Skip to content

fix(ci): drop stale eventrelay-ci-investigator governance checks - #1317

Closed
groupthinking wants to merge 1 commit into
mainfrom
claude/determined-maxwell-4gzjlq
Closed

fix(ci): drop stale eventrelay-ci-investigator governance checks#1317
groupthinking wants to merge 1 commit into
mainfrom
claude/determined-maxwell-4gzjlq

Conversation

@groupthinking

Copy link
Copy Markdown
Owner

Canonical issue

Closes #

Outcome

Restores a green test job on main (and therefore on every open PR branched from it). The unit-test suite was failing 1 failed, 7919 passed repo-wide because of a governance test that outlived the workflow it guarded.

Scope

  • Included:
    • tests/unit/test_gh_aw_workflow_governance.py — replaced test_ci_investigator_requires_dedicated_codex_credential (which asserted the removed eventrelay-ci-investigator.md / .lock.yml still exist) with test_obsolete_ci_investigator_workflow_removed, which codifies the deletion (mirrors the existing test_obsolete_agentic_verification_loop_removed). Inverted the stale assert "eventrelay-ci-investigator" in combined in test_gh_aw_validation_pins_runtime_version.
    • .github/workflows/gh-aw-validation.yml — removed eventrelay-ci-investigator from both gh aw compile steps and from the compiled-lock git diff step, so the gh-aw Validation workflow no longer compiles/diffs a source and lock file that no longer exist.
  • Explicitly excluded:
    • .github/workflows/AUDIT.md line 27 — a historical audit-ledger row mentioning the file; left intact as a record (non-breaking).
    • No change to canonical-pr-remediator / focused-coverage-controller, which remain the authoritative agentic workflows.

Root cause

Commit 07b8a2e ("ci: remove EventRelay CI Investigator workflow source — noise-only output; per repo cleanup") deleted both eventrelay-ci-investigator.md and .lock.yml but left two governance hooks pointing at them: a unit test that required their presence, and the gh-aw validation compile/diff steps. The unit test failure is what has been keeping the repo-wide test gate red across the open-PR backlog.

Risk

  • Risk level: low
  • Failure mode: none introduced — this deletes assertions/steps that reference non-existent files. Governance coverage is preserved by asserting the files stay absent.
  • Rollback: revert this commit; restores prior (failing) state.

Verification

Tied to head 6632f75:

  • Focused tests — pytest tests/unit/test_gh_aw_workflow_governance.py9 passed (was 1 failed / 8 passed on main).
  • gh-aw-validation.yml re-parsed as valid YAML after edits.
  • Repo-wide grep confirms no remaining functional reference to eventrelay-ci-investigator (only the AUDIT.md ledger row and the new absence-assertions remain).
  • Required CI — pending on this PR.

Production evidence

Not applicable — CI-governance/test-only change; no runtime or deploy surface affected.

Agent handoff

  • One canonical issue is linked — none exists; surfaced during triage of dependabot PR build(deps-dev): bump postcss from 8.5.21 to 8.5.23 #1310, whose test failure was this exact stale test.
  • No competing PR implements the same issue
  • Acceptance criteria are satisfied (test job green)
  • Required checks pass on the current head — pending
  • Human decision is requested only for merge approval to protected main

Agent provenance

Agent-authored. Opened as draft; merge to protected main left to a human.


Generated by Claude Code

The EventRelay CI Investigator workflow (.md + .lock.yml) was intentionally
removed in 07b8a2e ("noise-only output; per repo cleanup"), but two governance
hooks still referenced it, leaving `main` — and every PR branched from it — red:

- test_ci_investigator_requires_dedicated_codex_credential asserted the removed
  workflow files exist, failing the `test` job repo-wide (1 failed, 7919 passed).
- .github/workflows/gh-aw-validation.yml still ran `gh aw compile
  eventrelay-ci-investigator` and diffed its deleted .lock.yml, so the gh-aw
  Validation workflow would fail against files that no longer exist.

Codify the removal instead: assert the investigator files stay absent (mirroring
test_obsolete_agentic_verification_loop_removed) and drop the investigator from
the gh-aw validation compile/diff steps and its pin test. canonical-pr-remediator
and focused-coverage-controller remain the authoritative agentic workflows.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011GfJq7eGJ3FgkwJHu1YUYi
@vercel

vercel Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
v0-uvai Ready Ready Preview, v0 Aug 4, 2026 1:55am

@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are limited based on label configuration.

🏷️ Required labels (at least one) (1)
  • [‘architecture-gap’, ‘bug’, ‘ci-cd’, ‘ci/cd’, ‘copilot-rabbit’, ‘documentation’, ‘duplicate’, ‘enhancement’, ‘frontend’, ‘github_actions’, ‘good first issue’, ‘help wanted’, ‘high-priority’, ‘invalid’, ‘javascript’, ‘ml-model’, ‘needs-triage’, ‘pipeline-critical’, ‘placeholder-code’, ‘priority:high’, ‘python’, ‘python:uv’, ‘question’, ‘styling’, ‘tests’, ‘v0’]

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: c8e132f0-03ce-45b9-8145-1281e946e5d8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA 6632f75.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

Scanned Files

None

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

Agent Completion Truth Gate: BLOCKED

Reasons: invalid_payload

Machine-readable verdict
{
  "details": {
    "collection_errors": [
      "incomplete_linked_issue_contract",
      "missing_linked_issue",
      "missing_closing_issue_reference",
      "missing_agent_run_id",
      "missing_agent_login"
    ],
    "invalid_fields": [
      "issue.number",
      "policy.agent_login",
      "policy.run_id"
    ]
  },
  "reasons": [
    "invalid_payload"
  ],
  "verdict": "blocked"
}

Workflow evidence

Copy link
Copy Markdown
Owner Author

CI status @ 6632f75 — fix verified; one systemic governance gate remains

Everything this diff governs is green:

  • test — full suite passes. This is the job the change fixes; main was 1 failed / 7919 passed because test_ci_investigator_requires_dedicated_codex_credential asserted the intentionally-removed eventrelay-ci-investigator.md / .lock.yml still exist (deleted in 07b8a2e).
  • validate-gh-aw — the gh aw compile and lock-diff steps run cleanly after dropping the removed eventrelay-ci-investigator from gh-aw-validation.yml.
  • ✅ build, lint-python, lint-frontend, guards, bandit, npm-audit, trivy, CodeQL, Security Scan (python/js), dependency-review, gitleaks; Vercel preview Ready.

The single red check is agent-completion/truth-gateinvalid_payload on issue.number, policy.agent_login, policy.run_id. That is the repo-wide agent-completion governance gate, which enforces on agent / claude/* branches and requires a valid agent-lock manifest (linked canonical issue + agent login + provider run id). It is not produced by this diff — the identical invalid_payload fails across ~12 open PRs, and is the gate that #1154 and #1155 are in flight to repair. I am deliberately not fabricating a run id / manifest to force it green.

This PR is a draft; merge to protected main is a human decision.


Generated by Claude Code

Copy link
Copy Markdown
Owner Author

Closing: already landed on main via #1342

This work is done. #1342 (b21d383, "fix(ci): remove orphaned ci-investigator governance test unblocking main") merged on Aug 4 and removed both the governance test and the eventrelay-ci-investigator references from .github/workflows/gh-aw-validation.yml.

Verified against current main:

$ grep -c "eventrelay-ci-investigator" .github/workflows/gh-aw-validation.yml
0
$ grep -c "test_ci_investigator_requires_dedicated_codex_credential" tests/unit/test_gh_aw_workflow_governance.py
0

$ git diff <merge-base> claude/determined-maxwell-4gzjlq | git apply --check -
error: patch does not apply

The patch no longer applies because its target lines are already gone. There is no remaining work on this branch.

Closing as superseded. #1320, which targets the same two files, is being closed for the same reason.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants