forked from heavy-duty/ceremony
A called workflow cannot read the caller's dispatch inputs on this forge: github.event.inputs is empty inside workflow_call even though the top-level caller receives the value in both contexts (probe runs 6/7). The sweep's gate read exactly that, so every dispatch-woken sweep bootstrapped — runs 459 and 523, ~20 label upserts per board event — while the trigger honestly logged bootstrap=no. The bridge, per the #6361 contract: labels-sweep.yml declares workflow_call.inputs.bootstrap (string, default "no"); the dogfood caller and the published CONSUMERS.md stub pass it via with.bootstrap with empty mapped to "no" at the caller — kimi's edge: on schedule the top-level context is empty, and an empty that slipped through would have turned every cron into a bootstrap. The gate feeds the declared input to labels-reconcile unchanged, so an invalid value meets the action's own yes|no refusal. test/labels-bootstrap.test.sh pins every hop: the declared boundary, both gates as the identity, no expression reading github.event.inputs (scoped to ${{ }} bodies — the file's prose names the context to explain it), the two pass-throughs byte-exact, and the four value paths driven through the shipped expressions into the action's real validator. Mutations: dropping the declaration reds 4, dropping the pass-through reds 3, restoring the old gate reds 2. Refs #215 |
||
|---|---|---|
| .. | ||
| 192.md | ||
| 195.md | ||
| 198.md | ||
| 199.md | ||
| 200.md | ||
| 201.md | ||
| 202.md | ||
| 205.md | ||
| 209.md | ||
| 210.md | ||
| 215.md | ||
| README.md | ||
| shape | ||
changelog.d/ — the next release's section, one fragment per issue
Machine-assembled by bin/changelog-assemble (#112): every PR that changes
behavior writes one file here — <issue>.md, the exact prose that will be
published, nothing else — and the release PR folds them all into the next
## X.Y.Z — DATE section of CHANGELOG.md, consuming them. Distinct
filenames never conflict, which is this directory's whole reason to exist.
This README is the marker that keeps the directory tracked when it holds no
fragments (#112 D1) — changelog-armed refuses a tree without it; do not
delete it. The shape sentinel beside it declares the set's shape —
grouped here, so every fragment carries ### headings (#182).