Repository navigation
Conversation
This reverts commit 373f9ec. piri's first /forge-perf run (fil-forge/piri#148, pinned to 373f9ec) failed in the check job's react step with "Resource not accessible by integration (HTTP 403)". The reaction, the progress comment and the report all go through the issues API, but GitHub checks pull-requests: write for a comment whose issue is a pull request, whichever API it arrives through. issues: write alone does not cover them, so #48's premise was wrong and every job that writes to the pull request needs pull-requests: write back. The check, wait and report jobs ask for pull-requests: write again, the operations doc says why the caller has to grant it, and the test now requires every job that writes issues to write pull requests too, in place of the guard that kept write out. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reverts #48 and restores
pull-requests: writeon the check, wait and report jobs ofpr-run.yml.Why
piri's first
/forge-perfrun, on fil-forge/piri#148 with the pin at 373f9ec, failed in the check job's react step:Run: https://github.com/fil-forge/piri/actions/runs/36694053554/job/109817684240
#48 downgraded
pull-requeststo read on the premise that the reaction, the progress comment and the report go through the issues API, whichissues: writecovers. That premise does not hold for a pull request. GitHub checks the token'spull-requestspermission for a comment whose issue is a pull request, whichever API endpoint it arrives through, soissues: writealone gets a 403 on the very first write. The reaction was only the first place it showed; the wait job's progress comment and the report job's final comment would fail the same way.Changes
pr-run.yml: the check, wait and report jobs ask forpull-requests: writeagain.docs/operations.md: the caller snippet grantspull-requests: write, and the paragraph after it says why.scripts/ci/tests/workflows_test.sh: the guard that kept write out is replaced by one that requires every job withissues: writeto also havepull-requests: write.Callers need
pull-requests: writein their ownpermissionsblock as well as a pin on this commit, since a called job only receives what its own block declares. piri's caller-side change is in progress.🤖 Generated with Claude Code