Skip to content

ci: queue team-memory updates through Java Pack - #1708

Merged
Changyong Gong (chagong) merged 2 commits into
mainfrom
chagong-java-debugger-queued-memory
Oct 10, 2026
Merged

Changyong Gong (chagong) merged 2 commits into
mainfrom
chagong-java-debugger-queued-memory

Conversation

@chagong

@chagong Changyong Gong (chagong) commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Migrate only the Java debugger's team-memory caller to the shared queue introduced by microsoft/vscode-java-pack#1769.

  • Keep .github/workflows/team-memory-post-merge.yml and the existing source ISSUELENS_TEAM_MEMORY_ENABLED opt-in. Require the canonical repository, default-branch push, matching workflow/head SHA, and no created/deleted/forced push.
  • Replace direct IssueLens/Azure invocation and local manual maintenance with microsoft/IssueLens/.github/actions/queue-team-memory@a81d2d96167fc0e69ac631c2edc85f858e693289. Explicitly dispatch Java Pack's team-memory-coordinator.yml on main with exactly five string inputs: repository, run ID, attempt, reconciliation ancestor, and head SHA.
  • Mint a dedicated installation token with pinned actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 (v3.2.0), scoped only to microsoft/vscode-java-pack with Contents read and Actions write. Caller GITHUB_TOKEN permissions remain empty; token revocation remains enabled.
  • Workflow-only scope: all public documentation additions have been removed as requested. The central coordinator owns the shared-wiki queue, invocation, and final validation. Issue-triage workflows and extension behavior are unchanged. Internal configuration prerequisites remain below, not in repository documentation.

Validation

  • Original workflow validation: actionlint v1.7.12 and git diff --check passed.
  • Ten offline contract tests passed against the exact pinned dispatcher implementation and action schemas. Coverage includes trigger/gate rejection cases, fixed target ref independent of source default, scoped App input/token wiring, exact five-string payload, a single bounded POST after metadata validation, empty-token failure without fallback, malformed payload rejection, and uncertain-outcome failure without retry or completion claims.
  • Follow-up validation: CONTRIBUTING.md matches its pre-migration content exactly; the previously validated workflow is unchanged. YAML parsing, runtime-safeguard assertions, and git diff --check passed. The PR now changes only .github/workflows/team-memory-post-merge.yml.
  • Self-reviewed against main (3705df0d0b1215b044e759647e50e4caa231e5b6). Original test harness and downloaded validation tools stayed in session artifacts, outside the repository.
  • No workflow dispatch, agent invocation, live setting/credential changes, or merge was performed. No external live-readiness claim is made.

Rollout prerequisites

Configure authentication before merging with the existing source opt-in enabled. Enabled source runs switch to queue-only dispatch immediately; missing credentials fail rather than falling back to direct invocation.

  1. In microsoft/vscode-java-debug, supply the new variable ISSUELENS_DISPATCH_APP_CLIENT_ID and secret ISSUELENS_DISPATCH_APP_PRIVATE_KEY for a dedicated dispatch App installed only on Java Pack, with Contents read and Actions write. These names were absent from the source repository's names-only listings during the original migration checks. Do not reuse the hosted IssueLens App key or the central source-read credentials.
  2. In Java Pack, configure the separate ISSUELENS_SOURCE_READ_APP_CLIENT_ID and ISSUELENS_SOURCE_READ_APP_PRIVATE_KEY secrets, which were missing in the original coordinator rollout checks. That App needs Actions/Contents/Pull requests read for this already-allowlisted source. A successful central own-repository run does not exercise external-source authentication.
  3. Preserve the existing source opt-in and central coordinator opt-in. Manual merged-PR maintenance uses the central Run workflow with source_repository=microsoft/vscode-java-debug and pull_request_number; there is no local queue bypass.

push_before authorizes ancestor reconciliation, not attested original-event provenance. Dispatch acceptance is not coordinator completion or a wiki-update receipt; inspect central runs before retrying an uncertain result.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@chagong
Changyong Gong (chagong) merged commit 65ff83e into main Oct 10, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants