Skip to content

ci: lockstep HEAL — baked-tools.json auto-syncs when Dockerfile pin leads (#323) - #268

Merged
SilverKnightKMA merged 1 commit into
mainfrom
ci/lockstep-heal
Oct 1, 2026
Merged

SilverKnightKMA merged 1 commit into
mainfrom
ci/lockstep-heal

Conversation

@SilverKnightKMA

Copy link
Copy Markdown
Owner

Follow-up of #322/#267. The gate was right; the heal was manual. Now the workflow heals itself.

Why

  • PR chore(deps): bump debian from d7e1218 to a99cfc5 #262 entered main with baked-tools.json stale because it was merged by hand while 'Validate baked tools' was red — the auto-merge gate would have refused.
  • Dependabot FROM bumps always create this drift; until now a human had to patch baked-tools.json on every red PR.

Behavior

Case Result
All failures are version mismatches, PR same-repo, doesn't touch baked-tools.json sync commit pushed to PR head; this run red ('HEALED'); re-run green; auto-merge proceeds
baked-tools.json edited in PR / fork PR / missing regex / missing tool stays red for a human

Safety

  • One direction only (Dockerfile leads). Never rewrites Dockerfile.
  • Heals in a separate checkout (healsrc) — the merge-ref build steps are untouched.
  • Verified locally: positive + negative dry-runs; YAML linted.

… Dockerfile pin leads (#323)

Root cause of red-after-dependabot: auto-merge gate is correct (waits for
'Validate baked tools' on Dockerfile* changes, refuses on failure), but PR #262
was merged BY HAND while red, and unhealed dependabot PRs sit red waiting for a
manual baked-tools.json edit. This makes the sync a workflow:
- gate step: continue-on-error + id, re-asserted by a final fail step
- heal step: when ALL failures are 'Dockerfile pin X != baked-tools.json Y',
  the PR is same-repo, and the PR does NOT touch baked-tools.json →
  checkout PR head separately, rewrite versions (Dockerfile leads), push a
  sync commit, fail this run intentionally (nothing merges on pre-heal SHA;
  new SHA re-runs green and auto-merge proceeds)
- never heals the reverse direction; fork PRs and hand-edits stay red
Dry-run verified: positive (docker/dockerd/paseo healed, exit 42) and
negative (missing pin regex → refuse).
Copilot AI balanced review requested due to automatic review settings October 1, 2026 23:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@SilverKnightKMA
SilverKnightKMA merged commit 4ad951a into main Oct 1, 2026
7 checks passed
@SilverKnightKMA
SilverKnightKMA deleted the ci/lockstep-heal branch October 1, 2026 23:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants