Skip to content

fix(ci): a runs-on label glued from pieces may spell macos - #840

Merged
gHashTag merged 1 commit into
mainfrom
ci/run-syntax-split-label
Oct 3, 2026
Merged

gHashTag merged 1 commit into
mainfrom
ci/run-syntax-split-label

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Follow-up to #839, from the review-6 note at #839 (comment).

The false green. Take runs-on: ${{ matrix.family }}${{ matrix.ver }} over the include legs {family: mac, ver: os-14} and {family: ubuntu, ver: -latest}. Under a bash 5 gate it was checked as plain bash, but the first leg lands on macos-14, which parses with bash 3.2. The same hole was open for mac${{ matrix.v }}, where literal text and a matrix value spell macos together.

The fix. A matrix lookup now counts as provably not macOS only when it is the WHOLE label (WHOLE_MATRIX_LOOKUP.fullmatch(runs_on.strip())). Gluing pieces together, or gluing one to literal text, is cannot-tell (rc 2).

Proof.

  • Three new DIRECT vectors: the reviewer's glued label, the literal+value label, and a whole lookup with spaces around it, which stays bash. Self-test 60/60.
  • Tree: rc 0.
  • Mutants 3/3 killed: search instead of fullmatch, no strip, and never-macOS.

Not in this PR. The other review-6 follow-ups are left for later: shell: bash -O extglob {0}, sh checked by bash in POSIX mode instead of dash, and shell: BASH in capitals.

🤖 Generated with Claude Code

Review 6 of #839: ${{ matrix.family }}${{ matrix.ver }} over {mac, os-14}
passed as bash though the leg lands on macos-14. A matrix lookup now counts
only when it is the whole label.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown

X Brain Health Check

Score: 100.0/100
Status: 🟢 HEALTHY
Threshold: 80/100

X Brain is above merge threshold

@gHashTag
gHashTag merged commit b22994d into main Oct 3, 2026
46 checks passed
@gHashTag

gHashTag commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Reviewer bee: approved and merged.

Independent review at head 7ba546a, clone at /private/tmp (local bash 3.2; bash 5 forced with crs._BASH_MAJOR = 5, the with_bash pattern).

Gate and tree

  • python3 tools/test_check_run_syntax.py: 60/60. With the parent commit's check_run_syntax.py and the new tests: 58/60. The two glued-label vectors fail there, so they are real regressions caught.
  • python3 tools/check_run_syntax.py: rc 0 under bash 3.2, and also rc 0 with bash 5 forced (main() returned 0, 119/119 read). The gate only globs top-level workflows; the macos-latest and ${{ matrix.os }} jobs are all under archive/. So the CI gate on ubuntu is not falsely refusing anything.
  • CI (gh pr checks, read once): run-syntax and every other check passed. Two checks were still pending (Integration Test, Validate VIBEE Codegen); neither touches tools/.

False-green hunt, bash 5 forced, shell_of({}, job, {}). Every case that may land on macOS came back cannot tell (rc 2 path):

  • whole ${{ matrix.os }} with macos only through include, MacOS-14 in capitals, a nested label list [[self-hosted, macOS]], or an include object {group, labels: [macos-14]}
  • the same through YAML: a "\x6dacos-14" escape, and include: *legs from an anchor (PyYAML decodes and expands both before str(matrix))
  • runs-on as a list ["${{ matrix.os }}"], or a mapping {labels: ${{ matrix.os }}}. Conservative: cannot tell even over an ubuntu-only matrix.
  • ${{ matrix['os'] }}, ${{ matrix }}, ${{ matrix.os || 'ubuntu-latest' }}, ${{ format('mac{0}', matrix.v) }}, an unclosed ${{ matrix.os (the old findall treated this as all([]) == True, so the new form closes that too), no strategy, and a fromJSON matrix or include
  • whole lookup with NBSP around or inside the braces over ubuntu-only: bash. That is correct, because no value spells macos.

Non-blocking notes, not caused by this PR

  1. Self-hosted macOS: runs-on: [self-hosted, arm64], or ${{ matrix.os }} over os: [self-hosted], is checked as plain bash. A self-hosted macOS runner gets the labels self-hosted, macOS, ARM64 by default, so such a job could land on macOS with no "macos" written anywhere. This repo uses no self-hosted labels today.
  2. os: ["macoſ-14"] (U+017F long s) is checked as bash, because Python's lower() keeps the long s. I could not verify that GitHub's label matching folds it to MACOS-14, and I think it does not. I record it only as untested.

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown

🧪 Brain Stress Test Results

Score: not measured (no stress test prints a Score: line)
Status: 🟢 PASS
Threshold: 270/300

X Stress test passed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant