From b2e6ba770b9a7d1fd541288cdb73a106f230d1ee Mon Sep 17 00:00:00 2001 From: Cato <41178744+catomean@users.noreply.github.com> Date: Mon, 7 Sep 2026 17:54:14 +0200 Subject: [PATCH] ci(auto-merge): correct the reason this repo passes a PAT MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The comment added a few hours ago says GITHUB_TOKEN cannot merge a PR that touches .github/workflows. That is contradicted by this fleet's own history: github-actions[bot] merged datacat#253 and ai-kit#42 today, and both change a workflow file. I asserted it from the reusable workflow's docstring without checking, then found the counter-evidence while looking for something else. Two stalled PRs were offered as proof and neither survives either. ai-kit#11 opened 2026-08-29 and this repo's sweep was not added until 2026-09-04, so for most of that PR's life nothing was sweeping at all. aoz-housing#122 is still unexplained — I merged it before diagnosing it, which destroyed the evidence. The THROUGHPUT reason is unaffected and is why the line stays. A dispatch made with GITHUB_TOKEN triggers no workflows — the same rule the deploy reconciler exists for — so after a merge the re-armed CI run's completion fires no workflow_run and nothing wakes the sweep for the next PR. It waits for the cron, which GitHub throttles: fleetcrown's sweeps land 50-65 minutes apart against a */10 schedule. A PAT-created dispatch does emit workflow_run. The wrong claim is recorded in the file rather than quietly deleted, so the next reader does not re-derive it from the same docstring I did. No behaviour change: an undefined secret still resolves to empty and the reusable workflow still falls back to github.token. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01UvjGNAS9CMfEGNW26tUR4P --- .github/workflows/auto-merge.yml | 25 +++++++++++++++---------- 1 file changed, 15 insertions(+), 10 deletions(-) diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index 90efaa1..8ee203e 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -38,17 +38,22 @@ jobs: # SPACE-separated: the sweep word-splits this. rearm_workflows: 'ci.yml publish.yml' secrets: - # GITHUB_TOKEN cannot merge a PR that touches .github/workflows, so every - # Dependabot `github_actions` bump stalls forever: the sweep tries, the - # merge API refuses, it logs "leaving for the next sweep", and repeats — - # while still exiting 0. ai-kit #11 sat green for nine days that way, and - # aoz-housing #122 for nine more. + # Why a PAT and not the default token: THROUGHPUT. # - # A PAT also makes the queue drain at CI speed rather than at the - # schedule's. A dispatch made with GITHUB_TOKEN emits no workflow_run, so - # after each merge nothing wakes the sweep for the next PR until the cron - # fires — and GitHub throttles that to roughly hourly whatever the cron - # says. A PAT-created dispatch does emit it. + # A dispatch made with GITHUB_TOKEN triggers no workflows — the same rule + # that makes the deploy reconciler necessary. So after the sweep merges a + # PR and re-arms CI, that CI run's completion fires no workflow_run, and + # nothing wakes the sweep to take the next PR. It waits for the cron, and + # GitHub throttles scheduled workflows regardless of what the cron says: + # measured in fleetcrown, sweeps land 50-65 minutes apart against */10. + # A PAT-created dispatch does emit workflow_run, so a queue drains at CI + # speed instead. + # + # NOT the reason, though an earlier version of this comment said so: + # "GITHUB_TOKEN cannot merge a PR touching .github/workflows". That is + # contradicted here — github-actions[bot] merged datacat#253 and + # ai-kit#42, both of which change a workflow file. Recorded so the wrong + # reason does not get re-derived from this file. # # Undefined resolves to empty and the reusable workflow falls back to # github.token, so this line is inert until the org secret exists.