andygrove opened a new issue, #6408: URL: https://github.com/apache/datafusion-comet/issues/6408
### Describe the bug Every `Comet CI (label run)` has ended in `startup_failure` before any job starts since #4950 merged (2026-09-28 20:21 UTC). As a result, no `run-*` label has run anything. The run page shows: > Invalid workflow file: .github/workflows/ci_label.yml#L45 > Error calling workflow 'apache/datafusion-comet/.github/workflows/ci.yml@...'. The nested job 'docs' is requesting 'contents: write', but is only allowed 'contents: read'. #4950 set `ci.yml`'s default token permission to `contents: read` and raised the `docs` job to `contents: write`, because `docs.yaml` pushes the site to `asf-site`. `ci_label.yml` calls `ci.yml` with an explicit ceiling of `contents: read`. When the run starts, GitHub checks every job in the called workflow against that ceiling, including jobs the `labeled` event skips. ### Steps to reproduce Add any `run-*` label to an open pull request whose merge commit includes #4950. For example, `run-spark-4.2-tests` on #6398 produced [run 36581005535](https://github.com/apache/datafusion-comet/actions/runs/36581005535). Every label run since 03:08 UTC on 2026-09-29 has failed the same way. The few that passed after #4950 merged were built on merge commits based on an older `main`. ### Expected behavior The label run starts and runs the suite that the label gates. ### Additional context A pull request's own `Comet CI` run is unaffected, because there `ci.yml` runs as a top-level workflow with no caller ceiling. Until this is fixed, a push to a pull request that carries a `run-*` label runs the gated suite as part of that push's run. `dev/ci/check-ci-config.py` does not compare the permissions in the two files, so preflight did not catch the mismatch. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
