Skip to content

A branch with no PR can still be checked on demand - #23

Merged
JulienMartel merged 1 commit into
mainfrom
worktree-cut-gate-protection
Sep 12, 2026
Merged

JulienMartel merged 1 commit into
mainfrom
worktree-cut-gate-protection

Conversation

@JulienMartel

Copy link
Copy Markdown
Contributor

What

One line on .github/workflows/test.yml's trigger block: workflow_dispatch:.

Why

The CI pass narrowed push to branches: [main] so a commit on a PR branch
stops being checked twice, once as push and once as pull_request. That is
right, and it took something with it: a branch pushed without a PR now gets
no run at all.

workflow_dispatch is the replacement. haus's check.yml has had it all
along, and workshop's docs/ci.md rule 2 prescribes it as part of the
canonical trigger block (that rule's own yaml was missing it too — fixed in the
workshop PR this one pairs with).

Verify

git show HEAD:.github/workflows/test.yml | ruby -ryaml -e 'p YAML.safe_load($stdin.read)[true]'
# => {"push"=>{"branches"=>["main"]}, "pull_request"=>nil, "workflow_dispatch"=>nil}

Then: Actions → Tests → Run workflow offers a branch picker, and a PR here
still produces exactly one run per commit.

Watch out

factory shift reads gh run list -b main, so it is unaffected either way —
nothing here reads a run on a non-main branch. The factory opens a PR for
everything in this repo, so the dispatch button is an escape hatch, not a path
anyone walks daily.

🤖 Generated with Claude Code

https://claude.ai/code/session_019v1reBfZd8d4euMNyXry6B

Narrowing `push` to `main` stopped the double run for every commit on a PR
branch, and took away the only way a branch with no PR yet ever got checked.
`workflow_dispatch` hands that back — haus's check.yml has had it all along,
and it is the trigger block workshop's docs/ci.md rule 2 prescribes.

The factory opens a PR for everything here, so this is rarely the path that
gets used; it is the escape hatch for a branch pushed without one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019v1reBfZd8d4euMNyXry6B
JulienMartel added a commit to hausfold/workshop that referenced this pull request Sep 12, 2026
…e wrote down

Two leftovers from the CI pass.

Narrowing `push` to `main` took away the only way a branch with no PR yet ever
got checked. haus's check.yml already hands that back with `workflow_dispatch`;
workshop's test.yml did not, and neither did the canonical trigger block in
docs/ci.md's rule 2. Both now match haus. factory's test.yml had the same gap
and takes the same one line in hausfold/factory#23.

The path-filter question is now measured and closed. Against a real ignore list
over each repo's last 40 merged PRs, the share that would skip is haus 1,
trill 6, scruff 10, perch 11, nebelung 12 — two or three minutes saved on a
quarter of PRs at best. Not enough to buy a second silent copy of "which files
does this job protect?", which rots; and scruff's release path reaches its gate
through `workflow_call`, so a filter that skips a job on a docs path skips it
for a tag too. It goes under "What we deliberately don't do" with the numbers
and with the method, because the loose version of that measurement (which says
80%) is how the idea keeps coming back.

The same section's "no hosted binary cache" now says what it does not rule out:
a public read-only substituter for something nixpkgs doesn't carry needs no
account and no token, and fails soft to building from source.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019v1reBfZd8d4euMNyXry6B
JulienMartel added a commit to hausfold/workshop that referenced this pull request Sep 12, 2026
…e wrote down (#581)

* A branch with no PR can still be checked, and path filters are a no we wrote down

Two leftovers from the CI pass.

Narrowing `push` to `main` took away the only way a branch with no PR yet ever
got checked. haus's check.yml already hands that back with `workflow_dispatch`;
workshop's test.yml did not, and neither did the canonical trigger block in
docs/ci.md's rule 2. Both now match haus. factory's test.yml had the same gap
and takes the same one line in hausfold/factory#23.

The path-filter question is now measured and closed. Against a real ignore list
over each repo's last 40 merged PRs, the share that would skip is haus 1,
trill 6, scruff 10, perch 11, nebelung 12 — two or three minutes saved on a
quarter of PRs at best. Not enough to buy a second silent copy of "which files
does this job protect?", which rots; and scruff's release path reaches its gate
through `workflow_call`, so a filter that skips a job on a docs path skips it
for a tag too. It goes under "What we deliberately don't do" with the numbers
and with the method, because the loose version of that measurement (which says
80%) is how the idea keeps coming back.

The same section's "no hosted binary cache" now says what it does not rule out:
a public read-only substituter for something nixpkgs doesn't carry needs no
account and no token, and fails soft to building from source.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019v1reBfZd8d4euMNyXry6B

* The path-filter no is about the denylist, and it says which list it measured

Assurance pass on the first commit found three things worth the rewrite.

The scruff argument was wrong for the mechanism the heading named. A
`paths-ignore:` under `on:` cannot skip anything at a tag — a `workflow_call`
invocation does not evaluate the called workflow's own triggers, so
release.yml still runs the full gate. The risk is real only for an in-job
changed-files filter, which IS evaluated on that run, so the stanza now names
that implementation and says where a filter would have to go if one were ever
worth it.

The section also contradicted the hausfold.co paragraph above it, which calls a
`paths:` filter the first thing to reach for. Allowlist and denylist were never
distinguished: a `paths:` says what one task workflow is about, a
`paths-ignore:` on the gate says what the repo merges unchecked. Only the
second is the no, and the heading now says so.

The numbers were unreproducible because the ignore list they were measured
against was nowhere in the doc. It is in the doc now, and the closing paragraph
points at it instead of at an "actual list you would ship" the reader would
have to invent.

Two smaller ones: the substituter carve-out was answering "a cache we run" when
the paragraph above rules out one we rent and push to, and fail-soft is the
property that makes the difference, so it says that; and rule 2's block now
says it is the floor rather than the whole `on:`, since scruff's gate also
needs `workflow_call`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019v1reBfZd8d4euMNyXry6B

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@JulienMartel
JulienMartel merged commit 1cc8b9b into main Sep 12, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant