Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 0 additions & 10 deletions .github/workflows/claude-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,16 +46,6 @@ jobs:
pull-requests: write # post review + track_progress tracking comment
id-token: write # OIDC — mints the Claude GitHub App token (required
# even with an OAuth/API-key credential)
# Repo-wide review queue — a SEPARATE block from the workflow-level cancel
# group above, because `queue: max` cannot be combined with
# `cancel-in-progress: true`, the value that block sets
# (https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#jobsjob_idconcurrency)
# — and because this group is job-scoped and repo-wide, not per-PR.
# Serializes reviews repo-wide so parallel PRs queue for the shared Claude
# seat instead of contending for it.
concurrency:
group: claude-review-${{ github.repository }}
queue: max
uses: melodic-software/ci-workflows/.github/workflows/claude-review.yml@35880dcbb2f174aac90159e276dc7eddf1bc20b9 # v0.30.1
with:
# DEVIATION from the component, which names the managed fleet label:
Expand Down
10 changes: 0 additions & 10 deletions components/claude-lanes-hosted/claude-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,16 +75,6 @@ jobs:
pull-requests: write # post review + tracking comment
id-token: write # OIDC, mints the Claude GitHub App token (required
# even with an OAuth/API-key credential)
# Repo-wide review queue: a SEPARATE block from the workflow-level
# cancel group above, because `queue: max` cannot be combined with
# `cancel-in-progress: true`, the value that block sets
# (https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#jobsjob_idconcurrency),
# and because this group is job-scoped and repo-wide, not per-PR.
# Serializes reviews repo-wide so parallel PRs queue for the shared
# Claude seat instead of contending for it.
concurrency:
group: claude-review-${{ github.repository }}
queue: max
uses: melodic-software/ci-workflows/.github/workflows/claude-review.yml@35880dcbb2f174aac90159e276dc7eddf1bc20b9 # v0.30.1
with:
runner: ubuntu-24.04
Expand Down
2 changes: 1 addition & 1 deletion components/claude-lanes-hosted/claude-security-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ permissions:
# queue group: a full queue CANCELS new arrivals, which is the same wedge; a
# queue is added only if overflow smoke-testing proves otherwise. These are
# per-LANE values, deliberately different from the code-review caller's (which
# cancels superseded runs and queues repo-wide). Do not normalize the two.
# cancels superseded runs). Do not normalize the two.

jobs:
security-review:
Expand Down
15 changes: 0 additions & 15 deletions components/claude-lanes/claude-lanes.test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,6 @@ manifest='distribution/sync-manifest.yml'
config='.github/actionlint.yaml'
# The fleet callers and their hosted siblings (components/claude-lanes-hosted/).
source_prefix_re='components/claude-lanes(-hosted)?/'
queue_message='unexpected key "queue" for "concurrency" section'

if ! command -v actionlint >/dev/null 2>&1; then
skip_suite 'actionlint not installed'
Expand Down Expand Up @@ -126,18 +125,4 @@ for target in "${lane_targets[@]}"; do
assert_silent "$target sync emits no findings" "$out"
done

# Control: the suppression is load-bearing for every one of those targets, not
# a nicety. A target that owns actionlint locally must carry its own
# equivalent or its first sync PR fails its own lane. When this case stops
# failing, the upstream fix shipped — fire the removal trigger recorded in the
# canonical config instead of patching this test.
control="$scratch/no-config"
consumer_checkout "${lane_targets[0]}" "$control"
bash distribution/sync-manifest.sh apply --target "${lane_targets[0]}" --target-root "$control" >/dev/null
rm -f "$control/$config"
out="$(cd "$control" && actionlint -no-color 2>&1)"
rc=$?
assert_nonzero 'a synced lane caller fails actionlint without the suppression' "$rc"
assert_contains 'control run reports the suppressed message' "$out" "$queue_message"

[[ $FAILED -eq 0 ]] || exit 1
10 changes: 0 additions & 10 deletions components/claude-lanes/claude-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -71,16 +71,6 @@ jobs:
pull-requests: write # post review + tracking comment
id-token: write # OIDC, mints the Claude GitHub App token (required
# even with an OAuth/API-key credential)
# Repo-wide review queue: a SEPARATE block from the workflow-level
# cancel group above, because `queue: max` cannot be combined with
# `cancel-in-progress: true`, the value that block sets
# (https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#jobsjob_idconcurrency),
# and because this group is job-scoped and repo-wide, not per-PR.
# Serializes reviews repo-wide so parallel PRs queue for the shared
# Claude seat instead of contending for it.
concurrency:
group: claude-review-${{ github.repository }}
queue: max
uses: melodic-software/ci-workflows/.github/workflows/claude-review.yml@35880dcbb2f174aac90159e276dc7eddf1bc20b9 # v0.30.1
with:
runner: melodic-review-ubuntu-24.04-x64
Expand Down
2 changes: 1 addition & 1 deletion components/claude-lanes/claude-security-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ permissions:
# queue group: a full queue CANCELS new arrivals, which is the same wedge; a
# queue is added only if overflow smoke-testing proves otherwise. These are
# per-LANE values, deliberately different from the code-review caller's (which
# cancels superseded runs and queues repo-wide). Do not normalize the two.
# cancels superseded runs). Do not normalize the two.

jobs:
security-review:
Expand Down
5 changes: 1 addition & 4 deletions distribution/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -368,7 +368,7 @@ non-draft same-repository PR whose actor is not a bot, and a target's `.github/c
no longer read. The manifest never managed that file.

The two callers deliberately carry different concurrency values (per-PR
cancel plus a repo-wide queue on the code-review caller; cancel disabled and
cancel on the code-review caller; cancel disabled and
no queue on the security caller, whose check may be a required
Comment thread
kyle-sexton marked this conversation as resolved.
execution-evidence context). The component sources record the rationale
inline. Do not normalize the two.
Expand Down Expand Up @@ -406,9 +406,6 @@ and cursor-plugins.
- The sync never deletes a file. A target that moves between the hosted and
fleet variants must delete the old caller in a repo-local pull request, or
both run.
- ci-runner owns its actionlint config, which must extend its `queue` ignore to
`.github/workflows/claude-review-hosted.yml` before its sync pull request can
pass.
- Removal trigger: the one-shape work below landing, after which the hosted
pair retires.

Expand Down
5 changes: 0 additions & 5 deletions distribution/sync-manifest.yml
Original file line number Diff line number Diff line change
Expand Up @@ -385,11 +385,6 @@ targets:
- repository-text
- shellcheck
- typos
# The hosted review caller carries a job-level `concurrency.queue`, which
# the pinned actionlint rejects. ci-runner owns its actionlint config, so
# its `.github/actionlint.yaml` must extend the `queue` ignore to
# `.github/workflows/claude-review-hosted.yml` before the sync pull
# request that adds the caller can pass its own actionlint lane.
locally-owned:
- actionlint
melodic-software/ci-workflows:
Expand Down
Loading