Skip to content

Fix Cross-platform LTS upgrade checkout on reused runners - #8479

Merged
Amaury Chamayou (achamayou) merged 2 commits into
mainfrom
achamayou-ci-workflow-health
Oct 1, 2026
Merged

Amaury Chamayou (achamayou) merged 2 commits into
mainfrom
achamayou-ci-workflow-health

Conversation

@achamayou

Copy link
Copy Markdown
Member

Motivation

The weekly Cross-platform LTS workflow failed on main in both of its last scheduled runs (2026-09-20, 2026-09-27) and on #8477, always in the actions/checkout step of the Upgrade ... AL3 to ... AL4 job:

fatal: Unable to create '/usr/local/vss-agent/2.337.0/_work/CCF/CCF/.git/index.lock': Permission denied
File was unable to be removed Error: EACCES: permission denied, unlink '/usr/local/vss-agent/2.337.0/_work/CCF/CCF/.devcontainer/Dockerfile'

In every failing run, test-upgrade ran on the same VM as the Azure Linux 3 build-install job of that run (runners 30999b0ec_*, 27b3f7d4c_*, c6bb2e77c_*). That job checks out CCF as root inside its --user root container, and test-upgrade then runs directly on the reused host as the runner user, so it cannot clean or update the root-owned checkout.

Implementation summary

  • Add a "Restore workspace ownership" step (sudo chown -R "$(id -u):$(id -g)" "$GITHUB_WORKSPACE") before checkout in test-upgrade, and document why in .github/workflows/README.md.
  • The step is extracted unchanged from Validate C++ disaster recovery traces with Lean #8282, so that PR still merges cleanly. It was validated there: in this run, test-upgrade landed on the VM that had just run the root-container build and passed.
  • The only other job running directly on a VMSS runner host, image_digest in release.yml, does not check out the repository.
  • Validation: the workflow parses with the new step first in test-upgrade; prettier --check passes on both changed files. This PR triggers Cross-platform LTS through its paths filter.

Safety and compatibility

CI-only change with no runtime, API, or data-format impact. The new step only changes ownership of files inside the job's own workspace on the runner.

The test-upgrade job runs directly on a reused VMSS runner. When it lands
on the VM that just ran the Azure Linux 3 build-install job of the same
run, which checks out CCF as root inside its container, actions/checkout
fails with permission errors on the root-owned workspace. This broke the
last two weekly runs on main.

Restore ownership of the workspace to the runner user before checking
out. The step is identical to the one in #8282, where it was validated.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 09:50
@achamayou
Amaury Chamayou (achamayou) requested a review from a team as a code owner October 1, 2026 09:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused CI fix is documented and validated by a successful workflow run on a reused runner.

Review effort: Balanced
Findings: None

What changed in this PR

Restores checkout reliability on reused VMSS runners by correcting workspace ownership before the LTS upgrade job.

Changes:

  • Adds a pre-checkout recursive ownership restoration step.
  • Documents why reused runners require this cleanup.

Custom instructions used: .github/copilot-instructions.md, .github/instructions/reviewing.instructions.md

File Description
.github/​workflows/​cross-platform-lts.yml Restores workspace ownership before checkout.
.github/​workflows/​README.md Documents the reused-runner permission issue.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@achamayou
Amaury Chamayou (achamayou) merged commit 884dc3d into main Oct 1, 2026
16 checks passed
@achamayou
Amaury Chamayou (achamayou) deleted the achamayou-ci-workflow-health branch October 1, 2026 13:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants