workflow_yaml_check accepts `jobs: []` though it claims to require a jobs mapping
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 55/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Domain
- ci-cd, devtools, testing-qa
Research direction
The bug is in tools/workflow_yaml_check.sh line 227, which only checks for the existence of a 'jobs' key, not that it's a mapping. Start by reading the script, especially the validation logic around line 227. Write a test workflow file with 'jobs: []' and run the script to see it incorrectly pass. Then modify the script to ensure 'jobs' is a mapping (non-empty dictionary). Run the existing tests in tests/run_all_tests.sh to verify the fix doesn't break other checks.
Written by the indexing model from the issue text.
Description
PR #1284 at df74ef1bf1de6bc1e8620adbdef748a3060f392c was reviewed against git diff origin/main...HEAD.
Two coverage gaps block the supplied review bar:
-
The sole roadmap caller now depends on the labels audit succeeding.
.github/workflows/issue-triage.yml:241has no stepif, so GitHub appliessuccess(). If any open issue lacks labels, the earlier labels audit exits 1 and the roadmap contract, selftest and live arms are skipped, including on a PR editing ROADMAP.md or either gate. The old suite ran these gates independently; after this PR it cannot provide that coverage. Run the roadmap step with a status condition such as${{ !cancelled() }}, or put the two audits in independent jobs. Keep their failures advisory. The ordinary PR run did succeed: https://github.com/InauguralSystems/EigenScript/actions/runs/35922007325 . This finding concerns the first-step-failure path, not an observed failure of that run. GitHub's default status condition: https://docs.github.com/en/actions/reference/workflows-and-actions/expressions#status-check-functions . -
tests/run_all_tests.sh:7081-7084checks only the selftest exit status. The deleted caller also pinned its counts. In a disposable copy, addreturn 0immediately afterselftest() {intools/workflow_yaml_check.sh; execute the actual extracted[99zd]section, including the runner's bash accounting wrapper. It printsRESULTS: TOTAL=1 PASS=1 FAIL=0although--selftestemits nothing. Likewise, addreturn 0at the start ofst_case()and the section passes overSELFTEST: 0 case(s) run, 0 passed, 0 failed, 0 skipped. Disabling only selftest loader runs produces8 case(s) run, 6 passed, 0 failed, 2 skippedon a host whereimport yamlsucceeds, and the section still passes. Restore the small caller-owned summary check: eight total, eight passed/zero skipped with PyYAML, six passed/two skipped without it. Control is green; whole-gate exit-0, exit-1, disabled live loader, and malformed workflow plants are all red.
Dangling claims to repair with the above:
- issue-triage.yml:226-233 still says the dev image carries gh, Linux gcc exports its token, and contrasts this job with the former suite caller.
- docs/CI.md:337-340 and tools/workflow_yaml_check.sh:53-54,77-81 claim selftest/contract pins that the new caller does not enforce.
- tools/gh_probe.sh:32 refers to deleted CI.md text, “What the caller can and cannot prove”.
- CHANGELOG.md:1441 says “see below” for the new change, which is above at line 1389.
Validation (one heavy command at a time; no full-suite rerun):
- make: exit 0, EigenScript 0.43.0 built. Binary: 952K
- make precheck: 19 passed, 0 failed, 0 skipped in 89s
- section_plan.sh --skip-audit: 25 emitting lines (floor 20), 25 routed skips (floor 25), 25 reviewed reasons, unaccounted=0
- child_exit_check.sh: 122 child sites (floor 122), no bypasses, 8 environment-selectable children
- docs_claims_check.sh: NUMBERS 36 (history-deferred=0), PATHS 248, FLAGS 43, MAKE TARGETS 36, NAMES 463 (families 12), DOC ENROLMENT 12
- ci_tier_check.sh: 22 jobs (16 required, 6 workers), 19 required names, 25 jobs on required paths
- yaml.safe_load of all 9 workflow files: exit 0, no output
- Both lowered floors are exact: child sites 126 -> 122 (-4); docs/CI.md paths 68 -> 65 (-3).
- The live Protection ruleset lists exactly the 19 required checks in .github/required-checks.txt and excludes issue-triage.
Out of scope (pre-existing): workflow_yaml_check.sh:227 checks only whether jobs exists, not whether it is a mapping. A file containing name: lane, on: workflow_dispatch, jobs: [] is accepted with workflow-yaml: OK (examined=1 file(s), 1 name(s), loader=pyyaml), despite the tool header claiming a jobs mapping. This is not introduced by #1284.
- Dominant language
- C
- Stars
- 3
- Forks
- 7
- Avg merge
- 3h 58m
- Merged PRs (30d)
- 105
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from InauguralSystems/EigenScript
-
area:lint-tooling bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
InauguralSystems/EigenScript#1340 ·
Maintainers usually reply within 1 day
-
area:stdlib found-by:code-review kind:silent-wrong
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
InauguralSystems/EigenScript#1338 ·
Maintainers usually reply within 1 day
-
area:lint-tooling found-by:critic kind:docs-drift
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
InauguralSystems/EigenScript#1335 ·
Maintainers usually reply within 1 day
-
area:ci found-by:critic kind:gate-defect
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
InauguralSystems/EigenScript#1311 ·
Maintainers usually reply within 1 day
-
enrolment: decide test_gc_runner_controls.py (exempt vs enrol) and whether floors need a ratchetOpenarea:gates found-by:critic kind:decision
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
InauguralSystems/EigenScript#1280 · 1 comment ·
Maintainers usually reply within 1 day
All issues in InauguralSystems/EigenScript
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
johnsonjh/emu2-cpm86#68 · 1 comment ·
Maintainers usually reply within 1 day
-
Zenmap CrashOpenZenmap
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
BasedHardware/omi#19306 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
fastfetch-cli/fastfetch#2619 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100