andygrove opened a new issue, #6408:
URL: https://github.com/apache/datafusion-comet/issues/6408

   ### Describe the bug
   
   Every `Comet CI (label run)` has ended in `startup_failure` before any job 
starts since #4950 merged (2026-09-28 20:21 UTC). As a result, no `run-*` label 
has run anything. The run page shows:
   
   > Invalid workflow file: .github/workflows/ci_label.yml#L45
   > Error calling workflow 
'apache/datafusion-comet/.github/workflows/ci.yml@...'. The nested job 'docs' 
is requesting 'contents: write', but is only allowed 'contents: read'.
   
   #4950 set `ci.yml`'s default token permission to `contents: read` and raised 
the `docs` job to `contents: write`, because `docs.yaml` pushes the site to 
`asf-site`. `ci_label.yml` calls `ci.yml` with an explicit ceiling of 
`contents: read`. When the run starts, GitHub checks every job in the called 
workflow against that ceiling, including jobs the `labeled` event skips.
   
   ### Steps to reproduce
   
   Add any `run-*` label to an open pull request whose merge commit includes 
#4950. For example, `run-spark-4.2-tests` on #6398 produced [run 
36581005535](https://github.com/apache/datafusion-comet/actions/runs/36581005535).
 Every label run since 03:08 UTC on 2026-09-29 has failed the same way. The few 
that passed after #4950 merged were built on merge commits based on an older 
`main`.
   
   ### Expected behavior
   
   The label run starts and runs the suite that the label gates.
   
   ### Additional context
   
   A pull request's own `Comet CI` run is unaffected, because there `ci.yml` 
runs as a top-level workflow with no caller ceiling. Until this is fixed, a 
push to a pull request that carries a `run-*` label runs the gated suite as 
part of that push's run. `dev/ci/check-ci-config.py` does not compare the 
permissions in the two files, so preflight did not catch the mismatch.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to