[main-red] molecule-ai/molecule-core: e05fc4daae #1730

Closed
opened 2026-05-23 12:07:16 +00:00 by gitea-actions · 2 comments

Main is RED on molecule-ai/molecule-core at e05fc4daae

Commit: https://git.moleculesai.app/molecule-ai/molecule-core/commit/e05fc4daaedc92a9cd86c367113431504e0f1d1c

Auto-filed by .gitea/workflows/main-red-watchdog.yml (Option C of the main-never-red directive). Per feedback_no_such_thing_as_flakes + feedback_fix_root_not_symptom: investigate the root cause; do NOT revert as a reflex. The watchdog itself never reverts.

Failed status contexts

  • Railway pin audit (drift detection) / Audit Railway env vars for drift-prone pins (push)failurelogs
    • Failing after 3s
  • lint-continue-on-error-tracking / lint-continue-on-error-tracking (push)failurelogs
    • Failing after 1m11s

Resolution path

  1. Read the failed logs (links above).
  2. If reproducible locally, fix forward in a PR targeting main.
  3. If the failure is a real flake — STOP. Per feedback_no_such_thing_as_flakes, intermittent failures are real bugs. Investigate to root cause; do not mark as flake.
  4. If the failure is blocking unrelated work for >1 hour, file a follow-up issue and assign someone. Do NOT revert without a human GO per feedback_prod_apply_needs_hongming_chat_go (branch protection is a prod surface).

Debug

{
  "all_contexts": [
    {
      "context": "Handlers Postgres Integration / detect-changes (push)",
      "state": "success"
    },
    {
      "context": "E2E Chat / detect-changes (push)",
      "state": "success"
    },
    {
      "context": "E2E Staging Canvas (Playwright) / detect-changes (push)",
      "state": "success"
    },
    {
      "context": "lint-required-workflows-docker-host-pinned / Lint docker-host pin on docker-touching workflows (push)",
      "state": "success"
    },
    {
      "context": "Lint no tenant GITEA or GITHUB token write / Scan for repo-host token write into tenant workspace surface (push)",
      "state": "success"
    },
    {
      "context": "Lint forbidden tenant-env keys / Scan workspace_secrets writers for forbidden env keys (push)",
      "state": "success"
    },
    {
      "context": "CI / Platform (Go) (push)",
      "state": "success"
    },
    {
      "context": "Secret scan / Scan diff for credential-shaped strings (push)",
      "state": "success"
    },
    {
      "context": "CI / Shellcheck (E2E scripts) (push)",
      "state": "success"
    },
    {
      "context": "CI / Canvas (Next.js) (push)",
      "state": "success"
    },
    {
      "context": "E2E Staging Canvas (Playwright) / Canvas tabs E2E (push)",
      "state": "success"
    },
    {
      "context": "E2E Chat / E2E Chat (push)",
      "state": "success"
    },
    {
      "context": "E2E API Smoke Test / E2E API Smoke Test (push)",
      "state": "success"
    },
    {
      "context": "CI / all-required (push)",
      "state": "success"
    },
    {
      "context": "CI / Canvas Deploy Reminder (push)",
      "state": "success"
    },
    {
      "context": "Lint workflow YAML (Gitea-1.22.6-hostile shapes) / Lint workflow YAML for Gitea-1.22.6-hostile shapes (push)",
      "state": "success"
    },
    {
      "context": "Handlers Postgres Integration / Handlers Postgres Integration (push)",
      "state": "success"
    },
    {
      "context": "publish-workspace-server-image / build-and-push (push)",
      "state": "success"
    },
    {
      "context": "publish-workspace-server-image / Production auto-deploy (push)",
      "state": "success"
    },
    {
      "context": "Railway pin audit (drift detection) / Audit Railway env vars for drift-prone pins (push)",
      "state": "failure"
    },
    {
      "context": "lint-continue-on-error-tracking / lint-continue-on-error-tracking (push)",
      "state": "failure"
    },
    {
      "context": "gate-check-v3 / gate-check (push)",
      "state": "success"
    },
    {
      "context": "Sweep stale Cloudflare DNS records / Sweep CF orphans (push)",
      "state": "success"
    },
    {
      "context": "ci-required-drift / drift (push)",
      "state": "success"
    },
    {
      "context": "Sweep stale AWS Secrets Manager secrets / Sweep AWS Secrets Manager (push)",
      "state": "success"
    },
    {
      "context": "Sweep stale Cloudflare Tunnels / Sweep CF tunnels (push)",
      "state": "success"
    },
    {
      "context": "Sweep stale e2e-* orgs (staging) / Sweep e2e orgs (push)",
      "state": "success"
    },
    {
      "context": "Continuous synthetic E2E (staging) / Synthetic E2E against staging (push)",
      "state": "pending"
    },
    {
      "context": "Staging SaaS smoke (every 30 min) / Staging SaaS smoke (push)",
      "state": "success"
    },
    {
      "context": "main-red-watchdog / watchdog (push)",
      "state": "pending"
    }
  ],
  "branch": "main",
  "combined_state": "failure",
  "failed_contexts": [
    "Railway pin audit (drift detection) / Audit Railway env vars for drift-prone pins (push)",
    "lint-continue-on-error-tracking / lint-continue-on-error-tracking (push)"
  ],
  "recheck_combined_state": "failure",
  "recheck_failed_contexts": [
    "Railway pin audit (drift detection) / Audit Railway env vars for drift-prone pins (push)",
    "lint-continue-on-error-tracking / lint-continue-on-error-tracking (push)"
  ],
  "sha": "e05fc4daaedc92a9cd86c367113431504e0f1d1c"
}

This issue is idempotent: the watchdog runs hourly at :05 and edits this body in place. When main returns to green, the watchdog will close this issue automatically with a "main returned to green" comment.

# Main is RED on `molecule-ai/molecule-core` at `e05fc4daae` Commit: <https://git.moleculesai.app/molecule-ai/molecule-core/commit/e05fc4daaedc92a9cd86c367113431504e0f1d1c> Auto-filed by `.gitea/workflows/main-red-watchdog.yml` (Option C of the [main-never-red directive](https://git.moleculesai.app/molecule-ai/molecule-core/issues/420)). Per `feedback_no_such_thing_as_flakes` + `feedback_fix_root_not_symptom`: investigate the root cause; do NOT revert as a reflex. The watchdog itself never reverts. ## Failed status contexts - **Railway pin audit (drift detection) / Audit Railway env vars for drift-prone pins (push)** — `failure` → [logs](/molecule-ai/molecule-core/actions/runs/81585/jobs/0) - Failing after 3s - **lint-continue-on-error-tracking / lint-continue-on-error-tracking (push)** — `failure` → [logs](/molecule-ai/molecule-core/actions/runs/81589/jobs/0) - Failing after 1m11s ## Resolution path 1. Read the failed logs (links above). 2. If reproducible locally, fix forward in a PR targeting `main`. 3. If the failure is a real flake — STOP. Per `feedback_no_such_thing_as_flakes`, intermittent failures are real bugs. Investigate to root cause; do not mark as flake. 4. If the failure is blocking unrelated work for >1 hour, file a follow-up issue and assign someone. Do NOT revert without a human GO per `feedback_prod_apply_needs_hongming_chat_go` (branch protection is a prod surface). ## Debug ```json { "all_contexts": [ { "context": "Handlers Postgres Integration / detect-changes (push)", "state": "success" }, { "context": "E2E Chat / detect-changes (push)", "state": "success" }, { "context": "E2E Staging Canvas (Playwright) / detect-changes (push)", "state": "success" }, { "context": "lint-required-workflows-docker-host-pinned / Lint docker-host pin on docker-touching workflows (push)", "state": "success" }, { "context": "Lint no tenant GITEA or GITHUB token write / Scan for repo-host token write into tenant workspace surface (push)", "state": "success" }, { "context": "Lint forbidden tenant-env keys / Scan workspace_secrets writers for forbidden env keys (push)", "state": "success" }, { "context": "CI / Platform (Go) (push)", "state": "success" }, { "context": "Secret scan / Scan diff for credential-shaped strings (push)", "state": "success" }, { "context": "CI / Shellcheck (E2E scripts) (push)", "state": "success" }, { "context": "CI / Canvas (Next.js) (push)", "state": "success" }, { "context": "E2E Staging Canvas (Playwright) / Canvas tabs E2E (push)", "state": "success" }, { "context": "E2E Chat / E2E Chat (push)", "state": "success" }, { "context": "E2E API Smoke Test / E2E API Smoke Test (push)", "state": "success" }, { "context": "CI / all-required (push)", "state": "success" }, { "context": "CI / Canvas Deploy Reminder (push)", "state": "success" }, { "context": "Lint workflow YAML (Gitea-1.22.6-hostile shapes) / Lint workflow YAML for Gitea-1.22.6-hostile shapes (push)", "state": "success" }, { "context": "Handlers Postgres Integration / Handlers Postgres Integration (push)", "state": "success" }, { "context": "publish-workspace-server-image / build-and-push (push)", "state": "success" }, { "context": "publish-workspace-server-image / Production auto-deploy (push)", "state": "success" }, { "context": "Railway pin audit (drift detection) / Audit Railway env vars for drift-prone pins (push)", "state": "failure" }, { "context": "lint-continue-on-error-tracking / lint-continue-on-error-tracking (push)", "state": "failure" }, { "context": "gate-check-v3 / gate-check (push)", "state": "success" }, { "context": "Sweep stale Cloudflare DNS records / Sweep CF orphans (push)", "state": "success" }, { "context": "ci-required-drift / drift (push)", "state": "success" }, { "context": "Sweep stale AWS Secrets Manager secrets / Sweep AWS Secrets Manager (push)", "state": "success" }, { "context": "Sweep stale Cloudflare Tunnels / Sweep CF tunnels (push)", "state": "success" }, { "context": "Sweep stale e2e-* orgs (staging) / Sweep e2e orgs (push)", "state": "success" }, { "context": "Continuous synthetic E2E (staging) / Synthetic E2E against staging (push)", "state": "pending" }, { "context": "Staging SaaS smoke (every 30 min) / Staging SaaS smoke (push)", "state": "success" }, { "context": "main-red-watchdog / watchdog (push)", "state": "pending" } ], "branch": "main", "combined_state": "failure", "failed_contexts": [ "Railway pin audit (drift detection) / Audit Railway env vars for drift-prone pins (push)", "lint-continue-on-error-tracking / lint-continue-on-error-tracking (push)" ], "recheck_combined_state": "failure", "recheck_failed_contexts": [ "Railway pin audit (drift detection) / Audit Railway env vars for drift-prone pins (push)", "lint-continue-on-error-tracking / lint-continue-on-error-tracking (push)" ], "sha": "e05fc4daaedc92a9cd86c367113431504e0f1d1c" } ``` _This issue is idempotent: the watchdog runs hourly at `:05` and edits this body in place. When `main` returns to green, the watchdog will close this issue automatically with a "main returned to green" comment._
gitea-actions bot added the tier:high label 2026-05-23 12:07:16 +00:00
Member

RCA — root cause

Main-red #1730 is not a product/test regression from commit e05fc4d; it is two CI hygiene gates surfacing missing operational prerequisites. Railway pin audit hard-fails because the scheduled workflow requires RAILWAY_AUDIT_TOKEN but the repo secret is empty. The continue-on-error lint hard-fails because the new arm64 advisory workflow added a masked job whose tracker comments are outside the lint's allowed ±2-line window.

Evidence

  • Railway log run 81585/job 0 — RAILWAY_AUDIT_TOKEN secret missing with RAILWAY_AUDIT_TOKEN: empty in env.
  • .gitea/workflows/railway-pin-audit.yml:31-33 — schedule triggers intentionally hard-fail when that secret is missing.
  • .gitea/workflows/railway-pin-audit.yml:61-73 — the secret-check exits 1 before any audit can run.
  • lint log run 81589/job 0 — violation: ci-arm64-advisory.yml,line=105 missing nearby tracker comment.
  • .gitea/workflows/ci-arm64-advisory.yml:104-106 — tracker text exists on line 104, but internal#418 is on the prior comment line, not within the directive's own comment form expected by the lint.
  • .gitea/workflows/lint-continue-on-error-tracking.yml:22-27 — the lint enforces tracker references in the directive neighborhood and exits 1 for violations.

Suggested fix

Split ownership. For Railway, provision RAILWAY_AUDIT_TOKEN as a repo secret with read-only variables scope for the molecule-platform Railway project, or downgrade the scheduled audit until the secret exists. For the lint failure, move internal#418 or a fresh mc#/internal# tracker onto the same line or immediate nearby line of continue-on-error: true in .gitea/workflows/ci-arm64-advisory.yml, then rerun the lint. This should route to CI/ops hygiene, not application rollback.

Confidence

High — both failed logs point to explicit guardrails and neither failed context executed application tests.

## RCA — root cause Main-red #1730 is not a product/test regression from commit `e05fc4d`; it is two CI hygiene gates surfacing missing operational prerequisites. Railway pin audit hard-fails because the scheduled workflow requires `RAILWAY_AUDIT_TOKEN` but the repo secret is empty. The continue-on-error lint hard-fails because the new arm64 advisory workflow added a masked job whose tracker comments are outside the lint's allowed ±2-line window. ## Evidence - Railway log run 81585/job 0 — `RAILWAY_AUDIT_TOKEN secret missing` with `RAILWAY_AUDIT_TOKEN:` empty in env. - `.gitea/workflows/railway-pin-audit.yml:31-33` — schedule triggers intentionally hard-fail when that secret is missing. - `.gitea/workflows/railway-pin-audit.yml:61-73` — the secret-check exits 1 before any audit can run. - lint log run 81589/job 0 — violation: `ci-arm64-advisory.yml,line=105` missing nearby tracker comment. - `.gitea/workflows/ci-arm64-advisory.yml:104-106` — tracker text exists on line 104, but `internal#418` is on the prior comment line, not within the directive's own comment form expected by the lint. - `.gitea/workflows/lint-continue-on-error-tracking.yml:22-27` — the lint enforces tracker references in the directive neighborhood and exits 1 for violations. ## Suggested fix Split ownership. For Railway, provision `RAILWAY_AUDIT_TOKEN` as a repo secret with read-only variables scope for the molecule-platform Railway project, or downgrade the scheduled audit until the secret exists. For the lint failure, move `internal#418` or a fresh `mc#/internal#` tracker onto the same line or immediate nearby line of `continue-on-error: true` in `.gitea/workflows/ci-arm64-advisory.yml`, then rerun the lint. This should route to CI/ops hygiene, not application rollback. ## Confidence High — both failed logs point to explicit guardrails and neither failed context executed application tests.

main returned to green at SHA ca9fe8dbfca459f4b4a61f55dcd21fecae6c1b73 (https://git.moleculesai.app/molecule-ai/molecule-core/commit/ca9fe8dbfca459f4b4a61f55dcd21fecae6c1b73). Closing automatically. If the underlying root cause is not yet understood, reopen this issue and file a postmortem — green-by-flake is still a bug per feedback_no_such_thing_as_flakes.

`main` returned to green at SHA `ca9fe8dbfca459f4b4a61f55dcd21fecae6c1b73` (<https://git.moleculesai.app/molecule-ai/molecule-core/commit/ca9fe8dbfca459f4b4a61f55dcd21fecae6c1b73>). Closing automatically. If the underlying root cause is not yet understood, reopen this issue and file a postmortem — green-by-flake is still a bug per `feedback_no_such_thing_as_flakes`.
gitea-actions bot closed this issue 2026-05-26 16:05:55 +00:00
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: molecule-ai/molecule-core#1730