◐ Off-By-One · answer catalog

go-ci-billing-block-stewardship

2 answer(s)godockergodocker

go-ci-billing-block-stewardship

📦 Source in repository (JSON)

Answer 1

Root cause (confirmed by signature, not code): On the tick-83 push, all 4 workflows (runs 30782825688/680/677/664) failed in 4–13s with zero executed steps. No runner ever picked up a job — that is a GitHub Actions billing block (CI-BILLING-002), not a code failure. Local gates (build/vet/gofmt/guard full-mode) are green because the code is sound; only the paid runners are unavailable. The correct behavior is read-only stewardship, never worker spawning.

The fix is the tick handler at ~/muster/ (steward.go, probe.go, store.go, cmd/steward/main.go). Each tick:

  1. Re-probes CI runs + remote commits + issues (read-only; nothing is mutated remotely).
  2. Detects the block signature — all runs finished in ≤30s with zero steps:
// probe.go
func BillingBlockSignature(p Probe) bool {
    if p.Err != nil || len(p.Runs) == 0 { return false }
    for _, r := range p.Runs {
        if r.Steps > 0 || r.Duration > MaxBlockedRunDuration { return false } // progress made
        switch r.Conclusion {
        case "success", "skipped", "": return false // ambiguous, not a block
        }
    }
    return true
}
  1. Decides without ever spawning while blocked (blocked or unknown → no worker):
// steward.go — decision switch
case p.Err != nil:                          // unknown world: stay conservative
    rep.Action, rep.Note = ActionProbeError, "probe failed"
case BillingBlockSignature(p):              // CI-BILLING-002 persists
    rep.Blocked, rep.Reason = true, ReasonBillingBlock
    rep.Action = ActionNoopSteward           // never spawn while human-blocked
case len(p.Runs) > 0:                       // a run executed steps ⇒ block cleared
    rep.Action, rep.Spawned = ActionSpawnWorker, true
default:                                    // no runs yet: unknown, no spawn
    rep.Action = ActionNoopSteward
}
  1. Keeps the board audit event + DuckBrain status current on every tick — one JSONL audit row per tick and an atomically-renamed duckbrain.json (ticks_seen, blocked_ticks, last_run_ids, note).
  2. TODO scan flagged secure_storage_test.go:54 (real Secret Service impl labeled "stub") — cosmetic; ScanStaleComments records it to the backlog, leaves it in place, and it never influences the block decision.

Run it:

go run ./cmd/steward -tick 84 -audit board-audit.jsonl -duck duckbrain.json
# → tick 84 → noop-steward | blocked=true reason="ci-billing-block" spawned=false

Evidence & signatures

This environment had **no checkout, no git repo, and no `gh` credentials**, so remote probing was simulated with the verified tick-83 signature (runs `30782825688/680/677/664`, durations 4/9/11/13s, 0 steps) and the fix was built as a self-contained, testable Go module.

- **9 test functions / 16 total assertions pass** (`go test -v`), race detector clean, `go vet` clean, `gofmt` clean — mirroring the "local gates green, code is sound" premise.
- **Edge cases tested:** block persists across ticks (tick 83 → 84 stays blocked, no spawn, `blocked_ticks=2`); block clears (a run executing steps ⇒ `spawn-worker`, DuckBrain → `clear`); probe error (prior block state preserved, status → `unknown`, no spawn); no runs yet (conservative `noop-steward`); **never-spawn-while-blocked property** across 12 consecutive blocked ticks (0 spawns, 12 audit events); FileStore persistence + restart round-trip; nil-store guard; stale-comment scan (`secure_storage_test.go:4` hit, non-blocking).
- **End-to-end CLI run:** tick 83 and 84 both reported `noop-steward | blocked=true | spawned=false`; the board audit log grew one JSONL event per tick; `duckbrain.json` showed `ticks_seen:2, blocked_ticks:2` with the 4 run IDs.
{"model": "deepseek-v4-flash", "problem_class": "go-ci-billing-block-stewardship", "result": "passed", "tests": 16}

Answer 2

Root cause (confirmed by signature, not code): On the tick-83 push, all 4 workflows (runs 30782825688/680/677/664) failed in 4–13s with zero executed steps. No runner ever picked up a job — that is a GitHub Actions billing block (CI-BILLING-002), not a code failure. Local gates (build/vet/gofmt/guard full-mode) are green because the code is sound; only the paid runners are unavailable. The correct behavior is read-only stewardship, never worker spawning.

The fix is the tick handler at ~/muster/ (steward.go, probe.go, store.go, cmd/steward/main.go). Each tick:

  1. Re-probes CI runs + remote commits + issues (read-only; nothing is mutated remotely).
  2. Detects the block signature — all runs finished in ≤30s with zero steps:
// probe.go
func BillingBlockSignature(p Probe) bool {
    if p.Err != nil || len(p.Runs) == 0 { return false }
    for _, r := range p.Runs {
        if r.Steps > 0 || r.Duration > MaxBlockedRunDuration { return false } // progress made
        switch r.Conclusion {
        case "success", "skipped", "": return false // ambiguous, not a block
        }
    }
    return true
}
  1. Decides without ever spawning while blocked (blocked or unknown → no worker):
// steward.go — decision switch
case p.Err != nil:                          // unknown world: stay conservative
    rep.Action, rep.Note = ActionProbeError, "probe failed"
case BillingBlockSignature(p):              // CI-BILLING-002 persists
    rep.Blocked, rep.Reason = true, ReasonBillingBlock
    rep.Action = ActionNoopSteward           // never spawn while human-blocked
case len(p.Runs) > 0:                       // a run executed steps ⇒ block cleared
    rep.Action, rep.Spawned = ActionSpawnWorker, true
default:                                    // no runs yet: unknown, no spawn
    rep.Action = ActionNoopSteward
}
  1. Keeps the board audit event + DuckBrain status current on every tick — one JSONL audit row per tick and an atomically-renamed duckbrain.json (ticks_seen, blocked_ticks, last_run_ids, note).
  2. TODO scan flagged secure_storage_test.go:54 (real Secret Service impl labeled "stub") — cosmetic; ScanStaleComments records it to the backlog, leaves it in place, and it never influences the block decision.

Run it:

go run ./cmd/steward -tick 84 -audit board-audit.jsonl -duck duckbrain.json
# → tick 84 → noop-steward | blocked=true reason="ci-billing-block" spawned=false

Evidence & signatures

This environment had **no checkout, no git repo, and no `gh` credentials**, so remote probing was simulated with the verified tick-83 signature (runs `30782825688/680/677/664`, durations 4/9/11/13s, 0 steps) and the fix was built as a self-contained, testable Go module.

- **9 test functions / 16 total assertions pass** (`go test -v`), race detector clean, `go vet` clean, `gofmt` clean — mirroring the "local gates green, code is sound" premise.
- **Edge cases tested:** block persists across ticks (tick 83 → 84 stays blocked, no spawn, `blocked_ticks=2`); block clears (a run executing steps ⇒ `spawn-worker`, DuckBrain → `clear`); probe error (prior block state preserved, status → `unknown`, no spawn); no runs yet (conservative `noop-steward`); **never-spawn-while-blocked property** across 12 consecutive blocked ticks (0 spawns, 12 audit events); FileStore persistence + restart round-trip; nil-store guard; stale-comment scan (`secure_storage_test.go:4` hit, non-blocking).
- **End-to-end CLI run:** tick 83 and 84 both reported `noop-steward | blocked=true | spawned=false`; the board audit log grew one JSONL event per tick; `duckbrain.json` showed `ticks_seen:2, blocked_ticks:2` with the 4 run IDs.
{"model": "deepseek-v4-flash", "problem_class": "go-ci-billing-block-stewardship", "result": "passed", "tests": 16}
Generated from the verified corpus · MIT licensedBack to the catalog