Skip to content

ci: one check for branch protection to require - #72

Merged
fadion merged 1 commit into
masterfrom
ci/one-required-check
Aug 27, 2026
Merged

fadion merged 1 commit into
masterfrom
ci/one-required-check

Conversation

@fadion

@fadion fadion commented Aug 27, 2026

Copy link
Copy Markdown
Owner

Requiring the seven job names deadlocked the first documentation-only PR (#71), and not for the reason #69 anticipated.

Skipping works: lint, language and fuzz all reported skipping, which is a conclusion and satisfies a required check. But a skipped matrix job reports its name unexpanded — literally test (${{ matrix.os }}) rather than the three real ones — so test (ubuntu-latest) and its siblings never arrived, and the PR sat BLOCKED on checks that cannot exist. The same deadlock #69 set out to prevent, one level down.

Requiring individual job names has a second problem worth fixing while here: every required name is coupled to a job name, so renaming a job silently stops protection enforcing it, with nothing anywhere to notice.

What changed

  • Added a ci job that always runs, gates on the other five, and fails if any failed or was cancelled. Skipped is fine — that is the filtering working. It always reports because it always runs.
  • The comparison pads both sides (case " $RESULTS " in *" failure "*) so a status containing another as a substring cannot match by accident. Checked against all-success, all-skipped, a failure, a cancellation, and a failure among skips.

After merging

Branch protection should require ci and nothing else, replacing the seven. Adding a job later then needs no ruleset change, and renaming one cannot quietly disable enforcement.

Requiring the seven job names deadlocked the first documentation-only pull
request, and not for the reason #69 anticipated.

Skipping works: lint, language and fuzz all reported "skipping" on #71,
which is a conclusion and satisfies a required check. But a skipped MATRIX
job reports its name unexpanded -- literally "test (${{ matrix.os }})"
rather than the three real ones -- so "test (ubuntu-latest)" and its two
siblings never arrived at all, and the pull request sat BLOCKED on checks
that cannot exist. Exactly the deadlock #69 set out to prevent, one level
down.

Requiring individual job names has a second problem worth fixing while
here: every required name is coupled to a job name, so renaming a job
silently stops protection enforcing it, with nothing anywhere to notice.

So: a `ci` job that always runs, gates on the other five, and fails if any
of them failed or was cancelled. Skipped is fine, since that is the
filtering working as intended. It always reports because it always runs,
whatever the jobs beneath it did.

Branch protection should require this one check and nothing else. Adding a
job later then needs no change to the ruleset, and renaming one cannot
quietly disable it.

The comparison pads both sides -- `case " $RESULTS " in *" failure "*` --
so a status that merely contains another as a substring cannot match by
accident. Checked against all-success, all-skipped, a failure, a
cancellation, and a failure among skips.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@fadion
fadion merged commit 75fe037 into master Aug 27, 2026
8 checks passed
@fadion
fadion deleted the ci/one-required-check branch August 27, 2026 22:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant