Repository navigation
ci: a fork repository runs on GitHub's runners - #122
Merged
Merged
Conversation
In a fork of this repository a push, schedule or dispatch carries no pull_request, so the own-code expression chose cordon-exec, which a fork does not have, and the job would wait for a runner forever. The expression now also sends any run outside askalf/cordon to GitHub's runners, and the jobs that never run PR code use cordon-exec only here. The runner comments state the constraint without the runners' deployment details. scripts/fleet-status.test.mjs checks every event in a fork repository.
CodeQL sizes itself to the machine, and the exec runners of every repo share one host, so concurrent analyses from several repos exhausted its memory (six at once on 2026-10-06 drove host load past 150). The analyze job goes back to ubuntu-latest, without the ram and threads inputs it needed on the shared host.
sprayberry-redline
previously approved these changes
Oct 6, 2026
sprayberry-redline
left a comment
Collaborator
There was a problem hiding this comment.
Verdict: approve. The runner expressions send fork-repository runs to GitHub-hosted runners while preserving the existing PR isolation and home-repository routing. The tests exercise the new repository branch, and CodeQL consistently uses hosted runners with default resource sizing.
Docker reads a Dockerfile-specific ignore file, Dockerfile.dockerignore, in preference to .dockerignore. A PR that added one could drop the image's entry point while the input check said nothing changed, so the image smoke was skipped and the required docker-build passed.
sprayberry-redline
approved these changes
Oct 6, 2026
sprayberry-redline
left a comment
Collaborator
There was a problem hiding this comment.
Verdict: approve. The runner expressions send fork-repository runs to hosted runners while preserving this repository's runner split, with tests covering both cases. CodeQL now uses hosted resources, and the image-input filter correctly includes Dockerfile.dockerignore.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A fix to the runner split that moved this repo's own-code CI to
cordon-exec. In a fork repository of askalf/cordon, a push, schedule or dispatch carries nopull_request, so the expression pickedcordon-exec. A fork has no such runner, so the job would wait forever. (Redline caught this on the same change in askalf/dario.)The own-code expression now also sends any run outside
askalf/cordontoubuntu-latest:(github.repository != 'askalf/cordon' || github.event.pull_request && (<fork or Dependabot PR>)) && 'ubuntu-latest' || fromJSON('["self-hosted","cordon-exec"]')The jobs that never run PR code and used the literal label (
fleet-status.yml,fleet-status-backfill.yml) now use${{ github.repository == 'askalf/cordon' && fromJSON('["self-hosted","cordon-exec"]') || 'ubuntu-latest' }}.The runner comments state the constraint: a fork's PR and a Dependabot PR run code nobody here wrote, and a fork repository has no
cordon-execrunners. They no longer mention where the runners are deployed.CodeQL goes back to GitHub's runners. The
analyzejob runs onubuntu-latestagain, without theram/threadsinputs. CodeQL sizes itself to the machine, and the exec runners of every repo share one host, so concurrent analyses from several repos exhausted its memory: six at once on 2026-10-06 drove host load past 150.Apart from CodeQL, nothing changes for runs in this repository: same-repo PRs, pushes, schedules and dispatches still run on
cordon-exec.Tests
node scripts/fleet-status.test.mjs: 176 pass, 0 fail, locally. The runner checks now cover every event in a fork repository (someone/cordon→ GitHub's runners) besides fork PRs, fork reviews and Dependabot PRs; the repository-only expression is checked to run here for every event and in a fork on GitHub's runners, and only on jobs that never run PR code.cordon-exec-e1.