qwen-code/.github/workflows
易良 fc874dfe0b
fix(ci): retry sandbox image builds and file an issue when a release build fails (#9916)
* fix(ci): retry sandbox image builds and file an issue when a release build fails

The v0.22.0 tag build died on a transient ETXTBSY during `npm ci` and was
never retried, so ghcr.io/qwenlm/qwen-code:0.22.0 was never published while
npm already served 0.22.0. Every sandbox-based CI lane (/resolve, sandboxed
review, autofix) then crashes with "manifest unknown" until the image exists.

Add one bounded retry to the buildx step: the first attempt carries
continue-on-error so a successful retry turns the job green, and the retry
gates on the first attempt's outcome alone (a failure() gate would read false
once continue-on-error absorbs the first attempt). The publish condition is
shared through one job-level env so the two build steps cannot drift.

Add a follow-up job that files or updates one issue per version when both
attempts fail — for tag pushes and for publishing dispatches alike, since the
issue body itself recommends that dispatch as the recovery path. Dedup uses
an exact body marker matched client-side, because GitHub search tokenizes the
colon out of the marker and never finds these issues.

Extend the existing workflow gate test to pin the retry contract and the
issue-job gate.

Fixes #9898

* fix(ci): move the image-build failure issue logic to .github/scripts/

The workflow-size ratchet rejects growth past the recorded baseline +4096
bytes; the inline issue-filing step grew build-and-publish-image.yml by
~5.2 KB. Move the step body to .github/scripts/image-build-failure-issue.sh
(the gate's own recommended remedy), leaving the job as a thin env + script
call. No behavior change; the gate test now pins the script call and reads
the dedup contract from the script.

* fix(ci): grant the failure-issue job contents permission and normalize dispatch versions

* test(ci): pin the failure-issue gate and retry step invariants

* fix(ci): gate the failure-issue job on the exported publish decision

* fix(ci): skip the failure-issue job for versionless publishing dispatches

* test(ci): pin the PUSH_IMAGE value and the login gate at the definition site

* test(ci): replay the image-build failure-issue script under a gh stub

* fix(ci): describe release build job failures without asserting a buildx cause

* fix(ci): preserve annotations and recorded runs when updating the failure issue

* test(ci): pin the dedup label on create and the open-state filter on lookup

* fix(ci): document the pre-first-step gap in the failure-issue gate

A build job that fails before its first step runs (runner provisioning
failure) never executes publish-decision, so push_image stays empty and
file-failure-issue is skipped despite failure() being true. Closing the
gap structurally would restate the publish predicate and re-introduce
the drift this PR removes, so document it on the job comment instead:
future "failed publish, no issue filed" investigations start here, and
a scheduled npm-vs-GHCR reconciliation remains the backstop.

* fix(ci): record build-and-publish-image.yml's shipped size in the workflow size baseline

The retry logic and failure-issue filing steps added by this PR grew the
workflow from 4638 to 8887 bytes, past the 4096-byte allowance. Record
the new size so the size gate passes.

* fix(ci): harden the image-build failure reporter per review round 4 (#9916)

- Replace GNU-only `head -n -1` with POSIX `sed '$d'` so the stranded-heading
  strip no longer corrupts the body on BSD userland (R4-1).
- Skip the bash replay suite on win32, where backslash RUNNER_TEMP and the
  ';'-separated PATH cannot express it; the YAML pins still run there (R4-2).
- Re-check head readability AFTER the normalization strip, which can itself
  empty the head and used to drop the narrative permanently (R4-8).
- Admit only recorded-run shapes into the machine block so a bullet-shaped
  human annotation is no longer reordered into it or clipped by the cap (R4-13).
- Remove the marker-restore branch: with the run shape pinned, every body that
  matched the dedup carries its marker in head+tail, so it was unreachable (R4-9).
- Cross-reference the sibling split/merge contract in both implementations (R4-5),
  disable SC2016 with rationale on the literal-backtick formats (R4-6), and
  document the label-removal residual gap on the job (R4-11).
- Behavioral witnesses: run-cap, stranded-heading, marker-survival, empty-head
  and empty-after-strip prose fallbacks, and the annotation shape; each guard
  mutation-probed red. Pin the dedup label on the list call too (R4-10).

* fix(ci): document the version-marker dedup gap on the failure-issue job (#9916)

Round 4 removed the unreachable marker-restore branch (R4-9) but left its
residual gap undocumented: the dedup lookup only finds the tracked issue
while the version marker survives in the body, so a human edit deleting
the marker orphans the issue and the next failure files a duplicate. Fold
the marker into the job's existing known-gap note alongside its sibling,
the scope/ci-cd label (R4-11), and record the workflow's new size.
2026-08-26 08:52:56 +00:00
..
.size-baseline fix(ci): retry sandbox image builds and file an issue when a release build fails (#9916) 2026-08-26 08:52:56 +00:00
assign-issue-owner.yml feat(ci): auto-assign issues to area owners from labels (#8668) 2026-08-08 23:01:03 +00:00
audio-capture-prebuilds.yml Upgrade GitHub Actions for Node 24 compatibility (#5157) 2026-07-07 12:17:22 +00:00
auto-minimize-spam.yml fix(ci): minimize new spam comments on creation (#9266) 2026-08-17 05:12:04 +00:00
build-and-publish-image.yml fix(ci): retry sandbox image builds and file an issue when a release build fails (#9916) 2026-08-26 08:52:56 +00:00
cd-cua-driver.yml feat(computer-use): replace built-in tools with bundled skill (#9856) 2026-08-24 11:05:23 +00:00
cd-mobile-mcp.yml chore(ci): Drop NPM_TOKEN in favor of npm Trusted Publishing (#9552) 2026-08-20 08:31:41 +00:00
ci.yml ci: take the macOS and Windows lanes off pull requests (#10059) 2026-08-26 03:31:55 +00:00
codeql.yml Upgrade GitHub Actions for Node 24 compatibility (#5157) 2026-07-07 12:17:22 +00:00
comment-attachment-guard.yml ci: route trusted-author fork PRs and no-checkout jobs to the ECS pool (#8502) 2026-08-04 03:48:24 +00:00
desktop-release.yml fix(desktop): bridge Electron users on Windows and Linux (#9079) 2026-08-13 15:42:31 +00:00
docs-page-action.yml ci: route trusted-author fork PRs and no-checkout jobs to the ECS pool (#8502) 2026-08-04 03:48:24 +00:00
dsw-swe-verified-release.yml feat: chain Terminal-Bench release evaluation (#9120) 2026-08-17 05:53:06 +00:00
e2e.yml chore(ci): Add security hygiene: CODEOWNERS for release workflows, least-privilege permissions, security checks and Scorecard (#9008) 2026-08-14 01:22:53 +00:00
finalize-release.yml chore(ci): Disable install scripts in release CI and guard security-checks workflow (#9577) 2026-08-21 03:48:03 +00:00
live-host-release.yml fix(live): restore Live Host after desktop removal (#9994) 2026-08-25 12:32:31 +00:00
live-host.yml fix(live): restore Live Host after desktop removal (#9994) 2026-08-25 12:32:31 +00:00
main-ci-failure-issue.yml fix(ci): give the macOS and Windows lanes a trigger again (#9370) 2026-08-25 11:53:05 +00:00
npm-cache.yml fix(ci): avoid root-owned npm cache workspace files (#8669) 2026-08-07 07:08:34 +00:00
pr-force-push-reminder.yml ci: route trusted-author fork PRs and no-checkout jobs to the ECS pool (#8502) 2026-08-04 03:48:24 +00:00
pr-self-report-label.yml feat(autofix): escalate stopped takeover PRs and age out unanswered pauses (#8960) 2026-08-15 17:32:23 +00:00
qwen-autofix-fork-bridge.yml feat(autofix): bridge fork-PR reviews into the credentialed review lane (#8676) 2026-08-07 16:11:48 +00:00
qwen-autofix-fork-signal.yml fix(ci): gate the fork signal on fields the review payload delivers (#9469) 2026-08-22 18:47:00 +00:00
qwen-autofix-round-seed.md docs(autofix): correct the round-seed guide on leading whitespace (#9663) 2026-08-21 16:06:48 +00:00
qwen-autofix.md fix(ci): scope workflow-size ratchet to the PR that grew the file (#9931) 2026-08-25 01:46:34 +00:00
qwen-autofix.yml fix(ci): neutralize legacy ##[ commands in autofix stdout echoes (#9871) 2026-08-25 02:17:46 +00:00
qwen-ci-flaky-rerun.yml ci: bump qwen-code-action to 05f8171 (skip redundant install, surface install errors) (#8444) 2026-08-03 08:41:46 +00:00
qwen-code-pr-review.yml fix(review): repair permissions before giving up on worktree cleanup (#9748) 2026-08-23 14:27:46 +00:00
qwen-fleet-shepherd.yml fix(ci): stop counting wedged queued runs as in-flight in the shepherd (#9518) 2026-08-20 13:37:22 +00:00
qwen-issue-followup-bot.yml fix(ci): stop dropping agent settings in resolve and follow-up workflows (#9252) 2026-08-16 03:27:00 +00:00
qwen-pr-safety-precheck.yml Upgrade GitHub Actions for Node 24 compatibility (#5157) 2026-07-07 12:17:22 +00:00
qwen-triage-finalize.yml ci: route trusted-author fork PRs and no-checkout jobs to the ECS pool (#8502) 2026-08-04 03:48:24 +00:00
qwen-triage.yml docs(ci): the ECS pool does run containers — correct two comments that say it does not (#9575) 2026-08-21 06:38:43 +00:00
release-sdk-java.yml fix(sdk-java): Harden daemon transport reliability (#7603) 2026-07-24 04:22:05 +00:00
release-sdk-python.yml Upgrade GitHub Actions for Node 24 compatibility (#5157) 2026-07-07 12:17:22 +00:00
release-sdk.yml chore(ci): Drop NPM_TOKEN in favor of npm Trusted Publishing (#9552) 2026-08-20 08:31:41 +00:00
release-vscode-companion.yml ci(vscode): gate sync publish on RELEASE_VSCODE_SYNC_PUBLISH variable (#9132) 2026-08-14 06:32:59 +00:00
release.yml feat(channels): add DingTalk Workspace channel (#9394) 2026-08-25 06:40:47 +00:00
repo-hygiene.yml fix(ci): route workflow label mutations through REST (#8761) 2026-08-09 15:05:15 +00:00
scorecard-monthly.yml chore(ci): Add security hygiene: CODEOWNERS for release workflows, least-privilege permissions, security checks and Scorecard (#9008) 2026-08-14 01:22:53 +00:00
sdk-java.yml refactor: centralize approval mode contracts (#9796) 2026-08-24 07:46:50 +00:00
sdk-python.yml refactor: centralize approval mode contracts (#9796) 2026-08-24 07:46:50 +00:00
security-checks.yml chore(deps): Clear high-severity CVE baseline and harden the security gate (#9584) 2026-08-21 07:43:32 +00:00
serve-ab-publish.yml ci: route trusted-author fork PRs and no-checkout jobs to the ECS pool (#8502) 2026-08-04 03:48:24 +00:00
serve-ab.yml fix(ci): narrow serve-ab's self-hosted wipe to the A/B checkout dirs (#9228) 2026-08-24 13:27:38 +00:00
stale.yml ci: route trusted-author fork PRs and no-checkout jobs to the ECS pool (#8502) 2026-08-04 03:48:24 +00:00
sync-desktop-to-oss.yml fix(desktop): harden release pipeline (#9009) 2026-08-12 16:38:12 +00:00
sync-live-host-to-oss.yml fix(live): restore Live Host after desktop removal (#9994) 2026-08-25 12:32:31 +00:00
sync-release-to-oss.yml Upgrade GitHub Actions for Node 24 compatibility (#5157) 2026-07-07 12:17:22 +00:00
update-ecs-runner-qwen.yml ci: add hk ECS runners to update matrix (#8599) 2026-08-05 16:57:08 +00:00
web-shell-visuals-cleanup.yml ci: route trusted-author fork PRs and no-checkout jobs to the ECS pool (#8502) 2026-08-04 03:48:24 +00:00
web-shell-visuals-publish.yml fix(ci): don't let one failing scenario sink the whole visual preview (#7511) 2026-07-23 02:34:07 +00:00
web-shell-visuals.yml fix(ci): don't let one failing scenario sink the whole visual preview (#7511) 2026-07-23 02:34:07 +00:00
windows-runner-smoke.yml ci: run Windows merge queue tests on ECS (#8386) 2026-08-05 12:14:42 +00:00