f7a973e3d7
The advisory step ran `git merge-base origin/main HEAD` where HEAD is the checked-out refs/pull/N/merge commit. GitHub recomputes that synthetic merge commit whenever main moves, so by the time the job runs the checked-out SHA is often no longer reachable from any ref. `git fetch --deepen` on an unreachable commit can never pull in its parents, so all four fetches in the loop (200 + 3 x 1000) ran to completion, burned 4m15s, and still ended in "public-surface: no merge-base" (run 34285107265, job 102259026802). The step-level timeout keeps that overrun from cancelling the blocking job; this commit makes the step finish on the first fetch instead. Fetch refs/pull/N/head explicitly (always reachable server-side) and diff that ref against the base; the merge commit's own content is irrelevant to a symbol diff. Raise the step timeout from 2 to 3 minutes: one --deepen=200 fetch took ~56s and a --deepen=1000 ~67s on the runner, and main gains ~170 commits a day, so a branch a day old legitimately needs both. 45s of blocking steps + 3 min still fits the 5-minute job budget.