ci: temporary runner capability probe (NOT for merge) #36

Closed
mumuni-bot wants to merge 3 commits from ci/runner-probe into main
Owner

Temporary diagnostic: runner image node:20-bullseye lacks python3 (kills run 461 at step 2). This PR only exists to get a log from the new probe.yml. DO NOT MERGE — delete after one run.

Temporary diagnostic: runner image node:20-bullseye lacks python3 (kills run 461 at step 2). This PR only exists to get a log from the new probe.yml. **DO NOT MERGE — delete after one run.**
mumuni-bot added 6 commits 2026-09-25 19:05:27 +00:00
Replaced manual 'git clone' with password in URL with actions/checkout@v4.
Runner already auto-checkouts the repo - manual clone was redundant.
Also fixed YAML syntax issues in Config validation and No secrets check steps.
Credentials were exposed in git history since initial commit.

(cherry picked from commit aeb79c6286)
The truncation notice '[...truncated at Zulip limit]' was appended AFTER
slicing at MAX_ZULIP_MESSAGE (10000), causing the final message to exceed
Zulip's API limit. This fix subtracts the notice length from the slice so
the total stays within bounds.

(cherry picked from commit 19c52a9425)
Completes aeb79c6 (main): four more clone steps in deploy.yml still
embedded abiba-bot HTTP Basic credentials in plaintext. Runner already
auto-checkouts the repo, so the manual clone was redundant — replaced
with actions/checkout@v4, same pattern as ci.yml.

No secrets remain in tracked workflow files after this change.
Dynamic resolution (ADR-006) overrides this on connect, but when the
/api/v1/users call fails the adapter fell back to 1, silently dropping
every @all-bots mention. The realm's all-bots user is 20 (verified
2026-09-25: 'Resolved @all-bots user_id=20 from all-bots@chat.sysloggh.net';
CONTRACT_VERIFICATION_2026-06-29 fixed the Pi config to 20 for the same
reason). Align the Hermes-side fallback with the verified realm value.
ci.yml has been invalid YAML since introduction: the 'Config validation'
and old inline checks dedented out of their run:| block scalar, so Gitea
could never parse the workflow — CI never ran on any PR despite
CI_STATUS.md claiming 'Active'. The old 'No secrets check' also always
passed (|| echo swallows the grep hit) and never scanned *.yml — where
six embedded credentials were living.

- validation logic moved to ci_check.py (testable locally: python3 ci_check.py all)
- secrets check now FAILS on embedded http-basic URLs and long api_keys,
  across .py/.ts/.yaml/.yml/.cjs/.sh, with placeholder allowlist
- added workflow-YAML parse gate so this class of breakage can't recur
- py_compile steps no longer swallow errors with '|| echo skipped'
- removed ci.yml's duplicate deploy job: deploy.yml is the sole deploy
  pipeline (rc tags → Tanko canary only; stable → all agents). The ci.yml
  copy would have deployed Mumuni on rc tags too, breaking canary policy,
  and never ran anyway.
- CI_STATUS.md rewritten with the real state + caveats (history still
  contains the old creds — rotation is a server-side task)
ci: temporary runner-capability probe (node:20-bullseye image lacks python3)
CI / validate (pull_request) Failing after 11s
Runner Probe / probe (pull_request) Successful in 1s
509e461a60
mumuni-bot added 1 commit 2026-09-25 19:09:28 +00:00
mumuni-bot added 1 commit 2026-09-25 19:10:22 +00:00
ci: probe uses runner-injected GITHUB_* env instead of expression context
Runner Probe / probe (pull_request) Successful in 4s
CI / validate (pull_request) Failing after 7s
a47aea3328
mumuni-bot closed this pull request 2026-09-25 19:42:27 +00:00
Author
Owner

Closed — served its purpose. The probe proved the act container is alpine (apt-get absent, exit 127) and that checkout@v4 works. Real fix landed on PR #35 commit 52c41ca (apk-based python3 provisioning); validate run 468 is green.

Closed — served its purpose. The probe proved the act container is alpine (apt-get absent, exit 127) and that checkout@v4 works. Real fix landed on PR #35 commit 52c41ca (apk-based python3 provisioning); validate run 468 is green.

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.