Files
JMR-devandClaude Opus 4.8 2fcee291ce ci: trigger CI with the PAT so dispatches don't need manual approval (#351)
#350 made ci-trigger.yml dispatch ci.yml with the built-in GITHUB_TOKEN, on the
claim that a workflow_dispatch is anti-recursion-exempt so no PAT is needed. In
practice a GITHUB_TOKEN-triggered run is held in `action_required` awaiting manual
approval and never runs un-attended, so auto-updated PRs' CI never ran (stalled
#285). The original #349 design was right: dispatch with a PAT so the run executes
as the authorized owner with no approval gate.

- ci-trigger.yml: the trigger step's GH_TOKEN is now
  `${{ secrets.AUTOUPDATE_TOKEN || github.token }}` (was `${{ github.token }}`).
  AUTOUPDATE_TOKEN (the PAT) is REQUIRED for the scheduler; the `|| github.token`
  fallback stays fail-open but only starts CI if repo settings don't gate
  GITHUB_TOKEN-triggered runs.
- autoupdate.yml: branch update stays on GITHUB_TOKEN (must NOT retrigger CI --
  that would re-introduce the cascade). Clarified that AUTOUPDATE_TOKEN is still
  required by the repo (by ci-trigger.yml) so the secret isn't deleted.
- Corrected the now-wrong "no PAT needed / workflow_dispatch anti-recursion-exempt"
  comments in ci-trigger.yml and the traffic_control.py docstrings.

updates = GITHUB_TOKEN, triggering = PAT.

Validation: all three workflow YAMLs parse clean; traffic-control unit tests still
pass (59 tests) -- the change is workflow-env only, script logic unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-05 13:28:10 -05:00

54 lines
2.4 KiB
YAML

# SPDX-License-Identifier: GPL-3.0-or-later
name: Auto-update PR branches
# When main advances, rebase every open PR that has fallen behind, so the "require
# branches up to date" branch rule doesn't need manual branch updates. All open PRs are
# touched (PR_FILTER: all) — this is no longer limited to PRs with GitHub auto-merge
# enabled.
#
# IMPORTANT (issue #349): the branch update runs with the default GITHUB_TOKEN — ON PURPOSE.
# A GITHUB_TOKEN push does NOT start new workflow runs (GitHub's anti-recursion rule), so
# updating every behind PR here NO LONGER re-triggers every PR's CI. That deliberately breaks
# the old merge-cascade (every merge -> autoupdate rebases all PRs with a PAT -> all re-run ->
# ci.yml's cancel-in-progress kills each in-flight run -> PRs thrash and can't converge).
# Branches still go up to date (satisfying "require branches up to date"); they just don't
# auto-run CI on the new head SHA. Re-triggering that SHA's CI is now OWNED by the traffic-
# controller scheduler (`.github/workflows/ci-trigger.yml` -> `traffic_control.py --mode
# trigger`), which triggers the updated PRs deliberately, in priority order, a few at a time.
# So this workflow must NOT use the PAT for the update push (that would re-introduce the
# cascade). This workflow itself doesn't need AUTOUPDATE_TOKEN — but the secret is still REQUIRED
# by the repo: the ci-trigger.yml scheduler dispatches CI with it (a GITHUB_TOKEN dispatch would
# be held for manual approval and never run un-attended). Don't delete the secret. See
# ci-trigger.yml + issue #351.
on:
push:
branches: [main]
pull_request:
types: [opened, reopened, ready_for_review]
branches: [main]
permissions:
contents: write
pull-requests: write
concurrency:
group: autoupdate-${{ github.ref }}
cancel-in-progress: true
jobs:
autoupdate:
name: Auto-update open PRs
runs-on: ubuntu-latest
environment: CI_CD
steps:
- name: Update all behind PRs
uses: chinthakagodawita/autoupdate@0707656cd062a3b0cf8fa9b2cda1d1404d74437e # v1.7.0
env:
# Default GITHUB_TOKEN — NOT a PAT — so this update push does not auto-retrigger CI
# (anti-recursion). See the header: re-triggering is owned by ci-trigger.yml.
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_FILTER: "all"
PR_READY_STATE: "all"
MERGE_CONFLICT_ACTION: "ignore"