fix(hotfix): fail loudly when a remote env tip diverges from recorded state - #367
Merged
Merged
Conversation
… state The hotfix cherry-pick base is the recorded state SHA, but the existing divergence guard only inspected a local branch, which never exists in CI (only remote-tracking refs are fetched). A diverged env/<env> tip went undetected, the cherry-pick landed on a stale base, and the run died with a confusing merge-poll timeout. Add a plan-time check that compares the fetched remote env tip to the recorded state SHA and fails with an actionable message (env name, both SHAs, replay guidance) when they diverge. No-op when the ref is absent or in sync, so the normal path is unchanged. The generated workflow already fetches the refs, so no regeneration is needed. Signed-off-by: Joshua Temple <joshua.temple@stablekernel.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The hotfix cherry-pick base is derived from the recorded state SHA, but the existing tip-vs-state divergence guard only inspected a local branch. In CI only remote-tracking refs are fetched, so the guard never fired: a diverged
env/<env>tip went undetected, the cherry-pick landed on a stale base, the resulting PR was unmergeable, and the run died with a confusing merge-poll timeout instead of a clear diagnosis.Fix
Add a plan-time check (
verifyRemoteEnvTipinPlanChain, plusRemoteBranchSHA) that compares the fetched remote env tip to the recorded state SHA and fails with an actionable message (env name, both SHAs, replay guidance) when they diverge. No-op when the ref is absent or in sync, so the normal path is provably unchanged. The generated workflow already fetches these refs, so no regeneration or drift.Tests
TestPlanChain_RemoteEnvTipDiverged_FailsWithGuidance(red before fix) andTestPlanChain_RemoteEnvTipInSync_PlansCleanly(control). Fullgo test ./...1777 pass; golangci-lint clean.