devops(ci): run CI on the upstream branch itself so its PR can merge - #9
Merged
Merged
Conversation
The PR the playwright-cli watch opened (#8) sat BLOCKED with zero checks. The upstream workflows ran CI as a reusable ci.yml call, and a called workflow attaches its check runs to the caller's commit -- main -- under "test / <os> / node <n>". The PR is opened with the workflow token, which starts no pull_request CI, so its head commit never got the "<os> / node <n>" checks the main ruleset requires. A safe roll could never be merged automatically either: the merge step only commented. ci.yml now takes workflow_dispatch instead of workflow_call, and both upstream workflows dispatch it on the branch they pushed through .github/actions/ci-on-branch, then wait for the run. workflow_dispatch is the one event the workflow token may start, and its check runs land on the branch head under the plain job names. The result feeds the PR body, the tests-failed label and the safe merge as before; a failed CI still fails the run, so the scheduled-run notification fires. The wait polls `gh run view` rather than `gh run watch`, which also reads check annotations and would need a checks permission the workflows do not grant.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The PR the playwright-cli watch opened after #7 (b1zya/patchright-cli#8) is BLOCKED with zero checks.
Cause
The upstream workflows ran CI as a reusable
ci.ymlcall. A called workflow attaches its check runs to the caller's commit, which ismain, undertest / <os> / node <n>. Confirmed on the earlier watch run: the check runs sit on544960b(main), and the tracking commit has none. The PR itself is opened with the workflow token, which starts nopull_requestCI. So the PR head never gets the<os> / node <n>checks themainruleset requires. That also means asafepatchright-core roll could never merge automatically: the merge step would only leave its "could not merge" comment.Fix
ci.yml:workflow_dispatchreplacesworkflow_call(nothing else called it), and therefinput and checkout override go with it..github/actions/ci-on-branch: dispatchesci.ymlon the pushed branch, finds the run by its commit, and waits for it.workflow_dispatchis the one event the workflow token may start. Its check runs land on the branch head under the plain job names.upstream-roll.ymlandupstream-playwright-cli.yml: thetestjob is gone;pull-requestruns the composite, then everything works as before. The CI result (now with a link to the run) goes into the PR body, thetests-failedlabel and thesafemerge. A final step fails the run when CI did not pass, so the scheduled-run notification still fires. Both workflows getactions: writeto dispatch.gh run viewinstead ofgh run watch, which also reads check annotations and would need acheckspermission these workflows do not grant.roll.mddocuments the coupling: the ruleset's required checks have to change with the matrix inci.yml.No repository setting changes: the workflow merges a
safePR itself once its checks are green, so "Allow auto-merge" stays off.Verification
run:block passesbash -n, the YAML parses,npm run checkcleanworkflow_dispatchonfix-upstream-pr-checksata0c4dc6, found by committrack-playwright-cli_b85c7a7, CI runs on it, and chore: track microsoft/playwright-cli #8 gets its checks🤖 Generated with Claude Code