Skip to content

ci(main): the default branch is 263 commits behind and runs a retired security-tests job — every Python PR to main is red #13812

Description

@mrveiss

Summary

main is 263 commits behind Dev_new_gui, and its .github/workflows/ci.yml still runs a
security-tests job that no longer exists on the active branch. That job fails on collection for
missing optional dependencies, so any PR to main that touches a Python file is red before it
starts
.

Found while landing #13793 (putting the CI dispatch watchdog on the default branch, per #13791).
That PR adds three files — a workflow, a stdlib-only script, and its test — and cannot influence any
of the failures.

Evidence

$ git rev-list --count origin/main..origin/Dev_new_gui
263

main's ci.yml job list contains security-tests. Dev_new_gui's does not — it was restructured
into python-shard / python-suite:

$ git show origin/Dev_new_gui:.github/workflows/ci.yml | grep -n "^  [a-z-]*:"
  changes:  python-shard:  python-suite:  frontend-tests:  deployment-check:  notify:

The superseded job runs an unsharded pytest that collects the whole tree, and dies on optional deps:

ModuleNotFoundError: No module named 'asyncssh'
ModuleNotFoundError: No module named 'cachetools'
ModuleNotFoundError: No module named 'torchmetrics'
ModuleNotFoundError: No module named 'tools.lint'

ERROR collecting autobot-backend/pki/test_renewal.py
ERROR collecting autobot-backend/security/enterprise/threat_detection/test_learner.py
ERROR collecting autobot-backend/training/completion_trainer_test.py
ERROR collecting autobot-backend/api/knowledge_api_integration_test.py
ERROR collecting autobot-backend/mcp/mcp_security_test.py
ERROR collecting autobot-backend/services/redis_service_management_e2e_test.py
ERROR collecting repo_tests/lint/canonical/rules/test_py_*.py   (5 files)

Several of those files have already been given pytest.importorskip guards on Dev_new_gui
(test_learner.py guards sklearn, completion_trainer_test.py guards torch.nn.functional), and
main's copies differ. So this is not a missing fix — it is a fix that exists and has not reached
main.

Why it matters

main is the default branch. Two consequences beyond the red check:

  1. GitHub dispatches schedule only from the default branch, so any workflow whose cron matters must
    live on main. ci: bot-attributed runs park as action_required, and the watchdog cron that would clear them never fires #13791 is exactly that case — and getting the watchdog there is blocked by this.
  2. A default branch whose CI cannot pass is a default branch nobody can safely fix anything on.

Suggested fix

Sync main from Dev_new_gui. sync-main-to-dev.yml exists; whether it is the right vehicle for a
263-commit gap, or whether this wants a deliberate release merge, is an owner call.

A narrower interim option: bring main's ci.yml to the Dev_new_gui job set, so the default
branch stops running a workflow design that was retired on the active branch.

Acceptance criteria

  • A Python-touching PR against main can go green.
  • main no longer runs a CI job that the active branch has retired.
  • The gap between main and Dev_new_gui is either closed or deliberately recorded with the
    reason it stays open.

Related

Activity

  1. mrveiss commented on Aug 9, 2026

    @mrveiss
    OwnerAuthor

    Release sync PR opened: #13814 (Dev_new_gui → main, 263 commits), on the owner's instruction ahead of the next release.

    That merge is also the fix for this issue: it brings Dev_new_gui's current ci.yml — with python-shard/python-suite in place of the retired security-tests — onto the default branch, so a Python-touching PR to main can go green again.

    It merges cleanly:

    $ git merge-tree $(git merge-base origin/main origin/Dev_new_gui) origin/main origin/Dev_new_gui | grep -c '^<<<<<<<'
    0
    

    Context that made this urgent rather than cosmetic — the release investigation:

    releases:  1 stable · 10 prerelease
    latest (stable):  v0.2.0  @ 2026-03-26
    newest overall:   v0.6.3  @ 2026-08-04   (prerelease by policy, deliberate)
    
    Dev_new_gui commits not in v0.6.3:  263
    main commits not in Dev_new_gui:      4   (release chore commits)
    

    Releases fire on push to main, and v0.6.3's commit is on main but not an ancestor of Dev_new_gui. So cutting a release before this sync would publish a higher version number over a tree missing four months of merged work.

    #13793 becomes redundant if #13814 lands first — the sync carries the watchdog to main on its own, and that PR can be closed as superseded.

  2. added
    area: ci-gatesWave 0 · cluster P — CI gates & merge integrity
    on Sep 1, 2026
  3. added this to the v0.9.0 milestone on Sep 12, 2026
  4. mrveiss commented on Sep 17, 2026

    @mrveiss
    OwnerAuthor

    Verified against merged main and closing. Each criterion carries its own evidence; none is ticked on the strength of the branch rename alone.

    AC1 — a Python-touching PR against main can go green. Three merged today, all based on main, all carrying Python:

    PR .py files Base Merged
    #16813 1 main 2026-09-17
    #16811 2 main 2026-09-17
    #16810 3 main 2026-09-17

    AC2 — main no longer runs a retired CI job. git show origin/main:.github/workflows/ci.yml declares exactly six jobs:

    changes  python-shard  python-suite  frontend-tests  deployment-check  notify
    

    That is the restructured list this issue recorded as belonging to the active branch. git grep -c security-tests origin/main -- .github/workflows returns nothing — the job is gone from every workflow on the branch, not merely from ci.yml. So the collection failures on asyncssh / cachetools / torchmetrics / tools.lint have no job left to occur in.

    AC3 — the gap is closed. git rev-list --count origin/main..origin/Dev_new_gui returns 0, and gh repo view --json defaultBranchRef returns main. The relationship also inverted: main became the default branch on 2026-09-12, and mirror-main-to-legacy-dev-branch.yml now fast-forwards Dev_new_gui from main, so the direction that produced the 263-commit deficit cannot recur. #16461 tracks retiring the mirror once the deployed updater is confirmed to have stopped fetching the legacy name — that is a separate question about a deployment, not about this gap.

    What this issue was not. The 263-commit deficit and the retired job were one condition with one cause: main was not the branch development happened on. The rename removed the cause rather than patching either symptom, which is why all three criteria resolve together.

    Related: #15318 and #14444 also describe CI conditions predating the rename; #14444 is being re-scoped separately rather than closed here, because its subject — the self-hosted runner pool — was retired rather than repaired, and one of its criteria is still live.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions