbe55efde1ab7a7f5eb9de8b07336495

CI run #341 / 37593353163: PASS

  • test: PASS
    • Python compile checks: PASS
    • unit tests: 93/93 PASS
    • fake Copilot image + direct Action smoke: PASS
    • repository-command token sanitization smoke: PASS
  • runtime-integration: PASS
    • stock OpenCode image built once: PASS
    • pinned OpenCode: opencode v2.0.23
    • native observer probe: PASS
    • Code Mode capability probe: PASS, including explicit unsupported caller-final value/error behavior
    • provider-free runtime-evidence acceptance: 11/11 scenarios PASS
      • native success
      • native error
      • Code Mode success
      • caught Code Mode error
      • concurrent reverse completion
      • delegated Session ancestry
      • timeout
      • interrupted execution
      • credential redaction
      • forged collector-shaped payload rejection
      • capture tamper regression
    • OpenCode plugin activation preflight: PASS
    • config-root dependency-resolution preflight: PASS
    • real Copilot image build/version/interface check: PASS

The internal path decision excludes documentation-only changes such as README.md / docs/**; for those PRs the runtime-integration job still starts and succeeds through its explicit not-applicable path, so a future required check will not hang.

No runtime_evidence/v1, trusted-checkout threat-model, or invoke semantic changes were made.

@bateau84
bateau84 merged commit 6f37b3d into main Oct 7, 2026
2 checks passed
@bateau84
bateau84 deleted the ci/consolidate-required-checks branch October 7, 2026 08:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant