Problem
Only five of the 24 workflows run on pull requests. The other 19 are scheduled or manual, and nobody reads them. A census on main at edc91bc9e (2026-09-30), using the Actions API run counts rather than recent history:
| Lane |
Trigger |
Runs |
Successes |
State |
fuzz.yml |
daily schedule |
63 |
11 |
Red since 2026-08-10. dtolnay/rust-toolchain is pinned to a master SHA with no toolchain input: 'toolchain' is a required input. No fuzzing has run for 51 days. |
concurrency-stress-gate.yml |
weekly schedule |
9 |
0 |
Never passed. gate-registry.py run executes the registry command with a literal python3, dropping the virtualenv the workflow installed the wheel into: ModuleNotFoundError: No module named 'graphforge'. |
codspeed.yml |
daily schedule |
383 |
301 |
Red since 2026-09-17, every night since #1406 added the ingest floor gate. Tracked separately; not fixed here. |
native-local-admission.yml |
manual |
11 |
0 |
Cannot pass. It asks hosted runners to qualify as BenchExec admission hosts and they are disqualified by design. M5 names OVHC-AGENCY as the system under test. |
fly-tiny-qualification.yml |
manual |
1 |
0 |
Echo-only: prints gate-registry.py command … and performs no operation. |
fly-tiny-recovery.yml |
manual |
0 |
0 |
Echo-only, same shape. |
progressive-ladder.yml |
manual |
0 |
0 |
Echo-only, same shape. |
checkpoint-recovery-gate.yml |
manual |
0 |
0 |
Never run since 2026-07-28. Dispatched for the first time for this census. |
visualization-limits-stress.yml |
manual |
0 |
0 |
Never run since 2026-08-01. Dispatched for the first time for this census. |
release-certification.yml, clean-env-verify.yml |
manual |
0 |
0 |
Never run. Release path for M13; out of scope here, flagged to the release owner. |
Scripts, 151 tracked files under scripts/:
- Five test files that no workflow, Makefile target, or doc invokes, 303 passing tests that protect nothing because nothing runs them:
test-validate-g500-certification.py (248 tests), test-fly-filesystem-qualification.py (23), test-release-workflows.py (15), test-publish-track.py, test-binding-parity-policy.py. Their subjects are live. test.yml lists 50 script tests by hand, which is how five fell out.
- Three dead scripts last touched 2026-07-28 with no reference anywhere:
scripts/inventory_tck.py, scripts/tck_metrics.py, scripts/validate_datasets.py (its docstring says "for v0.3.0 release").
SQLite, DuckDB, and the DataFusion projects run fuzzing and stress on a schedule too. The difference is that a red scheduled lane there is somebody's problem within a day. A lane that is red for seven weeks, or has never been green, is cost with no signal, and a fuzz lane that does not fuzz is worse than none because the repo claims the coverage.
Scope
- Fix
fuzz.yml: pass the toolchain explicitly. Prove it with a dispatched run on the branch that reaches the fuzz targets.
- Fix the registry
run path so a registry command starting with python3 executes under the invoking interpreter. command output is unchanged. Add a regression test in test-gate-registry.py. Prove it with a dispatched concurrency-stress-gate.yml run on the branch.
- Delete the three echo-only handoff workflows. The registry commands they print remain available through
gate-registry.py command <gate>.
- Delete
native-local-admission.yml. The admission validator and the local-linux-cgroups-v2 profile stay; they run on the designated host.
- Dispose
checkpoint-recovery-gate.yml and visualization-limits-stress.yml on the result of their first run: passing lanes stay; a failing lane gets its root cause fixed here if bounded, otherwise its own issue.
- Wire the five orphan test files into
test.yml beside their subjects.
- Delete the three dead scripts.
- Guard: an existing policy test fails when a
scripts/ci/test-* file is invoked by no workflow or Makefile target, so tests cannot be orphaned again.
- Update
config/gate-registry.json, .github/workflows/README.md, and any policy test that pins the workflow list. Record in the README that a scheduled lane red for seven days is fixed or removed.
Non-goals
Acceptance criteria
Problem
Only five of the 24 workflows run on pull requests. The other 19 are scheduled or manual, and nobody reads them. A census on
mainatedc91bc9e(2026-09-30), using the Actions API run counts rather than recent history:fuzz.ymldtolnay/rust-toolchainis pinned to amasterSHA with notoolchaininput:'toolchain' is a required input. No fuzzing has run for 51 days.concurrency-stress-gate.ymlgate-registry.py runexecutes the registry command with a literalpython3, dropping the virtualenv the workflow installed the wheel into:ModuleNotFoundError: No module named 'graphforge'.codspeed.ymlnative-local-admission.ymlfly-tiny-qualification.ymlgate-registry.py command …and performs no operation.fly-tiny-recovery.ymlprogressive-ladder.ymlcheckpoint-recovery-gate.ymlvisualization-limits-stress.ymlrelease-certification.yml,clean-env-verify.ymlScripts, 151 tracked files under
scripts/:test-validate-g500-certification.py(248 tests),test-fly-filesystem-qualification.py(23),test-release-workflows.py(15),test-publish-track.py,test-binding-parity-policy.py. Their subjects are live.test.ymllists 50 script tests by hand, which is how five fell out.scripts/inventory_tck.py,scripts/tck_metrics.py,scripts/validate_datasets.py(its docstring says "for v0.3.0 release").SQLite, DuckDB, and the DataFusion projects run fuzzing and stress on a schedule too. The difference is that a red scheduled lane there is somebody's problem within a day. A lane that is red for seven weeks, or has never been green, is cost with no signal, and a fuzz lane that does not fuzz is worse than none because the repo claims the coverage.
Scope
fuzz.yml: pass the toolchain explicitly. Prove it with a dispatched run on the branch that reaches the fuzz targets.runpath so a registry command starting withpython3executes under the invoking interpreter.commandoutput is unchanged. Add a regression test intest-gate-registry.py. Prove it with a dispatchedconcurrency-stress-gate.ymlrun on the branch.gate-registry.py command <gate>.native-local-admission.yml. The admission validator and thelocal-linux-cgroups-v2profile stay; they run on the designated host.checkpoint-recovery-gate.ymlandvisualization-limits-stress.ymlon the result of their first run: passing lanes stay; a failing lane gets its root cause fixed here if bounded, otherwise its own issue.test.ymlbeside their subjects.scripts/ci/test-*file is invoked by no workflow or Makefile target, so tests cannot be orphaned again.config/gate-registry.json,.github/workflows/README.md, and any policy test that pins the workflow list. Record in the README that a scheduled lane red for seven days is fixed or removed.Non-goals
codspeed.yml; separate issue under epic(storage): scale complete ingest across cores and reach 1M edges/s #1387.release-certification.ymlandclean-env-verify.yml; release tooling owned by M13.test.ymljobs; test: make the TCK the primary oracle and collapse the four test grammars toward Rust plus TCK plus one smoke suite per binding #1620 owned the test consolidation.Acceptance criteria
fuzz.ymlrun on the PR head completes the toolchain step and runs the fuzz targets.concurrency-stress-gate.ymlrun on the PR head passes, or fails on a stress finding rather than an import error; any such finding is filed.test-gate-registry.pyhas a test that fails on the oldpython3behaviour.make gate-registry-checkpasses.test.yml; the guard test fails when one is removed from the workflow.