Repository navigation
ci(hooks): run actionlint under a deadline so a deadlock fails loudly (ADR-2199) - #2423
Merged
Merged
Conversation
lusoris
force-pushed
the
ci/actionlint-bounded
branch
3 times, most recently
from
October 8, 2026 01:46
27667d2 to
490bf7b
Compare
…2548 landed twice (#2560) * fix(test): drop the second MALLOC_PERTURB_ entry and state row that #2548 landed twice #2548 landed the merge train's squash of its first revision, which still carried its own MALLOC_PERTURB_=0 entry for test_gpu_picture_pool_uaf and a state row for the same bug; #2547 had already landed both. core/test/meson.build now lists the entry once (#2547's), docs/state.md keeps T-GPU-POOL-UAF-TEST-FILLS-HOST-MEMORY-2026-10-08 only, and the #2548 changelog and rebase-note fragments no longer claim that fix. Signed-off-by: Lusoris <lusoris@proton.me>
… (ADR-2199) (#2423) * ci(hooks): run actionlint under a deadline so a deadlock fails loudly (ADR-2199) actionlint v1.7.12 writes the script of a `run:` block to shellcheck's stdin pipe before it starts shellcheck, so it deadlocks when the script is larger than the pipe. A user over fs.pipe-user-pages-soft gets pipes of 8 KiB, which made the pre-push hook hang on about every other push. scripts/ci/run_actionlint.py gives the run 90 seconds, terminates the process group, names the cause and exits 124; it never reports a pass for a run that did not finish. The hook and `make lint-actions` both go through it. The defect is upstream (rhysd/actionlint#702). Decision Q-078. Restore SIGQUIT for actionlint and signal only it, so the hang dump survives a background start where non-interactive shells ignore SIGQUIT by default. Signed-off-by: Lusoris <lusoris@proton.me>
lusoris
force-pushed
the
ci/actionlint-bounded
branch
from
October 8, 2026 02:16
490bf7b to
d695b80
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The
actionlintpre-commit and pre-push hook hung with no output and no exit on about every other push of 2026-10-07 (ADR-2199, maintainer decision Q-078). A goroutine dump shows actionlint v1.7.12 writing the script of arun:block to the shellcheck child's stdin pipe before it starts the child, so a script larger than the pipe deadlocks; a user overfs.pipe-user-pages-softgets 8 KiB pipes. Upstream tracks the defect (rhysd/actionlint#702).scripts/ci/run_actionlint.pyruns actionlint under a deadline (ACTIONLINT_TIMEOUT_S, default 90 s), sends SIGQUIT to save the goroutine dump, terminates the process group, names the cause and exits 124. It never reports a pass for a run that did not finish.make lint-actionsboth go through it.Type
build/ci— tooling / infraChecklist
make format && make lintis green locally (pre-commit hooks passed on the commit;test_run_actionlint.py: 13 passed;make lint-actionsclean).docs/adr/_index_fragments/2199-actionlint-bounded-run.md.Bug-status hygiene
docs/state.mdupdated:T-HOOK-ACTIONLINT-DEADLOCK-2026-10-07closed.Netflix golden-data gate
assertAlmostEqual(...)score in the Netflix golden Python tests.Deep-dive deliverables
## Alternatives considered.AGENTS.mdinvariant note —scripts/ci/AGENTS.d/pre-commit-hygiene.md.changelog.d/changed/actionlint-bounded-run.md.Reproducer
python3 -m pytest -q scripts/ci/tests/test_run_actionlint.py # plants the hang; fails without the wrapper make lint-actions