Cancel replaced CI runs and drop the checkout token (closes #107) #109

Merged
clawbot merged 1 commits from issue-107-workflow-concurrency into next 2026-10-06 05:52:58 +02:00
Collaborator

The canonical .gitea/workflows/check.yml lacked two things dnswatcher added under sneak/dnswatcher#216, so a byte-identical re-vendor removed them (#107):

  • A concurrency block grouped by workflow and branch, with cancel-in-progress: true: a new push cancels the older run on the same branch, queued or running, and leaves every other branch's runs alone, next and main included.
  • persist-credentials: false on the checkout step, so the job's token is not left in .git/config for later steps. script/cibuild needs no token.

Each has a one-line comment in the file saying why. The checkout pin and its date comment are unchanged. The workflow bullet of prompts/REPO_POLICIES.md and the workflow item of both checklists now describe the file as it is. Repositories pick this up on their next re-vendor of the workflow.

Disclosures:

  • Unverified: the live checks in the definition of done (a second push cancelling the first run, no token extraheader in the checkout's .git/config) cannot run while Gitea's shared runner is out of disk space (sneak/project-management#28).
  • Judgement call: the canonical .dockerignore comment and the matching policy and checklist text still name the token the CI checkout step stores in .git/config; a repository not yet re-vendored, or any other workflow, still stores it, so that exclusion and its reason stay.
  • #106 edits the same three documents and their last_modified dates; whichever lands second needs a rebase.

Model: opus-5-5

The canonical `.gitea/workflows/check.yml` lacked two things `dnswatcher` added under https://git.eeqj.de/sneak/dnswatcher/issues/216, so a byte-identical re-vendor removed them (https://git.eeqj.de/sneak/prompts/issues/107): - A `concurrency` block grouped by workflow and branch, with `cancel-in-progress: true`: a new push cancels the older run on the same branch, queued or running, and leaves every other branch's runs alone, `next` and `main` included. - `persist-credentials: false` on the checkout step, so the job's token is not left in `.git/config` for later steps. `script/cibuild` needs no token. Each has a one-line comment in the file saying why. The checkout pin and its date comment are unchanged. The workflow bullet of `prompts/REPO_POLICIES.md` and the workflow item of both checklists now describe the file as it is. Repositories pick this up on their next re-vendor of the workflow. Disclosures: - Unverified: the live checks in the definition of done (a second push cancelling the first run, no token `extraheader` in the checkout's `.git/config`) cannot run while Gitea's shared runner is out of disk space (https://git.eeqj.de/sneak/project-management/issues/28). - Judgement call: the canonical `.dockerignore` comment and the matching policy and checklist text still name the token the CI checkout step stores in `.git/config`; a repository not yet re-vendored, or any other workflow, still stores it, so that exclusion and its reason stay. - https://git.eeqj.de/sneak/prompts/pulls/106 edits the same three documents and their `last_modified` dates; whichever lands second needs a rebase. Model: opus-5-5
clawbot added the needs-review label 2026-10-06 03:37:12 +02:00
clawbot self-assigned this 2026-10-06 03:37:12 +02:00
clawbot force-pushed issue-107-workflow-concurrency from 22e6bda2bb to 8196ccfeb0 2026-10-06 04:18:19 +02:00 Compare
Author
Collaborator

Rebased onto next after #106: both changes kept in REPO_POLICIES.md and the two checklists (their last_modified dates already matched), and this branch's TODO.md entry moved to the top of Completed Steps.

Model: opus-5-5

Rebased onto `next` after https://git.eeqj.de/sneak/prompts/pulls/106: both changes kept in `REPO_POLICIES.md` and the two checklists (their `last_modified` dates already matched), and this branch's `TODO.md` entry moved to the top of Completed Steps. Model: opus-5-5
Author
Collaborator

PASS: the canonical workflow cancels only the same branch's older run and leaves no token in .git/config, each with a true one-line comment, the checkout pin is unchanged, the policy and both checklists describe the file as it is, and the .dockerignore exclusion and its reason still stand.

Unverified: the two live checks, which wait on the shared runner (sneak/project-management#28).

Model: opus-5-5

PASS: the canonical workflow cancels only the same branch's older run and leaves no token in `.git/config`, each with a true one-line comment, the checkout pin is unchanged, the policy and both checklists describe the file as it is, and the `.dockerignore` exclusion and its reason still stand. Unverified: the two live checks, which wait on the shared runner (https://git.eeqj.de/sneak/project-management/issues/28). Model: opus-5-5
clawbot added 1 commit 2026-10-06 05:18:14 +02:00
The canonical `.gitea/workflows/check.yml` gains a `concurrency` block grouped
by workflow and branch with `cancel-in-progress: true`, so a new push cancels
the older run on the same branch and no other, and its checkout step sets
`persist-credentials: false`, so the job's token is not left in `.git/config`;
`script/cibuild` needs none. Both come from `dnswatcher`, where a byte-identical
re-vendor would have removed them. The workflow bullet of
`prompts/REPO_POLICIES.md` and both checklists now describe the file as it is.

Model: opus-5-5
clawbot force-pushed issue-107-workflow-concurrency from 8196ccfeb0 to ce695c9c97 2026-10-06 05:18:14 +02:00 Compare
Author
Collaborator

Rebased onto current next after #108; the only conflict was TODO.md Completed Steps, where every entry is kept whole and this branch's entry is back on top.

Model: opus-5-5

Rebased onto current `next` after https://git.eeqj.de/sneak/prompts/pulls/108; the only conflict was `TODO.md` Completed Steps, where every entry is kept whole and this branch's entry is back on top. Model: opus-5-5
Author
Collaborator

PASS: rebased onto current next with only the TODO.md entry moved, every Completed Steps entry whole and this one on top, and the canonical workflow, the policy and both checklists still match the definition of done in #107.

Unverified: the two live checks, which wait on the shared runner (sneak/project-management#28).

Model: opus-5-5

PASS: rebased onto current `next` with only the `TODO.md` entry moved, every Completed Steps entry whole and this one on top, and the canonical workflow, the policy and both checklists still match the definition of done in https://git.eeqj.de/sneak/prompts/issues/107. Unverified: the two live checks, which wait on the shared runner (https://git.eeqj.de/sneak/project-management/issues/28). Model: opus-5-5
clawbot merged commit 6aac45857a into next 2026-10-06 05:52:58 +02:00
clawbot deleted branch issue-107-workflow-concurrency 2026-10-06 05:52:59 +02:00
Sign in to join this conversation.