Skip to content

fix(ci): pin the Zephyr fork by revision, not by branch name (+ a gate that the pin stays reachable) - #405

Merged
avrabe merged 2 commits into
mainfrom
fix/pin-zephyr-fork-revision
Sep 18, 2026
Merged

avrabe merged 2 commits into
mainfrom
fix/pin-zephyr-fork-revision

Conversation

@avrabe

@avrabe avrabe commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

gale CI cloned pulseengine/zephyr by branch name at all 15 west init sites, so each run built against whatever gale/sem-replacement held at that moment, and no gale commit recorded which. #401's 38 → 0 kernel delta spanned exactly such a change (pulseengine/zephyr#1, merged mid-issue). Those results are honest but not reproducible from gale's history.

  • .github/zephyr-fork-pin holds the revision; every site reads it and refuses if it is empty. Pinned at 9550d256 — today's branch head, so this changes no build.
  • New kill-criteria gate zephyr-fork-pin: the pin must be 40-hex and still reachable from gale/sem-replacement (compare status identical|ahead). A rebase or force-push on the fork now fails here, once, instead of failing west init in every Zephyr job at the same time.
  • Negative control in the gate: a fabricated revision must be rejected by the same query. Verified live: identical for the pin, ahead for its parent, 404 for the fabricated sha. The control branches on gh's exit status — gh prints the 404 body to stdout, so a string compare would have failed the gate for the wrong reason.

Taking a fork change is now a reviewable pin bump, like varve's.

🤖 Generated with Claude Code

https://claude.ai/code/session_011QG86sovTbfnPNY9SfhSmo

… recorded

All 15 `west init` sites cloned pulseengine/zephyr by BRANCH name
(`--mr gale/sem-replacement`), so a run's Zephyr was whatever that branch
held at the time and no gale commit recorded it. gale#401's 38 -> 0 kernel
delta spanned exactly such a change (pulseengine/zephyr#1 merged mid-issue):
the runs are honest, but not reproducible from gale's history alone.

The revision now lives in .github/zephyr-fork-pin, read by every site, with
a refusal if the file is empty. Taking a fork change becomes a reviewable
bump, like any other pin. Pinned at 9550d256 (current branch head).

New kill-criteria gate `zephyr-fork-pin`: the pin must be 40-hex AND still
reachable from gale/sem-replacement (compare status identical|ahead), so a
rebase or force-push on the fork fails here rather than in every Zephyr job
at once. It carries its own negative control — an unreachable revision must
be rejected by the same query. Both arms verified against the live fork:
identical for the pin, ahead for its parent, 404 for a fabricated sha. The
control branches on gh's EXIT STATUS: gh prints the 404 body to stdout, so
a string compare would have failed the gate for the wrong reason.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011QG86sovTbfnPNY9SfhSmo
@codecov

codecov Bot commented Sep 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

…a SHA

The first version passed the pinned revision to west init. west runs
'git clone --branch <rev>', which takes a branch or tag, so every Zephyr job
failed at once: 'fatal: Remote branch 9550d256... not found in upstream
origin' (56 checks).

Each of the 15 sites now inits on gale/sem-replacement, then fetches and
checks out the pinned revision in the manifest repo (<workspace>/zephyr,
per the fork's west.yml 'self: path: zephyr') BEFORE west update reads it,
and asserts HEAD equals the pin — an unpinned build would otherwise look
identical in the log.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011QG86sovTbfnPNY9SfhSmo
@avrabe
avrabe merged commit eb52437 into main Sep 18, 2026
83 checks passed
@avrabe
avrabe deleted the fix/pin-zephyr-fork-revision branch September 18, 2026 03:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant