feat(upstream-watch): run the watch on GitHub Actions; routine only dispatches - #249
Merged
Merged
Conversation
gh 2.45 (apt on Ubuntu 24.04) has no --slurp, so every thread read failed in the cloud routine's first run. --paginate --jq '.[]' prints one comment per line on every gh 2.x.
gh auth status called the cloud session's injected GH_TOKEN invalid while gh api user worked with it; an Actions installation token cannot read /user either. gh api rate_limit works with every token and fails without one.
The routine's first run printed "No new upstream events." although every read had failed. check now names the unchecked threads instead, and check --json reports blind when gh is unusable or no watched thread could be read.
watchPolicy.ledger.authors lists the logins whose ledger comments count: the maintainer and the workflow's github-actions[bot]. watchPolicy.ours stays our upstream logins, because it decides whose comment is our last word on a thread.
comment reads the ledger issue's comments by watchPolicy.ledger.authors only, starts the check from the newest checked-at in them (else seven days ago), drops lines already posted, and prints the comment: the lines in a text block ending with checked-at (kept at the previous start when a read failed), then one fixed sentence per line. It prints nothing on a quiet day, lists the dispatch branches in --json, and exits 3 when blind, so the scheduled workflow needs no model.
Runs node scripts/upstream-watch.mjs comment at 14:00 UTC and on demand with the workflow token, posts the script's body on the ledger issue after checking it is non-empty and well formed, reads the posted length back, and re-applies the upstream-dispatch label when a released line carries a dispatch branch. A blind run (exit 3) fails the job. On a pull request that touches the watch, a read-only preview job proves the token reads the upstream threads.
…patches UPSTREAM-WATCH.md describes the comment command, the ledger authors, the daily workflow and the dispatch routine with its label trigger and new prompt. ADR-0041 §7 Updated; the audit record gains decision 14 (4b-A..C) and current open items; MAINTAINER.md lists the new commands. The doc tests now read the dispatch routine's prompt and pin the label the workflow applies.
A token scoped to the ledger's repository still reads our tracking issues there while every upstream read fails; that run now counts as blind (exit 3) instead of passing green. comment --json on an invalid registry prints the same blind shape the workflow reads on every other failure.
…s unknown A failed read of Ruflo's release dates left the support-window floor null, and a null floor held nothing, so a Ruflo or AgentDB fix above the real floor got a dispatch branch. With the workflow dispatching without a human, an unread floor now holds every Ruflo-carried fix (waiting for the window, no branch=) and the report marks the floor unknown. A registry with no window policy still holds nothing. The bundling-chain test drops the window it could not compute.
The dispatch list came from new lines only and the routine read only the newest comment, so a post whose label step failed, or a later maintainer comment, lost the dispatch for good. comment --json now lists every released line with a branch, recorded or not, so the workflow re-signals daily; the routine reads all ledger authors' comments and skips a branch that exists or an entry main no longer marks watching or fixed-unreleased.
Thread ids, pull request numbers and branches in the sentences are code spans, so a bare #n no longer links to this repository and upstream threads get no mention. A body past 60,000 characters posts the lines that fit and keeps the previous checked-at, so the rest follow next run. A checked-at later than now is ignored instead of silencing replies until that date.
…flow The ubiquitous language names the workflow and the ledger authors; the audit's Branch 4 open items drop a stale go-ahead line and record that Branch 3 adopted ruvnet/ruflo#3167 and #3415 while #3194 waits for the window. UPSTREAM-WATCH.md says who GitHub notifies about a failed scheduled run, that public repositories' schedules pause after 60 idle days, and that a thread failing every day keeps the check window growing.
…rphan it Under FORCE_COLOR (set in Claude Code shells) console.log colours a number even into a pipe, so the wrapper's pid parsed as NaN, the assertion ran before the try block that kills the detached wrapper, and the live child kept the test runner from exiting: the unit suite hung. The wrapper now writes the pid raw, and the read sits inside the try so a failure still cleans up.
Claude Code shells set FORCE_COLOR=3. Node then colours console.log into pipes and, beside NO_COLOR, prints a warning into captured output, so about-security.test.mjs parsed a warning as JSON on both Node versions. Tests read plain text; scripts/run-tests.mjs now removes FORCE_COLOR from the suite's environment. CI never set it, so CI results do not change.
tsc --checkJs inferred the spread object's type without FORCE_COLOR, so deleting it failed the typecheck (CI quality job).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Decision 14: the upstream watch runs as a scheduled GitHub Actions workflow in this repository; the cloud routine only dispatches. The routine's first run (session
cse_01Xb8wcBL8h335pxUeQ9sbnQ) was blind — a cloud session reaches only attached repositories (HTTP 403 upstream), apt'sgh2.45 lacks--slurp,gh auth statuscalled the injected token invalid — and the script still printed "No new upstream events.".github/workflows/upstream-watch.yml: daily0 14 * * *+workflow_dispatch(postswitch). Jobwatch(issues: write) runsnode scripts/upstream-watch.mjs comment --json, posts the body on Upstream watch #243 after checking it is non-empty and well formed, reads the posted length back, and re-applies theupstream-dispatchlabel while a released line carriesbranch=. A blind run (exit 3) fails the job. Jobpreview(read-only) runs on pull requests that touch the watch — this PR's run proves the workflow token reads the upstream threads.commentsubcommand (scripts/upstream-watch/ledger.mjs): reads onlywatchPolicy.ledger.authorscomments, starts from the newestchecked-at(future values ignored), drops recorded lines, renders a deterministic comment (text block + one sentence per line, ids in code spans, ≤60,000 chars), keeps the previous start when anything failed or was cut. No model.--slurp(--paginate --jq '.[]'); auth probegh api rate_limit;checknever reports a quiet day after a failed read;blindjudged on upstream threads only.watchPolicy.ledger.authors(pacphi,github-actions[bot]), separate fromours(which decides "our last word" upstream). Schema + validator.scripts/run-tests.mjsdrops the shell'sFORCE_COLOR(Claude Code sets 3), which coloured a pid inprocess-tree.test.mjs(orphaned wrapper → suite hang) and put a Node warning intoabout-security.test.mjsoutput. CI never set it.Test plan
node scripts/run-tests.mjs unit— Node 26 5347/0, Node 22 green; tripwire: concurrent writers onlycomment --json: 36 events, 0 fetch errors, not blind, no dispatchpreviewjob (token reads upstream)workflow_dispatchrun (proves posting on locked Upstream watch #243); routine prompt + label trigger; re-enable routine🤖 Generated with Claude Code