◐ Off-By-One · answer catalog

go-ci-billing-block-steward-tick

1 answer(s)godocker

go-ci-billing-block-steward-tick

📦 Source in repository (JSON)

Answer

Root cause. CI-BILLING-002 is not a code defect: all 4 workflows (build/vet/guard + e2e) complete in 4–13s with zero steps executed, which is the GitHub billing signature — the org's Actions minutes/spend cap blocks job start at the queue, so runs fail before any step runs. A code failure would produce step traces and variable runtimes (typically ≥30s). There is therefore no source fix; the fix is the steward-tick procedure that (a) keeps local gates + the due-window fixture green as the "code is healthy" proof, (b) re-verifies the block signature each tick, (c) records a board audit event with explicit MAX(id)+1 (never auto-increment), (d) commits only events/+tasks/ parquet (board/+fixtures/ are derived/untracked), (e) updates the Phase-2 last_commit DB, then pushes.

The one genuine bug found while building this: the classic gh run list --json … | python3 - <<'PY' pattern — the heredoc steals stdin, so the JSON never reaches the parser and the billing check silently no-ops (exactly what a broken steward tick looks like). Fix: stream to a temp file and parse with a real script.

1. Billing-check (the fix, scripts/check_billing_block.py)

import json, sys
from datetime import datetime
WINDOW_S = (4, 13)  # CI-BILLING-002: runs fail in 4-13s with zero steps

def main() -> int:
    runs = json.load(open(sys.argv[1]))          # from `gh run list --json …`
    assert len(runs) >= 4, f"expected >=4 runs, got {len(runs)}"
    sigs = []
    for r in runs[:4]:
        t0 = datetime.fromisoformat(r["createdAt"].replace("Z", "+00:00"))
        t1 = datetime.fromisoformat(r["updatedAt"].replace("Z", "+00:00"))
        d = (t1 - t0).total_seconds()
        sigs.append((r["workflowName"], r["status"], r["conclusion"], d))
        print(f"  {r['workflowName']}: {r['status']} {r['conclusion']} {d:.1f}s")
    if not all(s == "completed" and c == "failure" for _, s, c, _ in sigs):
        return 1                                  # block lifted / in progress → escalate
    if not all(WINDOW_S[0] <= d <= WINDOW_S[1] for *_, d in sigs):
        return 1                                  # real code failure → escalate
    print("=> CI-BILLING-002 confirmed: 4/4 fail in 4-13s, zero steps (billing, not code)")
    return 0

2. Board audit with explicit MAX(id)+1 (scripts/board_audit.py, core)

import duckdb
con = duckdb.connect()
if os.path.exists(AUDIT):
    next_id = int(con.execute(
        f"SELECT COALESCE(MAX(id),0)+1 FROM read_parquet('{AUDIT}')").fetchone()[0])
else:
    next_id = 1                                    # empty/missing table → id=1
con.execute("CREATE OR REPLACE TABLE audit (id BIGINT, tick BIGINT, event VARCHAR, detail VARCHAR, ts TIMESTAMP)")
if os.path.exists(AUDIT):
    con.execute(f"INSERT INTO audit SELECT * FROM read_parquet('{AUDIT}')")
con.execute("INSERT INTO audit VALUES (?,?,?,?,?::TIMESTAMP)",
            [next_id, args.tick, args.event, args.detail, args.ts])
con.execute(f"COPY (SELECT * FROM audit ORDER BY id) TO '{AUDIT}' (FORMAT PARQUET)")

Explicit MAX(id)+1 (not identity) keeps ids deterministic and gap-free even if a tick is replayed after a partial rollback; COALESCE handles the empty-table edge case.

3. Orchestrator (scripts/steward_tick.sh, 8 steps exactly per muster)

PY="${PYTHON:-python3}"; TICK="${1:-82}"; TS="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
make build && make vet && [ -z "$(gofmt -l .)" ] && make guard      # 1 gates
make test-e2e                                                        # 2 E2E-001 (~43.9s) PASS
TMP=$(mktemp)                                                        # 3 billing check
gh run list --limit 10 --json databaseId,workflowName,status,conclusion,createdAt,updatedAt > "$TMP"
"$PY" scripts/check_billing_block.py "$TMP"; rm -f "$TMP"            #    (stdin bug avoided)
echo "blocked=CI-BILLING-002 (org block, human) - no dispatch"       # 4 no worker spawn
"$PY" scripts/board_audit.py --event billing_block_verified --tick "$TICK" --ts "$TS" ...   # 5 audit
git status --porcelain | grep -E 'board/.*\.parquet|fixtures/.*\.parquet' && exit 1  # 6 guard
git add events tasks && git commit -m "tick $TICK: ... (events/tasks parquet only)"
"$PY" scripts/phase2_last_commit.py --tick "$TICK" --sha "$(git rev-parse HEAD)"   # 7 phase2
git push origin HEAD                                                  # 8

board/*.parquet + fixtures/*.parquet are gitignored (derived artifacts); step 6 re-guards so a careless git add -A can never track them.


Evidence & signatures

Verified by executing the full tick-82 sequence in a faithful reproduction (`/tmp/tick82`, go1.26, duckdb 1.5.5, gh 2.46 stub emitting the exact billing signature):

| Check | Result |
|---|---|
| Gates `make build / vet / gofmt / guard` | all green (guard rejects any `board/fixtures/*.parquet` in status) |
| E2E-001 `make test-e2e` | `PASS`; emits `events/events.parquet`, `events/tasks.parquet` |
| Billing signature | `wf901: failure 13.0s / wf900: 9.0s / wf899: 5.0s / wf898: 4.0s` → confirmed |
| Audit id (missing/empty table) | id=1 (COALESCE edge case) |
| Audit append / replay | id=2, id=3 — gap-free, append-only journal |
| Commit contents | exactly `events/events.parquet` + `events/tasks.parquet`; `git ls-files '*.parquet'` shows only those 2; `board/audit.parquet` untracked on disk |
| Phase-2 `last_commit` DB | row `(1, 82, cefe9db…)` inserted |
| Push | received by remote (`cefe9db tick 82 …`) |
| Negative path (block lifted / real failure: 60s run + a success) | rejected, exit 1 → escalation, exactly the "billing no longer blocked" tripwire |
| Fixed stdin bug | `gh run list \| python3 - <<PY` parsed nothing; temp-file+script parses 4/4 — the steward check no longer silently no-ops |

Environment honesty: the harness workspace contained only `problem.json` (no repo mounted, `gh` not authenticated, no remote workflows visible), so literal `gh run list` against the live org could not be run — consistent with the human-blocked premise; all procedural steps were verified against the reproduction above.

---
{"model": "deepseek-v4-flash", "problem_class": "go-ci-billing-block-steward-tick", "result": "passed", "tests": 12}
Generated from the verified corpus · MIT licensedBack to the catalog