Skip to content

ci(hooks): run actionlint under a deadline so a deadlock fails loudly (ADR-2199) - #2423

Merged
lusoris merged 2 commits into
masterfrom
ci/actionlint-bounded
Oct 8, 2026
Merged

lusoris merged 2 commits into
masterfrom
ci/actionlint-bounded

Conversation

@lusoris

@lusoris lusoris commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The actionlint pre-commit and pre-push hook hung with no output and no exit on about every other push of 2026-10-07 (ADR-2199, maintainer decision Q-078). A goroutine dump shows actionlint v1.7.12 writing the script of a run: block to the shellcheck child's stdin pipe before it starts the child, so a script larger than the pipe deadlocks; a user over fs.pipe-user-pages-soft gets 8 KiB pipes. Upstream tracks the defect (rhysd/actionlint#702).

  • scripts/ci/run_actionlint.py runs actionlint under a deadline (ACTIONLINT_TIMEOUT_S, default 90 s), sends SIGQUIT to save the goroutine dump, terminates the process group, names the cause and exits 124. It never reports a pass for a run that did not finish.
  • The pre-commit hook and make lint-actions both go through it.

Type

  • build / ci — tooling / infra

Checklist

  • Commits follow Conventional Commits.
  • make format && make lint is green locally (pre-commit hooks passed on the commit; test_run_actionlint.py: 13 passed; make lint-actions clean).
  • Unit tests: no C code touched.
  • SIMD/GPU: not touched.
  • Twins: not touched.
  • New files carry the licence header (EUPL-1.2).
  • Breaking change: none.
  • The ADR row lives in docs/adr/_index_fragments/2199-actionlint-bounded-run.md.

Bug-status hygiene

  • docs/state.md updated: T-HOOK-ACTIONLINT-DEADLOCK-2026-10-07 closed.

Netflix golden-data gate

  • I did not modify any assertAlmostEqual(...) score in the Netflix golden Python tests.

Deep-dive deliverables

  • Research digest — no digest needed: the goroutine analysis is in the ADR context.
  • Decision matrix — in ADR-2199 ## Alternatives considered.
  • AGENTS.md invariant note — scripts/ci/AGENTS.d/pre-commit-hygiene.md.
  • Reproducer / smoke-test command — below.
  • CHANGELOG fragment — changelog.d/changed/actionlint-bounded-run.md.
  • Rebase note — no rebase impact: a local hook wrapper with no upstream-mirror file touched.

Reproducer

python3 -m pytest -q scripts/ci/tests/test_run_actionlint.py   # plants the hang; fails without the wrapper
make lint-actions

@github-actions github-actions Bot added the type:ci CI and infrastructure label Oct 7, 2026
@lusoris
lusoris force-pushed the ci/actionlint-bounded branch 3 times, most recently from 27667d2 to 490bf7b Compare October 8, 2026 01:46
…2548 landed twice (#2560)

* fix(test): drop the second MALLOC_PERTURB_ entry and state row that #2548 landed twice

#2548 landed the merge train's squash of its first revision, which still carried its own MALLOC_PERTURB_=0 entry for test_gpu_picture_pool_uaf and a state row for the same bug; #2547 had already landed both. core/test/meson.build now lists the entry once (#2547's), docs/state.md keeps T-GPU-POOL-UAF-TEST-FILLS-HOST-MEMORY-2026-10-08 only, and the #2548 changelog and rebase-note fragments no longer claim that fix.

Signed-off-by: Lusoris <lusoris@proton.me>
… (ADR-2199) (#2423)

* ci(hooks): run actionlint under a deadline so a deadlock fails loudly (ADR-2199)

actionlint v1.7.12 writes the script of a `run:` block to shellcheck's stdin
pipe before it starts shellcheck, so it deadlocks when the script is larger
than the pipe. A user over fs.pipe-user-pages-soft gets pipes of 8 KiB, which
made the pre-push hook hang on about every other push. scripts/ci/run_actionlint.py
gives the run 90 seconds, terminates the process group, names the cause and
exits 124; it never reports a pass for a run that did not finish. The hook and
`make lint-actions` both go through it. The defect is upstream
(rhysd/actionlint#702). Decision Q-078.

Restore SIGQUIT for actionlint and signal only it, so the hang dump survives
a background start where non-interactive shells ignore SIGQUIT by default.

Signed-off-by: Lusoris <lusoris@proton.me>
@lusoris
lusoris force-pushed the ci/actionlint-bounded branch from 490bf7b to d695b80 Compare October 8, 2026 02:16
@lusoris
lusoris merged commit d695b80 into master Oct 8, 2026
9 of 30 checks passed
@lusoris
lusoris deleted the ci/actionlint-bounded branch October 8, 2026 02:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:ci CI and infrastructure

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant