From 1501bb3eb50e94cc2b8c0735f80c232d703e61b7 Mon Sep 17 00:00:00 2001 From: askalf <263217947+askalf@users.noreply.github.com> Date: Wed, 7 Oct 2026 00:11:51 -0400 Subject: [PATCH 1/2] ci: Fleet status runs only for a comment that can change a status Every PR comment started a Fleet status run, though the script reads only "## Verification at " comments; preview bots' comments started dozens a day. issue_comment now runs it only when the comment starts with that heading, or did before an edit. The test's evaluator learns startsWith and checks a verification comment, another comment, an edit away from one and a deletion. fleet-status-self-test no longer runs for a PR that touches only redline.yml or redline-fix.yml, which is every Redline pin bump. --- .github/workflows/fleet-status-self-test.yml | 3 +++ .github/workflows/fleet-status.yml | 6 +++++- scripts/fleet-status.test.mjs | 13 ++++++++++--- 3 files changed, 18 insertions(+), 4 deletions(-) diff --git a/.github/workflows/fleet-status-self-test.yml b/.github/workflows/fleet-status-self-test.yml index 1fc2cb9..b8b9d31 100644 --- a/.github/workflows/fleet-status-self-test.yml +++ b/.github/workflows/fleet-status-self-test.yml @@ -9,6 +9,9 @@ on: types: [opened, synchronize, reopened, ready_for_review] paths: - .github/workflows/** + # A Redline pin bump touches only these two, and moves no fleet-status rule. + - '!.github/workflows/redline.yml' + - '!.github/workflows/redline-fix.yml' - scripts/fleet-status.mjs - scripts/fleet-status.test.mjs diff --git a/.github/workflows/fleet-status.yml b/.github/workflows/fleet-status.yml index 13ecc49..ad317df 100644 --- a/.github/workflows/fleet-status.yml +++ b/.github/workflows/fleet-status.yml @@ -41,8 +41,12 @@ jobs: # the PR merge ref's workflow with a read-only token, so they never run this job. # A fork's workflow_run lists no pull requests; the script finds them by head repo and branch. # issue_comment fires for issues too; only PR comments matter. The script re-checks it. + # And only a verification comment changes a status, so no other comment starts a run (preview + # bots' comments started dozens a day); an edit away from one, or its deletion, still does. if: >- - (github.event_name == 'issue_comment' && github.event.issue.pull_request != null) || + (github.event_name == 'issue_comment' && github.event.issue.pull_request != null && + (startsWith(github.event.comment.body, '## Verification at') || + startsWith(github.event.changes.body.from, '## Verification at'))) || (github.event_name == 'workflow_run' && ((contains(fromJSON('["pull_request","pull_request_target"]'), github.event.workflow_run.event) && github.event.workflow_run.head_repository.full_name == github.repository && diff --git a/scripts/fleet-status.test.mjs b/scripts/fleet-status.test.mjs index a4aa748..7c44523 100644 --- a/scripts/fleet-status.test.mjs +++ b/scripts/fleet-status.test.mjs @@ -439,6 +439,7 @@ console.log('\n fleet-status.yml: which events run the job for a fork'); const fns = { contains: (h, n) => (Array.isArray(h) ? h.some((x) => eq(x, n)) : String(h ?? '').toLowerCase().includes(String(n ?? '').toLowerCase())), fromJSON: (x) => JSON.parse(x), + startsWith: (h, n) => String(h ?? '').toLowerCase().startsWith(String(n ?? '').toLowerCase()), }; const primary = () => { const k = toks[p++]; @@ -491,9 +492,15 @@ console.log('\n fleet-status.yml: which events run the job for a fork'); check('a fork\'s pull_request event does not run the job', !onPr('pull_request', FORKED)); check('a fork\'s pull_request_review event does not run the job', !onPr('pull_request_review', FORKED)); check('a same-repo pull_request and review run it', onPr('pull_request', REPO) && onPr('pull_request_review', REPO)); - check('a comment on a PR runs it, fork or not; a comment on an issue does not', - runs({ event_name: 'issue_comment', event: { issue: { pull_request: { url: 'x' } } } }) - && !runs({ event_name: 'issue_comment', event: { issue: {} } })); + const onComment = (body, extra = {}) => runs({ event_name: 'issue_comment', event: { issue: { pull_request: { url: 'x' } }, comment: { body }, ...extra } }); + check('a verification comment on a PR runs it, fork or not; one on an issue does not', + onComment('## Verification at abc1234\n\nPassed.') + && !runs({ event_name: 'issue_comment', event: { issue: {}, comment: { body: '## Verification at abc1234' } } })); + check('any other comment does not run it (a preview bot, a person)', + !onComment('Deploying with Cloudflare Workers ... preview URL') && !onComment('lgtm') && !onComment('')); + check('a comment edited away from a verification, or a deleted one, still runs it', + onComment('never mind', { changes: { body: { from: '## Verification at abc1234' } } }) + && onComment('## Verification at abc1234', { action: 'deleted' })); check('a fork\'s CI finishing runs it, though the event lists no PR', onRun('pull_request', FORKED, [])); check('a fork\'s pull_request_target run finishing runs it', onRun('pull_request_target', FORKED, [])); check('the review relay finishing on a fork runs it', onRun('pull_request_review', FORKED, [])); From db5e6cae2607fbfa80e8c2c3f1dfc68c4574822c Mon Sep 17 00:00:00 2001 From: askalf <263217947+askalf@users.noreply.github.com> Date: Wed, 7 Oct 2026 04:27:28 +0000 Subject: [PATCH 2/2] ci: Fleet status comment filter is described by the comments it admits --- .github/workflows/fleet-status.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/fleet-status.yml b/.github/workflows/fleet-status.yml index ad317df..41e1848 100644 --- a/.github/workflows/fleet-status.yml +++ b/.github/workflows/fleet-status.yml @@ -41,8 +41,8 @@ jobs: # the PR merge ref's workflow with a read-only token, so they never run this job. # A fork's workflow_run lists no pull requests; the script finds them by head repo and branch. # issue_comment fires for issues too; only PR comments matter. The script re-checks it. - # And only a verification comment changes a status, so no other comment starts a run (preview - # bots' comments started dozens a day); an edit away from one, or its deletion, still does. + # A comment starts a run only when it can change a status: a verification comment, an edit + # away from one, or its deletion. if: >- (github.event_name == 'issue_comment' && github.event.issue.pull_request != null && (startsWith(github.event.comment.body, '## Verification at') ||