fix(strix): reserve NIM budget after GitHub Models 410 brownout - #955
fix(strix): reserve NIM budget after GitHub Models 410 brownout#955seonghobae wants to merge 15 commits into
Conversation
A 90-minute NVIDIA NIM attempt left no fallback compute, then GitHub Models o3/gpt-5-chat returned HTTP 410 github_models_retirement_brownout and failed required Strix closed. Cap each NIM attempt at 1800s, add Llama-3.1-Nemotron-Ultra-253B before GitHub Models, and skip remaining github_models fallbacks after a same-line retirement 410. Vulnerability signals stay blocking. NVIDIA_NIM_API_KEY is unchanged.
|
Warning Review limit reached
Next review available in: 48 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (8)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent Review-only request for exact current head |
Record that one hung NVIDIA NIM attempt cannot allocate the remaining scan budget without an independent 1800-second process limit. Clear the cached trusted-uv installer so Darwin hosts still exercise the linux x86_64 runner path.
A same-line github_models_retirement_brownout plus a bare 410 digit run (issue #410) could skip remaining github_models fallbacks. Keep family-dead only for Error code: 410, HTTP 410, or the retirement brownout phrase.
Issue #410 is already rejected. Error code 4100 and HTTP 4104 must not match the GitHub Models retirement-brownout skip either.
|
@opencode-agent @cwl-noema-review Review-only request for exact current head |
OpenCode Review Overview
Pull request overviewOpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed. Findings1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
Failed checks:
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: strix.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: strix.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: strix-github-models-retirement-brownout.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: strix-github-models-retirement-brownout.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script (3 files)"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script (3 files)"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (2 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (2 files)"]
R5 --> V5["targeted test run"]
|
Materialize a base Python lock only when every package line is an exact SHA-256 pin or a two-token relative -r/--requirement include of a candidate lock path. A lone --require-hashes directive, ./dotted paths, and -r other-hashes.txt no longer enter the trusted build context.
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
13118614c6699a94aa8d60316c70406c59a7a178. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Bandit (Python SAST) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613679/job/94496993610)
- Close Empty PR/close-empty: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613281/job/94496013532)
- CodeQL PR/Detect CodeQL languages: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613759/job/94496015256)
- Detect CodeQL languages check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613759/job/94496015256)
- Detect Python check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613679/job/94496015018)
- OSV-Scanner PR/osv-scan / osv-scan: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714614164/job/94496017154)
- Python 3.10 compatibility contract check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613633/job/94496014833)
- Python 3.14 full quality gate check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613633/job/94496014574)
- Python Security/Bandit (Python SAST): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613679/job/94496993610)
- Python Security/Detect Python: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613679/job/94496015018)
- Python Security/pip-audit (Python dependency audit): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613679/job/94496993822)
- SAST Semgrep/Semgrep (multi-language SAST): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613617/job/94496014640)
- SBOM Generation/generate-sbom: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613699/job/94496015159)
- Scorecard PR/Scorecard: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613757/job/94496015129)
- Scorecard check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613757/job/94496015129)
- Secret Scan/gitleaks (secret scan): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613651/job/94496015124)
- Security Scan/dependency-review: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613706/job/94496015214)
- Security Scan/osv-scan: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613706/job/94496015211)
- Security Scan/scorecard: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613706/job/94496015240)
- Security Scan/trivy-fs: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613706/job/94496015278)
- Semgrep (multi-language SAST) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613617/job/94496014640)
- Strix Changed Path Quality CI/exact-head-path-policy: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613636/job/94496014766)
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613227/job/94614112964)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613227/job/94614112964)
- Trusted uv Materializer Quality CI/Python 3.10 compatibility contract: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613633/job/94496014833)
- Trusted uv Materializer Quality CI/Python 3.14 full quality gate: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613633/job/94496014574)
- close-empty check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613281/job/94496013532)
- coverage-source-tree check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613239/job/94496985204)
- dependency-review check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613706/job/94496015214)
- exact-head-path-policy check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613636/job/94496014766)
- generate-sbom check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613699/job/94496015159)
- gitleaks (secret scan) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613651/job/94496015124)
- osv-scan / osv-scan check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714614164/job/94496017154)
- osv-scan check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613706/job/94496015211)
- pip-audit (Python dependency audit) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613679/job/94496993822)
- required-workflow-bootstrap check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613239/job/94496014164)
- scorecard check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613706/job/94496015240)
- trivy-fs check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714613706/job/94496015278)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: strix.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: strix.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (4 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (4 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: strix-github-models-retirement-brownout.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: strix-github-models-retirement-brownout.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script (4 files)"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script (4 files)"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (3 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (3 files)"]
R5 --> V5["targeted test run"]
|
Returned to Draft because the exact current tree mixes the Strix provider-family/budget repair with an unrelated trusted-uv materializer branch. The intended resilience boundary is narrow: reserve bounded compute for multiple hosted NIM candidates, classify only the exact same-line GitHub Models HTTP-410 retirement brownout as family-dead, and never neutralize vulnerability findings or generic application 410s. Head Rebuild from protected |
|
Additional exact downstream evidence for this central fix:
This is owning-layer provider-budget evidence, not a backend/source finding in fast-mlsirm #831. The observed 5,400-second first NIM attempt exhausted the entire scan budget exactly as this PR's 1,800-second per-attempt cap is intended to prevent. Preserve fail-closed missing-report behavior; after protected integration, rerun the unchanged #831 head and require either an authoritative clean/finding report or bounded fallback exhaustion rather than a single-model full-budget timeout. |
|
@coderabbitai review Review only exact current head |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
head_expected='2efd7d8607527cacde2aeeb33f3accc02c8367c3'
base_expected='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'
printf '%s\n' '== checked-out HEAD =='
git rev-parse HEAD
printf '%s\n' '== expected objects =='
git cat-file -t "$head_expected"
git cat-file -t "$base_expected"
printf '%s\n' '== ancestry and merge base =='
git merge-base "$base_expected" "$head_expected"
git merge-base --is-ancestor "$base_expected" "$head_expected" && echo 'base-is-ancestor=yes'
printf '%s\n' '== changed files =='
git diff --name-status "$base_expected" "$head_expected"
printf '%s\n' '== changed paths: outlines =='
git diff --name-only "$base_expected" "$head_expected" | while IFS= read -r path; do
printf '\n--- %s ---\n' "$path"
case "$path" in
*.yml|*.yaml) ast-grep outline "$path" --lang yaml --items all 2>/dev/null || true ;;
*.py) ast-grep outline "$path" --lang python --items all 2>/dev/null || true ;;
*.sh) ast-grep outline "$path" --lang bash --items all 2>/dev/null || true ;;
*) sed -n '1,80p' "$path" ;;
esac
done
printf '%s\n' '== full scoped diff =='
git diff --find-renames --find-copies --unified=80 "$base_expected" "$head_expected"Length of output: 164645 🏁 Script executed: #!/bin/bash
set -euo pipefail
head='2efd7d8607527cacde2aeeb33f3accc02c8367c3'
printf '%s\n' '== workflow neutralization block with line numbers =='
git show "$head:.github/workflows/strix.yml" |
nl -ba |
sed -n '/backend_unavailable_signal=/,/exit "\$strix_rc"/p'
printf '%s\n' '== gate brownout classifier and fallback handling with line numbers =='
git show "$head:scripts/ci/strix_quick_gate.sh" |
nl -ba |
sed -n '/is_github_models_retirement_brownout_error()/,/^}/p;/skip_remaining_github_models=0/,/if should_fail_pull_request_infra_zero_findings/p'
printf '%s\n' '== regression assertions for workflow-level neutralization =='
git show "$head:tests/test_strix_github_models_retirement_brownout.py" |
nl -ba |
sed -n '1,220p'
printf '%s\n' '== current PR status checks =='
gh api "repos/ContextualWisdomLab/.github/commits/${head}/check-runs?per_page=100" \
--jq '.check_runs[] | [.name, .status, (.conclusion // ""), .details_url] | `@tsv`' || trueLength of output: 1372 🏁 Script executed: #!/bin/bash
set -euo pipefail
head='2efd7d8607527cacde2aeeb33f3accc02c8367c3'
printf '%s\n' '== workflow neutralization block with line numbers =='
git show "$head:.github/workflows/strix.yml" |
awk '
/backend_unavailable_signal=/ {show=1}
show {printf "%6d %s\n", NR, $0}
show && /exit "\$strix_rc"/ {exit}
'
printf '%s\n' '== gate brownout classifier with line numbers =='
git show "$head:scripts/ci/strix_quick_gate.sh" |
awk '
/^is_github_models_retirement_brownout_error\(\)/ {show=1}
show {printf "%6d %s\n", NR, $0}
show && /^}$/ {exit}
'
printf '%s\n' '== workflow-level brownout regression coverage =='
git show "$head:tests/test_strix_github_models_retirement_brownout.py" |
awk '{printf "%6d %s\n", NR, $0}'
printf '%s\n' '== current PR status checks =='
if command -v gh >/dev/null 2>&1; then
gh api "repos/ContextualWisdomLab/.github/commits/${head}/check-runs?per_page=100" \
--jq '.check_runs[] | [.name, .status, (.conclusion // ""), .details_url] | `@tsv`' || \
echo 'GitHub check query was unavailable.'
else
echo 'GitHub CLI is unavailable in this sandbox.'
fiLength of output: 21690
The reviewed checkout equals the requested head. The requested base is its ancestor. Current required checks are queued or in progress, so they are not acceptance evidence.
|
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
2efd7d8607527cacde2aeeb33f3accc02c8367c3. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/31808101914/job/94791817357)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/31808101914/job/94791817357)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: strix.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: strix.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (4 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (4 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: strix-github-models-retirement-brownout.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: strix-github-models-retirement-brownout.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script (3 files)"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script (3 files)"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (3 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (3 files)"]
R5 --> V5["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
2efd7d8607527cacde2aeeb33f3accc02c8367c3. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/31808101914/job/94791817357)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/31808101914/job/94791817357)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: strix.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: strix.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (4 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (4 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: strix-github-models-retirement-brownout.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: strix-github-models-retirement-brownout.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script (3 files)"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script (3 files)"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (3 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (3 files)"]
R5 --> V5["targeted test run"]
|
@opencode-agent @cwl-noema-review @coderabbitai review Review exact head |
Rate Limit Exceeded
|
|
Exact-current-head read-only review request for The current head is an owner-authored metadata-only rebind of the verified Submit a verdict for this unchanged content/current head only. Treat predecessor checks/reviews as historical. Do not mutate or merge the branch, synthesize author approval, or weaken protection. @opencode-agent review |
Rate Limit Exceeded
|
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
1eb99cdff72fa30ea4df1ea45a2643759ef3f876. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/31887079389/job/95017850623)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/31887079389/job/95017850623)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: strix.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: strix.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: strix-github-models-retirement-brownout.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: strix-github-models-retirement-brownout.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script (3 files)"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script (3 files)"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (2 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (2 files)"]
R5 --> V5["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
1eb99cdff72fa30ea4df1ea45a2643759ef3f876. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/31887079389/job/95017850623)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/31887079389/job/95017850623)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: strix.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: strix.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: strix-github-models-retirement-brownout.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: strix-github-models-retirement-brownout.md"]
R3 --> V3["docs review"]
Evidence --> S4["CI script (3 files)"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script (3 files)"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (2 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (2 files)"]
R5 --> V5["targeted test run"]
Purpose
Required Strix runs failed closed when the primary hosted NVIDIA model consumed nearly the full process budget and the GitHub Models fallback family returned the scheduled-retirement HTTP 410 signal. That left no budget for another hosted NVIDIA attempt and made provider-family outages indistinguishable from actionable vulnerability evidence in buyer-facing required checks.
Bounded repair
Ultra-253B → Super-49B → GitHub Models, preserving the protected-mainSuper-49B → GitHub Modelssmoke contract while reserving a second hosted NVIDIA attempt;github_models_retirement_brownoutplus GitHub Models context plus HTTP 410 as family-dead, then skip remaininggithub_models/*candidates;NVIDIA_NIM_API_KEY; never addCOPILOT_GITHUB_TOKENor merge reviewer credential chains.Exact identity and scope
main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba;1eb99cdff72fa30ea4df1ea45a2643759ef3f876;CHANGELOG.md.Unrelated AGENTS/CLAUDE/Architecture/materializer-test drift had already been removed through ordinary forward commits. The prior exact-content head
2af893cedf8e3327f74c7b7bd43dc4115b4accbdwas produced by a GitHub Actions repair commit; GitHub consequently createdaction_requiredruns with zero jobs. The current owner-authored metadata-only forward commit points to the identical tree to obtain executable current-head checks. No source, test, workflow, credential, permission, reviewer, merge, or release behavior changed in that rebind; no force-push, rebase, or bypass was used.Every predecessor-head check, review, or approval is historical only.
Evidence lineage
The verified predecessor tree passed the required-workflow smoke test and eight focused brownout regressions. Its source shows the intended NIM chain and same-line retirement classification. Those results establish lineage, not current-head authorization.
The current head must regenerate terminal-success exact-head Strix, quality, security, SAST, dependency/SBOM, supply-chain, and semantic-review evidence. A run that is
action_required, has zero jobs, is queued, cancelled, stale, skipped, or bound to a predecessor head is not success.Merge gate
Merge or auto-merge only after the unchanged current head has terminal-success required gates, zero valid unresolved findings, a qualifying current-head semantic verdict, the independent non-author approvals and last-push approval required by live protection, a compatible live base, and ordinary expected-head merge authority. No admin merge, self-approval, review dismissal, or ruleset bypass is requested.