Skip to content

CI Retry Gate v1.2.0 — State-Bound Reruns with Evidence-Gated Safety

Latest

Choose a tag to compare

@achirothmane achirothmane released this 27 Sep 15:41
· 15 commits to main since this release
f9bc919

CI Retry Gate v1.2.0

CI Retry Gate now binds rerun authorization to the exact workflow state that produced the evidence.

This release strengthens the core principle:

Evidence before action.

Highlights

  • Added EASL-compatible subject-state binding for pre-mutation validation.
  • Full-workflow reruns now revalidate the exact:
    • repository
    • run ID
    • run attempt
    • head SHA
    • workflow ID
    • failed-job set
  • Selective reruns now bind authorization to:
    • run attempt
    • head SHA
    • workflow ID
    • workflow lifecycle
    • exact failed-job execution state
  • Selective mode performs at most one mutation per evaluated workflow-state epoch.
  • Any remaining candidate must be re-evaluated after the first mutation changes workflow state.
  • Added canonical EASL subject-state conformance vectors for the Python compatibility layer.
  • Added external consumer E2E coverage for the state-bound selective-rerun path.

Safety

  • Workflow-state drift invalidates old rerun justification before mutation.
  • Invalid or unavailable state bindings fail closed.
  • Mutating GitHub API POST requests are not blindly replayed after ambiguous transport outcomes.
  • Automatic reruns remain disabled by default.
  • Causal Dominance remains research-only and does not participate in production retry authority.

External verification

A real external GitHub Actions consumer test demonstrated:

  1. Two failed jobs qualified as selective-safe candidates.
  2. Exactly one rerun mutation was issued from the evaluated state epoch.
  3. GitHub advanced the workflow to a new attempt.
  4. Exactly one job received a new execution.
  5. The other job was carried forward without a new execution timestamp.
  6. The new attempt was re-evaluated before any further write.
  7. No second mutation was authorized from the old state epoch.

The published @v1 line was also exercised from an external consumer against both ALLOW and fail-closed UNKNOWN evidence contracts.

Install

Use the stable major release:

- uses: achirothmane/workflow-failure-lab@v1

Or pin this exact version:

- uses: achirothmane/workflow-failure-lab@v1.2.0

Automatic reruns remain explicit opt-in.