ceremony/changelog.d/198.md
cluade-reviewer-andresmgsl 728102a3ba
All checks were successful
CI / test (pull_request) Successful in 3m3s
CI / release-exercise (pull_request) Successful in 11s
CI / self-guards (pull_request) Successful in 6s
CI / action-exercise (pull_request) Successful in 6s
CI / docs-sync-exercise (pull_request) Successful in 6s
Refs guard / refs-not-closing (pull_request) Successful in 5s
labels / labels (pull_request) Successful in 45s
fix(issueflow): issue_payload_valid refuses an empty payload on jq 1.6 too (#198)
`CI / test` was red at 97e63ac on a case that passes on this box: upstream's
own "an empty payload is refused". The cause is not the test.

`jq -e` disagrees with itself across versions on EMPTY input. jq 1.7 exits 4 —
no valid result was ever produced. jq 1.6 exits 0. Measured both ways today
against the same filter. This instance's runner image
(ghcr.io/catthehacker/ubuntu:act-22.04) carries jq 1.6.

So on this forge the guard #247 D3 added specifically to refuse an unreadable
read was ACCEPTING one: an empty body read as a valid issue payload, and the
sweep would have reconciled an issue from a payload it never received. The
test is upstream's, it is correct, and it passes on a GitHub runner — which is
why upstream never saw this.

The fix does not depend on jq's exit code for an input it never receives: the
payload is read, emptiness is decided in the shell, and jq judges only a
non-empty body.

Verified under BOTH jq versions, not just the one on this box: empty refused
and healthy accepted on 1.6 and 1.7, and the whole suite green under jq 1.6 —
28 test files, 0 failed — as well as under 1.7.

Refs #198
2026-08-05 12:22:20 +00:00

2.5 KiB

Added

  • This tree carries upstream ceremony through 8c3a4d1 (upstream 0.6.0): lib/attention.sh, lib/read.sh, actions/refs-not-closing, the guarded reads, and the ruling and window rules (#198).

  • test/no-runtime-gh.test.sh — the forge-portability guard: no runtime gh outside lib/forge-github.sh unless the file declares CEREMONY_FORGE_CLIENT=gh (#198).

  • CHANGELOG.md names the upstream commit this tree carries, so a drill record can say which 0.6.0 it exercised (#197, #198).

Fixed

  • Eight runtime gh call sites arrived with the merge outside every conflict hunk, in functions upstream added to files this tree already owned. Seven are ported onto the shim; the eighth is named with its reason (#198).

  • The open-PR gather reads Refs, not only closing keywords. Reading one side for closing links and the other for Refs is what released a live claim in crew#321, and this tree carried that shape (#198).

  • The merged record gains merged_at, so post_merge_pr_for_issue answers the PR that merged last rather than the highest-numbered one. Without the column every sort key ties and the old order returns silently (#198).

  • The open gather feeds open_pr_issues one record per physical body line. A whole decoded body as one record loses every declaration including the first, and reclaims a claim a live PR was holding (#198).

  • The post-merge nudge links the issue on the forge in play rather than a hard-coded github.com (#198).

  • actions/refs-not-closing reports and skips on a forge it cannot speak, naming the client and #199, instead of standing red on every PR. It reaches the forge zero times, so no verdict is produced either way (#198).

  • .github/workflows/labels.yml's sweep dispatch declares the client it speaks and refuses by name on a runner without it, instead of dying with command not found on every sweep. #205 ports it to REST (#198).

  • issue_payload_valid refuses an empty payload on jq 1.6 as well as 1.7. jq -e exits 4 on empty input under 1.7 and 0 under 1.6, and this instance's runner carries 1.6 — so the guard #247 D3 added to refuse an unreadable read was accepting one here (#198).

  • The post-merge nudge strips a trailing slash from the server URL, so a forge URL carrying one does not render //owner/repo (#198).

  • .github/scripts/release-path.sh names lib/forge.sh: #191 put the shim on the release doors' executable path here, so a doors-unchanged record that omitted it was measuring the wrong set (#198).