go-ci-billing-block-stewardship
Root cause (confirmed by signature, not code): On the tick-83 push, all 4 workflows (runs 30782825688/680/677/664) failed in 4–13s with zero executed steps. No runner ever picked up a job — that is a GitHub Actions billing block (CI-BILLING-002), not a code failure. Local gates (build/vet/gofmt/guard full-mode) are green because the code is sound; only the paid runners are unavailable. The correct behavior is read-only stewardship, never worker spawning.
The fix is the tick handler at ~/muster/ (steward.go, probe.go, store.go, cmd/steward/main.go). Each tick:
// probe.go
func BillingBlockSignature(p Probe) bool {
if p.Err != nil || len(p.Runs) == 0 { return false }
for _, r := range p.Runs {
if r.Steps > 0 || r.Duration > MaxBlockedRunDuration { return false } // progress made
switch r.Conclusion {
case "success", "skipped", "": return false // ambiguous, not a block
}
}
return true
}
// steward.go — decision switch
case p.Err != nil: // unknown world: stay conservative
rep.Action, rep.Note = ActionProbeError, "probe failed"
case BillingBlockSignature(p): // CI-BILLING-002 persists
rep.Blocked, rep.Reason = true, ReasonBillingBlock
rep.Action = ActionNoopSteward // never spawn while human-blocked
case len(p.Runs) > 0: // a run executed steps ⇒ block cleared
rep.Action, rep.Spawned = ActionSpawnWorker, true
default: // no runs yet: unknown, no spawn
rep.Action = ActionNoopSteward
}
duckbrain.json (ticks_seen, blocked_ticks, last_run_ids, note).secure_storage_test.go:54 (real Secret Service impl labeled "stub") — cosmetic; ScanStaleComments records it to the backlog, leaves it in place, and it never influences the block decision.Run it:
go run ./cmd/steward -tick 84 -audit board-audit.jsonl -duck duckbrain.json
# → tick 84 → noop-steward | blocked=true reason="ci-billing-block" spawned=false
This environment had **no checkout, no git repo, and no `gh` credentials**, so remote probing was simulated with the verified tick-83 signature (runs `30782825688/680/677/664`, durations 4/9/11/13s, 0 steps) and the fix was built as a self-contained, testable Go module. - **9 test functions / 16 total assertions pass** (`go test -v`), race detector clean, `go vet` clean, `gofmt` clean — mirroring the "local gates green, code is sound" premise. - **Edge cases tested:** block persists across ticks (tick 83 → 84 stays blocked, no spawn, `blocked_ticks=2`); block clears (a run executing steps ⇒ `spawn-worker`, DuckBrain → `clear`); probe error (prior block state preserved, status → `unknown`, no spawn); no runs yet (conservative `noop-steward`); **never-spawn-while-blocked property** across 12 consecutive blocked ticks (0 spawns, 12 audit events); FileStore persistence + restart round-trip; nil-store guard; stale-comment scan (`secure_storage_test.go:4` hit, non-blocking). - **End-to-end CLI run:** tick 83 and 84 both reported `noop-steward | blocked=true | spawned=false`; the board audit log grew one JSONL event per tick; `duckbrain.json` showed `ticks_seen:2, blocked_ticks:2` with the 4 run IDs.
{"model": "deepseek-v4-flash", "problem_class": "go-ci-billing-block-stewardship", "result": "passed", "tests": 16}Root cause (confirmed by signature, not code): On the tick-83 push, all 4 workflows (runs 30782825688/680/677/664) failed in 4–13s with zero executed steps. No runner ever picked up a job — that is a GitHub Actions billing block (CI-BILLING-002), not a code failure. Local gates (build/vet/gofmt/guard full-mode) are green because the code is sound; only the paid runners are unavailable. The correct behavior is read-only stewardship, never worker spawning.
The fix is the tick handler at ~/muster/ (steward.go, probe.go, store.go, cmd/steward/main.go). Each tick:
// probe.go
func BillingBlockSignature(p Probe) bool {
if p.Err != nil || len(p.Runs) == 0 { return false }
for _, r := range p.Runs {
if r.Steps > 0 || r.Duration > MaxBlockedRunDuration { return false } // progress made
switch r.Conclusion {
case "success", "skipped", "": return false // ambiguous, not a block
}
}
return true
}
// steward.go — decision switch
case p.Err != nil: // unknown world: stay conservative
rep.Action, rep.Note = ActionProbeError, "probe failed"
case BillingBlockSignature(p): // CI-BILLING-002 persists
rep.Blocked, rep.Reason = true, ReasonBillingBlock
rep.Action = ActionNoopSteward // never spawn while human-blocked
case len(p.Runs) > 0: // a run executed steps ⇒ block cleared
rep.Action, rep.Spawned = ActionSpawnWorker, true
default: // no runs yet: unknown, no spawn
rep.Action = ActionNoopSteward
}
duckbrain.json (ticks_seen, blocked_ticks, last_run_ids, note).secure_storage_test.go:54 (real Secret Service impl labeled "stub") — cosmetic; ScanStaleComments records it to the backlog, leaves it in place, and it never influences the block decision.Run it:
go run ./cmd/steward -tick 84 -audit board-audit.jsonl -duck duckbrain.json
# → tick 84 → noop-steward | blocked=true reason="ci-billing-block" spawned=false
This environment had **no checkout, no git repo, and no `gh` credentials**, so remote probing was simulated with the verified tick-83 signature (runs `30782825688/680/677/664`, durations 4/9/11/13s, 0 steps) and the fix was built as a self-contained, testable Go module. - **9 test functions / 16 total assertions pass** (`go test -v`), race detector clean, `go vet` clean, `gofmt` clean — mirroring the "local gates green, code is sound" premise. - **Edge cases tested:** block persists across ticks (tick 83 → 84 stays blocked, no spawn, `blocked_ticks=2`); block clears (a run executing steps ⇒ `spawn-worker`, DuckBrain → `clear`); probe error (prior block state preserved, status → `unknown`, no spawn); no runs yet (conservative `noop-steward`); **never-spawn-while-blocked property** across 12 consecutive blocked ticks (0 spawns, 12 audit events); FileStore persistence + restart round-trip; nil-store guard; stale-comment scan (`secure_storage_test.go:4` hit, non-blocking). - **End-to-end CLI run:** tick 83 and 84 both reported `noop-steward | blocked=true | spawned=false`; the board audit log grew one JSONL event per tick; `duckbrain.json` showed `ticks_seen:2, blocked_ticks:2` with the 4 run IDs.
{"model": "deepseek-v4-flash", "problem_class": "go-ci-billing-block-stewardship", "result": "passed", "tests": 16}