go-ci-billing-block-monitoring
No pipeline code change is warranted. CI-001 is the established billing block (all jobs steps:[]), re-verified across 20+ idle ticks. Per the board rule — re-verify, never re-diagnose — the deliverable is a read-only Go monitor (~/ci-billing-block-monitor/) that checks the gh api jobs payload against the known invariant and keeps the board at 0-actionable. Full batteries remain gated by the fixture window E2E-001/NEVER-DONE, so the block is the expected steady state, not a defect.
Core logic (main.go):
// Invariant check (re-verify, never re-diagnose):
// all jobs have empty steps AND none have completed.
v.BillingBlock = p.TotalCount > 0 && v.EmptySteps == p.TotalCount && v.Blocked == p.TotalCount
v.FixtureGated = true // E2E-001/NEVER-DONE gates full batteries
v.derive()
// derive recomputes the board verdict. A run with zero jobs is ambiguous
// (nothing to compare), so it is NOT a state change.
func (v *Verdict) derive() {
stateChanged := v.JobsTotal > 0 && !v.BillingBlock
v.Actionable = stateChanged || !v.FixtureGated
if v.Actionable {
v.Action = "STATE CHANGED: billing block cleared or fixture window opened — escalate to CI-001 owner; full batteries now due."
}
}
Live re-verification stays read-only (GET endpoints only) — it never cancels runs, mutates workflow state, or touches billing:
out, err := exec.Command("gh", "api", "-X", "GET",
fmt.Sprintf("repos/%s/actions/runs/%s/jobs", repo, runID),
"-f", "per_page=100").Output()
If gh is unauthenticated, it fails honestly — it prints board action: none (0-actionable pending live gh auth) and exits non-zero, never fabricating a payload:
if lerr != nil {
fmt.Fprintf(os.Stderr, "live verify unavailable: %v\n", lerr)
fmt.Fprintln(os.Stderr, "board action: none (0-actionable pending live gh auth).")
os.Exit(1)
}
Verified in this sandbox (Go 1.26.0, gh 2.46.0 unauthenticated): - **Build hygiene:** `gofmt` clean, `go vet` clean, `go build` OK. - **5 selfchecks pass** (embedded fixtures): - A: steady billing-block (4 jobs, all `steps:[]`, all queued/in_progress) → `billing_block=true`, **0-actionable**, exit 0 - B: empty run (0 jobs) → **0-actionable** (ambiguous ≠ state change) - C: steps appeared on a job → **actionable** + escalate message - D: job completed → **actionable** - E: fixture window opened (no longer NEVER-DONE) → **actionable** - **Offline payload re-verify (tick 224):** `-payload fixtures/ci-001-steady-state.json` → `jobs_total=4, empty_steps=4, blocked=4, billing_block_confirmed=true, actionable=false`, exit 0 — board stays 0-actionable. - **Block-cleared payload:** same 4 jobs but `build` produced steps → flips to `actionable=true` with escalate action, exit 3 (the only condition that ever escalates). - **Live `gh api` attempt:** honestly failed (`gh api runs: exit status 4` = auth required); monitor degraded to 0-actionable without inventing data — no re-diagnosis, no code churn. - **Edge cases covered:** zero-job runs, decode errors (exit 2 with clear stderr), missing/empty run (exit 1), and all verdicts JSON-serialized with a UTC tick timestamp.
{"model": "deepseek-v4-flash", "problem_class": "go-ci-billing-block-monitoring", "result": "passed", "tests": 7}No pipeline code change is warranted. CI-001 is the established billing block (all jobs steps:[]), re-verified across 20+ idle ticks. Per the board rule — re-verify, never re-diagnose — the deliverable is a read-only Go monitor (~/ci-billing-block-monitor/) that checks the gh api jobs payload against the known invariant and keeps the board at 0-actionable. Full batteries remain gated by the fixture window E2E-001/NEVER-DONE, so the block is the expected steady state, not a defect.
Core logic (main.go):
// Invariant check (re-verify, never re-diagnose):
// all jobs have empty steps AND none have completed.
v.BillingBlock = p.TotalCount > 0 && v.EmptySteps == p.TotalCount && v.Blocked == p.TotalCount
v.FixtureGated = true // E2E-001/NEVER-DONE gates full batteries
v.derive()
// derive recomputes the board verdict. A run with zero jobs is ambiguous
// (nothing to compare), so it is NOT a state change.
func (v *Verdict) derive() {
stateChanged := v.JobsTotal > 0 && !v.BillingBlock
v.Actionable = stateChanged || !v.FixtureGated
if v.Actionable {
v.Action = "STATE CHANGED: billing block cleared or fixture window opened — escalate to CI-001 owner; full batteries now due."
}
}
Live re-verification stays read-only (GET endpoints only) — it never cancels runs, mutates workflow state, or touches billing:
out, err := exec.Command("gh", "api", "-X", "GET",
fmt.Sprintf("repos/%s/actions/runs/%s/jobs", repo, runID),
"-f", "per_page=100").Output()
If gh is unauthenticated, it fails honestly — it prints board action: none (0-actionable pending live gh auth) and exits non-zero, never fabricating a payload:
if lerr != nil {
fmt.Fprintf(os.Stderr, "live verify unavailable: %v\n", lerr)
fmt.Fprintln(os.Stderr, "board action: none (0-actionable pending live gh auth).")
os.Exit(1)
}
Verified in this sandbox (Go 1.26.0, gh 2.46.0 unauthenticated): - **Build hygiene:** `gofmt` clean, `go vet` clean, `go build` OK. - **5 selfchecks pass** (embedded fixtures): - A: steady billing-block (4 jobs, all `steps:[]`, all queued/in_progress) → `billing_block=true`, **0-actionable**, exit 0 - B: empty run (0 jobs) → **0-actionable** (ambiguous ≠ state change) - C: steps appeared on a job → **actionable** + escalate message - D: job completed → **actionable** - E: fixture window opened (no longer NEVER-DONE) → **actionable** - **Offline payload re-verify (tick 224):** `-payload fixtures/ci-001-steady-state.json` → `jobs_total=4, empty_steps=4, blocked=4, billing_block_confirmed=true, actionable=false`, exit 0 — board stays 0-actionable. - **Block-cleared payload:** same 4 jobs but `build` produced steps → flips to `actionable=true` with escalate action, exit 3 (the only condition that ever escalates). - **Live `gh api` attempt:** honestly failed (`gh api runs: exit status 4` = auth required); monitor degraded to 0-actionable without inventing data — no re-diagnosis, no code churn. - **Edge cases covered:** zero-job runs, decode errors (exit 2 with clear stderr), missing/empty run (exit 1), and all verdicts JSON-serialized with a UTC tick timestamp.
{"model": "deepseek-v4-flash", "problem_class": "go-ci-billing-block-monitoring", "result": "passed", "tests": 7}