Skip to content

feat(ci): depot diagnostics collector - #107829

Open
rnegron wants to merge 3 commits into
refactor/depot-relay-check-parsingfrom
fix/depot-relay-diagnostics
Open

rnegron wants to merge 3 commits into
refactor/depot-relay-check-parsingfrom
fix/depot-relay-diagnostics

Conversation

@rnegron

@rnegron rnegron commented Sep 28, 2026

Copy link
Copy Markdown
Member

Problem

  • PR authors see Depot cancellations without the prerequisite failure.

Changes

  • Report root failures and sanitized diagnostics while preserving the selected workflow's verdict.
  • Isolate credentials from PR code in a default-branch collector.
  • Activation requires approved credential availability; live verification remains pending.

Before:

flowchart LR
    D[Depot gate] --> R[GitHub relay]
    classDef phBlue fill:#1d4aff,stroke:#1d4aff,color:#fff;
    class D,R phBlue;
Loading

After:

flowchart LR
    D[Depot checks] --> R[GitHub relay]
    R -->|Request artifact| C[Trusted collector]
    C -->|Sanitized report| R
    classDef phBlue fill:#1d4aff,stroke:#1d4aff,color:#fff;
    class D,R,C phBlue;
Loading

How did you test this code?

  • Local relay, audit, security and workflow checks cover stale attempts, injection and verdict preservation.
  • End-to-end verification and repo-wide mypy remain unchecked.

Release status

  • No feature flag controls this change

Automatic notifications

  • Publish to changelog?

Docs update

  • Updated existing relay guidance.

🤖 Agent context

  • Human-driven; Codex, GPT-6. No duplicate found; fixtures are synthetic.
  • CodeRabbit skipped at the author's request; CLI signed out.
  • Skills: depot-ci, authoring-ci-workflows, writing-tests, running-ci-preflight, hogli, writing-dataclasses, writing-code-comments, simplify, reviewing-with-coderabbit, shipping-a-pr, writing-pr-descriptions.

@rnegron rnegron self-assigned this Sep 28, 2026
@trunk-io

trunk-io Bot commented Sep 28, 2026

Copy link
Copy Markdown

Merging to master in this repository is managed by Trunk.

  • To merge this pull request, check the box to the left or comment /trunk merge below.

After your PR is submitted to the merge queue, this comment will be automatically updated with its status. If the PR fails, failure details will also be posted here

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

🤖 CI report

🚨 Trunk lane — universal lane

This PR is assigned to the universal lane. It cannot merge in parallel with other PRs, so it can take longer to merge. Ask dev-ex if you think this is wrong.

✅ Duplication (Python) — clean

New Python code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.

✅ Duplication (TypeScript) — clean

New TypeScript code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 75f02b33-c937-49df-9a48-92aded3d94f3

📥 Commits

Reviewing files that changed from the base of the PR and between f324dd0 and 1a72557.

📒 Files selected for processing (6)
  • .github/scripts/ci_backend_diagnostics.py
  • .github/scripts/ci_backend_relay.py
  • .github/scripts/test_ci_backend_diagnostics.py
  • .github/scripts/test_ci_backend_relay.py
  • .github/workflows/ci-backend-diagnostics.yml
  • .github/workflows/ci-backend.yml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 6 remain after this review.


📝 Walkthrough

Walkthrough

The relay now records selected check identifiers and creates a diagnostics request when it fails. A separate workflow validates the request and collects bounded Depot evidence. The collector checks workflow and attempt identity, sanitizes report text, and classifies retryability from failure evidence. Tests and handbook guidance cover relay behavior, workflow isolation, evidence validation, and unavailable diagnostics.

Priority: ➖ Normal

Merge Risk: 🟡 Moderate · up to 1a725

An ambiguous gate result may break CI failure reporting, and collector polling may exhaust the API budget used by the required gate. Resolve or explicitly accept these risks before merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 1a725

The collector is separated from PR code, checks that requests match the originating run, and returns bounded, sanitized diagnostics without changing the CI result. Credential availability and the complete path have not yet been verified in a live run.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A same-repository PR run can initiate a diagnostic request, but cannot directly execute code in the token-bearing collector. The newly published report is limited to a validated Depot workflow and a bounded subset of failures.

Trust Boundaries and Controls

  • observed — The PR-produced request is treated as data: the collector checks GitHub run and handoff provenance, request identity, and current gate selection before privileged reads. The receiver requires a report from the expected collector workflow and repeats selection validation.

Resilience and Maintainability Implications

  • observed — Request and report names include the run and attempt; a changed attempt or ambiguous report is not accepted. Diagnostic failure does not turn the failed relay into a success.

Hardening Proposals

  • proposed — Before enabling the credential, verify its effective Depot privileges and exercise the full request-to-report path in a live same-repository PR run, including cancellation and rerun behavior.
🚥 Pre-merge checks | ✅ 1
✅ Passed checks (1 passed)
Check name Status Explanation
Description check ✅ Passed The description covers the required Problem, Changes, testing, release status, notifications, docs, and agent context sections. It explains the user impact, includes before-and-after workflow diagrams…
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (1)
.github/scripts/ci_backend_relay.py (1)

94-94: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Build the path regex from DEPOT_ORG instead of a second hardcoded org literal.

Line 94 hardcodes ntsdt08fpt. Line 46 defines DEPOT_ORG, and Line 97 and Line 111 use it. If DEPOT_ORG changes and Line 94 does not, from_api clears every details_url. CheckRunReader.read then drops every check, and the relay reports ABSENT for all runs. The path instructions require that code "says everything once and only once."

♻️ Proposed fix
-        match = re.fullmatch(r"/orgs/ntsdt08fpt/workflows/([a-z0-9]+)", parsed.path)
+        match = re.fullmatch(rf"/orgs/{re.escape(DEPOT_ORG)}/workflows/([a-z0-9]+)", parsed.path)

As per path instructions: "says everything once and only once, and has no superfluous parts."

Source: Path instructions


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: afb2c53a-2bdb-48e3-85b3-ebefbc41ab7e

📥 Commits

Reviewing files that changed from the base of the PR and between 1f62cf3 and af5cf92.

📒 Files selected for processing (11)
  • .depot/workflows/ci-backend.yml
  • .github/scripts/ci_backend_audit.py
  • .github/scripts/ci_backend_diagnostics.py
  • .github/scripts/ci_backend_relay.py
  • .github/scripts/test_ci_backend_audit.py
  • .github/scripts/test_ci_backend_diagnostics.py
  • .github/scripts/test_ci_backend_relay.py
  • .github/workflows/ci-backend-diagnostics.yml
  • .github/workflows/ci-backend.yml
  • docs/published/handbook/engineering/fork-pull-requests.md
  • tools/workflow-plan/tests/workflows.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 8 remain after this review.

Comment thread .github/scripts/ci_backend_audit.py Outdated
Comment thread .github/scripts/ci_backend_diagnostics.py Outdated
@greptile-apps

greptile-apps Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Retrigger

[High risk] Adds diagnostic collection for CI backend test failures.

The PR should not merge until the request SHA check is corrected so the collector can deliver the diagnostics this change introduces.

Reviews (1) · Last reviewed commit: "fix(ci): explain depot backend failures"

Comment thread .github/scripts/ci_backend_diagnostics.py
Comment thread .github/scripts/ci_backend_diagnostics.py Outdated
Comment thread .github/scripts/ci_backend_diagnostics.py Outdated
@rnegron
rnegron force-pushed the fix/depot-relay-diagnostics branch from af5cf92 to 0bdae28 Compare September 28, 2026 16:23
@rnegron
rnegron changed the base branch from master to refactor/depot-relay-check-parsing September 28, 2026 16:23
@rnegron
rnegron added this pull request to stack #107875 September 28, 2026 16:23
@rnegron rnegron changed the title fix(ci): explain depot backend failures feat(ci): depot diagnostics collector Sep 28, 2026
@hosthog

hosthog Bot commented Sep 28, 2026

Copy link
Copy Markdown

HostHog preview — storybook-quill

Latest build (0bdae28): https://7dc95493a8a843359a8922e36eb90f9e.hosthog.dev

Employee-gated; every push gets a fresh URL whose content never changes. All previews stop serving when the PR closes.

@hosthog

hosthog Bot commented Sep 28, 2026

Copy link
Copy Markdown

HostHog preview — posthog-desktop-web

Latest build (0bdae28): https://0441e93a8a314274b1831f2e6355f378.hosthog.dev

Employee-gated; every push gets a fresh URL whose content never changes. All previews stop serving when the PR closes.

@rnegron
rnegron force-pushed the refactor/depot-relay-check-parsing branch from 468575b to cba8d6b Compare September 28, 2026 17:21
@rnegron
rnegron force-pushed the fix/depot-relay-diagnostics branch from 0bdae28 to b488447 Compare September 28, 2026 17:23
@rnegron
rnegron removed this pull request from stack #107875 September 28, 2026 19:08
@rnegron
rnegron added this pull request to stack #107951 September 28, 2026 19:13
@rnegron
rnegron force-pushed the refactor/depot-relay-check-parsing branch from cba8d6b to 7603442 Compare September 28, 2026 19:17
@rnegron
rnegron force-pushed the fix/depot-relay-diagnostics branch from b488447 to f324dd0 Compare September 28, 2026 19:18
@rnegron
rnegron marked this pull request as ready for review September 28, 2026 19:24
@pr-assigner-resolver-posthog
pr-assigner-resolver-posthog Bot requested a review from a team September 28, 2026 19:25
@rnegron
rnegron force-pushed the refactor/depot-relay-check-parsing branch from 7603442 to 64564a1 Compare September 28, 2026 19:34
@rnegron
rnegron force-pushed the fix/depot-relay-diagnostics branch from f324dd0 to 1a72557 Compare September 28, 2026 19:36
@rnegron rnegron added the stamphog Request AI approval (no full review) label Sep 28, 2026

@stamphog stamphog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not approved yet — waiting on the conditions below.

Re-add the stamphog label to request another review once you have addressed this.

This pull request was refused automatically and cannot be merged as-is.

  • deny-list gate: FAILED — the change touches CI/CD infrastructure (infra_cicd), specifically .depot/workflows/ci-backend.yml, .github/workflows/ci-backend.yml, and the new .github/workflows/ci-backend-diagnostics.yml, which fall under a category this policy never auto-clears.
  • tier gate: FAILED — classified as T2-never, since it's a cross-cutting feat spanning 9 files and 1143 lines (including new scripts, tests, and workflow definitions), which exceeds what automated review is permitted to approve.

These are hard policy stops, not a judgment on the code itself. To move forward, ask a human reviewer (ideally one with CI/CD infra ownership) to review and approve this manually, or split the change into smaller, non-infra pieces (e.g. docs updates, script logic, and workflow changes as separate PRs) so each can go through the normal automated gates.

  • 👍 on the PR from greptile-apps[bot].
Gate mechanics and policy version
Gate Result
prerequisites ✓ all clear
deny-list ✗ matches: infra_cicd
size ✓ 657L, 5F substantive, 1143L/9F incl. docs/generated/snapshots — within ceiling
tier ✗ classified as T2-never: T2-never (1143L, 9F, cross-cutting, feat)
stamphog 2.2.0 .stamphog/policy.yml @ unknown · reviewed head 1a72557

@stamphog stamphog Bot removed the stamphog Request AI approval (no full review) label Sep 28, 2026
@trunk-io

trunk-io Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Static Badge   Static Badge   Static Badge

View Full Report ↗︎ ⋅ Docs

@webjunkie webjunkie left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Agent review, actively prompted for and steered.

Commenting. The trust boundary looks sound. The cost and behavior points below need an answer first.

Open points

  • Dormant cost. Without DEPOT_CI_CANCEL_TOKEN, the collector uploads no report, but receive still polls for 300 s. Every failed Depot gate fails 5 minutes later.
  • Idle runner. workflow_run: in_progress holds a GitHub-hosted runner for each Depot-routed run until the run completes. It polls two API calls every 30 s on the repo GITHUB_TOKEN budget, also when nothing fails.
  • Retry guidance removed. The relay drops the depot ci retry commands and the ci-backend-github label. The description does not mention this.
  • Least privilege. The cancel token becomes a read credential. A read-only token fits better.
  • Doc location. The new section is general Depot guidance, not fork guidance, so fork-pull-requests.md is the wrong home.

Suggested direction

Trigger the collector on completed and post the report as a check run. That removes the in-run wait and the idle runner, and likely most of the code.

@rnegron
rnegron removed this pull request from stack #107951 September 29, 2026 13:54
An error occurred while trying to automatically change base from refactor/depot-relay-check-parsing to fix/depot-relay-root-failure September 29, 2026 14:46

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants