Skip to content

ci: restore cross-repository hourly maintenance workflow resolution #185

Description

@seonghobae

Protected-main hourly maintenance acceptance

EgressWeave protected main must prove that its cross-repository reusable maintenance workflows actually materialize and execute from an immutable central identity without widening secret, review, or merge authority. A green wrapper without called jobs, a skipped required action, or stale/provider-only evidence is not acceptance.

Current protected-main truth

Fresh exact state (2026-08-13):

  • protected/live main: 7faf7a3b8a47980113982914000e724ab6a6cda5;
  • source repair PR ci: restore hourly reusable workflow resolution #188 is merged;
  • latest observed scheduled Hourly PR Maintenance run: 31652432378 on exact protected-main head 7faf7a3b8a47980113982914000e724ab6a6cda5;
  • run 31652432378 completed successfully;
  • its referenced_workflows are exactly pr-review-merge-scheduler.yml@59505c1d89eb7ea816e921b6da38079c736608c2 and pr-review-fix-scheduler.yml@59505c1d89eb7ea816e921b6da38079c736608c2;
  • called job fix-review-feedback / dispatch-review-fixes completed successfully, including canonical scheduler checkout, scheduler-contract self-test, and review-feedback dispatch;
  • called job review-recheck-and-merge / scan-pr-queue completed successfully, including app-token exchange, targeted-dispatch validation, trusted source-ref resolution, trusted scheduler materialization, scheduler self-test, and PR queue inspection;
  • its Wait for approved OpenCode publication run to finish step was skipped because it was not applicable; org-queue-sweep and cancel-closed-pr-runs jobs were likewise skipped as optional/non-applicable paths and are not promoted into separate acceptance evidence;
  • the historical zero-job reusable-workflow startup defect remains operationally fixed on the current exact protected head.

This is a fresh repetition of already-accepted operational behavior, so no clean-head churn is required merely to manufacture another run.

Secret and merge-authority boundary

The protected EgressWeave caller uses only the two named callable secrets published by central candidate revision 59505c1d89eb7ea816e921b6da38079c736608c2:

  • PR_REVIEW_MERGE_TOKEN;
  • OPENCODE_APPROVE_TOKEN.

The caller preserves disabled autonomous merge authority and the literal-\n workflow-startup regression. The current protected-main run proves the named-secret reusable calls materialize and execute without restoring blanket secrets: inherit.

The referenced central revision is immutable by SHA but is still the head of open read-only central PR ContextualWisdomLab/.github#897, not protected-central main. Fresh read-only refetch confirms #897 remains open / Ready / mergeable / unmerged at exact head 59505c1d89eb7ea816e921b6da38079c736608c2. EgressWeave must not duplicate or mutate that central lane.

Remaining fail-closed prerequisites

The organization-owned Dependency Review defect remains live. EgressWeave required Security Scan evidence remains non-passing whenever the wrapper is green but the actual immutable-pinned Dependency review action is skipped.

The separate required Strix unavailable/no-report false-green boundary is tracked centrally by ContextualWisdomLab/.github#891 and locally by #197. Neither wrapper success nor another scanner substitutes for an actual exact-head semantic Strix report.

Acceptance criteria

  • Reproduce the historical protected-main zero-job reusable-workflow startup failure.
  • Replace the stale/divergent reusable-workflow identity without force-push or destructive rebase.
  • Add job-scoped immutable pin and merge-authority regression coverage.
  • Preserve disabled autonomous merge authority and the literal-\n workflow-startup regression.
  • Replace blanket secret inheritance with the smallest named caller mapping exposed by the central candidate.
  • Merge the EgressWeave source repair through normal protected integration.
  • Observe protected-main scheduled runs with actual called reusable-workflow jobs and exact referenced_workflows identities.
  • Re-prove on current exact protected main 7faf7a3... with latest observed run 31652432378 that both reusable scheduler paths materialize and their substantive queue/dispatch jobs complete successfully.
  • Central owner integrates a protected-central revision that preserves the named callable-secret contract used by EgressWeave.
  • Central owner integrates the fail-closed Dependency Review repair.
  • Central owner corrects the Strix unavailable/no-report false-green boundary.
  • Obtain fresh required Security Scan evidence where the actual immutable-pinned Dependency review action executes and succeeds rather than being skipped.
  • Obtain actual exact-head semantic Strix evidence on an accepted protected EgressWeave consumer path.

This issue remains open only for those read-only central prerequisites and resulting protected EgressWeave evidence. COMMENTED/status/check/reaction/model/author/dismissed/predecessor evidence is not qualifying approval. No self-approval, bypass, force-push, local central-workflow fork, or clean-head churn merely to retrigger external behavior.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions