Skip to content

arena-ai-coding-agent PRs get zero CI signal: all 5 Actions workflows STARTUP_FAILURE (actor not allowed to trigger workflows) — #328 merged on this #330

Description

@hyperpolymath

Measured

PR #328 ("restore main typecheck — carry the fiber invariant in FiberBundle", author arena-ai-coding-agent, head 6044971, merged 2026-09-27T23:12:36Z) merged on a head where its own Agda run (36357715429) was startup_failure — so the change was never typechecked before merge, and (per #329) did not actually cure the red Agda run on main.

The run page's annotation for 36357715429 is unambiguous:

Error — Actor is not allowed to trigger Actions workflows. Workflow file: .github/workflows/agda.yml.

This is not an actions.lock/uses: literal-string mismatch. Confirmed via GraphQL (repository.pullRequest(number:328).commits(last:1).nodes[0].commit.checkSuites) that on that same head, every GitHub-Actions-triggered check suite recorded STARTUP_FAILURE / status: COMPLETED:

Workflow Run ID Conclusion
CodeQL Security Analysis 36357713089 STARTUP_FAILURE
Governance 36357713718 STARTUP_FAILURE
Secret Scanner 36357714196 STARTUP_FAILURE
Hypatia Security Scan 36357714816 STARTUP_FAILURE
Agda 36357715429 STARTUP_FAILURE

Five unrelated workflows, all STARTUP_FAILURE, all on the same head, all from the same actor (arena-ai-coding-agent) — an actions.lock/uses: defect in agda.yml would not explain the other four. A repo/org Actions permission gate refusing to run workflows for this actor on a pull_request event explains all five identically.

Why this matters

Any PR from arena-ai-coding-agent (or any actor hitting the same gate) merges with zero CI signal — no Agda, no CodeQL, no Secret Scanner, no Governance, no Hypatia check ever runs. #328 is a live instance: it was merged as a "fix" for red-main Agda while its own Agda run never executed, and main stayed red.

Acceptance criteria

  1. Identify the specific gate blocking arena-ai-coding-agent (org-level "Require approval for first-time contributors"/"fork PR workflow approval" setting, an actor allow/deny list, or an app-level restriction) via repo/org Settings → Actions, not guesswork.
  2. Either approve/allowlist the actor so its PRs get real CI signal, or — if the actor should not be allowed to trigger workflows at all — block it from opening PRs / require a human to re-push from an allowed actor before merge, so a PR from it can never merge without CI having actually run.
  3. Add a merge-time guard (ruleset/branch-protection check) that treats STARTUP_FAILURE the same as failure for required contexts, so a PR can't merge "green" when its checks never started — closing the specific hole fix(agda): restore main typecheck — carry the fiber invariant in FiberBundle #328 fell through.

Filed from #329's investigation (acceptance criterion 3: "the startup_failure on #328's head is explained and fixed … or documented as a caller defect with its own issue").

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:p1High - schedule nextscope:repoConfined to this repository

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions