Skip to content

ci: refuse patch-fragment source files; security policy timelines - #596

Merged
hyperpolymath merged 1 commit into
mainfrom
rescue/d37-phase-zero-recovery
Oct 7, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
rescue/d37-phase-zero-recovery

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Summary

This PR is a rescue of the D37 phase-zero recovery commit 632b54a (2026-08-24), rebuilt as the single commit d19776e on main (the original commit left the branch so GitGuardian no longer sees its test-canary password; kept locally in refs/rescued/pr596/). main had independently landed most of the original work, so every one of the 33 conflicts resolves to main's version:

Net change against main, 3 files:

  1. repo-integrity-guard.yml: a new step, Source files must not be patch fragments. It fails when a tracked *.rs/ex/exs/res/js/ts/py/sh file starts with @@ , *** Begin Patch or diff --git. That is exactly how fixer.rs was broken.
  2. .gitignore: ignores .claude/worktrees/, so an agent worktree can't be committed as a gitlink again. That had happened with actions-policy, which main has since dropped.
  3. SECURITY.md: adds reporting expectations (acknowledgement within 48 hours, assessment within 7 days, 90-day coordinated disclosure), a supported-versions statement and a safe-harbour clause. It keeps main's pointer to SECURITY.adoc, which has none of these.

Closes: none

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue). The breakage is already fixed on main.
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative). The integrity guard did not catch a source file that was a patch fragment.
  • 📖 Documentation (SECURITY.md)
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

📌 New pins

Head SHA: d19776e. This PR adds or changes no pins. Every uses: ref and actions.lock entry is main's, byte for byte.

How has this been verified?

  • git diff --stat origin/main d19776e shows 3 files changed, +41/−10, and nothing else.
  • I ran the new guard's script locally on the merged tree: rc=0, no findings.
  • Positive control: I planted planted_frag.rs starting with @@ -1,2 +1,2 @@ and staged it with intent-to-add. The guard reported ::error file=planted_frag.rs::Source file begins with patch syntax with rc=1. The planted file was then removed.
  • actionlint .github/workflows/repo-integrity-guard.yml was clean.
  • grep of SECURITY.adoc for hour/day/harbour/disclosure/acknowledge found nothing, so the SECURITY.md additions are not duplicates.

Checklist

  • My commits are signed (git commit -S). d19776e shows G.
  • I ran the project's own checks/tests locally and they pass. No Rust source changed against main. The repo's CI on d19776e is the check, and I ran the guard step locally (above).
  • New files carry the correct SPDX-License-Identifier. There are no new files; SECURITY.md keeps its existing MPL-2.0 header.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole. The guard only adds a failure path.

Notes for reviewers

  • The guard checks only the first non-blank line of each file. A fragment that is spliced into the middle of a file is out of its scope.
  • The SECURITY.md response-time commitments are the owner's text from 632b54a, kept verbatim.

🤖 Generated with Claude Code

https://claude.ai/code/session_014BxjiTAaTZCHVWn2U5NWhL

@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 7687befb-8528-4c33-be3f-41b01fe1c0b1
📥 Commits

Reviewing files that changed from the base of the PR and between 3d9d8bc and 632b54a.

⛔ Files ignored due to path filters (2)
  • .github/workflows/actions.lock is excluded by !**/*.lock
  • dashboard/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (33)
  • .claude/worktrees/actions-policy
  • .github/workflows/boj-build.yml
  • .github/workflows/casket-pages.yml
  • .github/workflows/codeql.yml
  • .github/workflows/dogfood-gate.yml
  • .github/workflows/e2e.yml
  • .github/workflows/governance.yml
  • .github/workflows/hypatia-dispatch-intake.yml
  • .github/workflows/hypatia-scan.yml
  • .github/workflows/inbox-steward.yml
  • .github/workflows/instant-sync.yml
  • .github/workflows/learning-loop.yml
  • .github/workflows/mirror.yml
  • .github/workflows/pages.yml
  • .github/workflows/panicbot-sweep.yml
  • .github/workflows/push-email-notify.yml
  • .github/workflows/repo-integrity-guard.yml
  • .github/workflows/rust.yml
  • .github/workflows/scorecard.yml
  • .github/workflows/secret-scanner.yml
  • .github/workflows/supervised-fleet-scan.yml
  • .gitignore
  • .machine_readable/AGENTIC.a2ml
  • .machine_readable/ECOSYSTEM.a2ml
  • .machine_readable/META.a2ml
  • .machine_readable/NEUROSYM.a2ml
  • .machine_readable/PLAYBOOK.a2ml
  • .machine_readable/STATE.a2ml
  • SECURITY.md
  • bots/cipherbot/src/analyzers/infra.rs
  • bots/echidnabot/docs/content/api.adoc
  • robot-repo-automaton/src/fixer.rs
  • robot-repo-automaton/src/hypatia.rs
 _________________________________________________________________________
< Congratulations, you implemented a distributed single point of failure. >
 -------------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gitguardian

gitguardian Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

️✅ There are no secrets present in this pull request anymore.

If these secrets were true positive and are still valid, we highly recommend you to revoke them.
While these secrets were previously flagged, we no longer have a reference to the
specific commits where they were detected. Once a secret has been leaked into a git
repository, you should consider it compromised, even if it was deleted immediately.
Find here more information about risks.


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@hyperpolymath hyperpolymath changed the title fix: recover phase-zero CI and governance ci: refuse patch-fragment source files; security policy timelines Oct 7, 2026
Rescue of the D37 phase-zero recovery commit 632b54a (2026-08-24),
rebuilt on main. main had independently superseded everything else in
it (pins, actions.lock, permissions, the fixer.rs restoration, the
hypatia.rs refactor, the 6a2 -> descriptiles move). What remains:

- repo-integrity-guard: fail when a tracked source file begins with
  patch syntax (@@, *** Begin Patch, diff --git), the way fixer.rs
  was once a 14-line patch fragment.
- .gitignore: ignore .claude/worktrees/ so an agent worktree cannot
  be committed as a gitlink again.
- SECURITY.md: reporting timelines, supported versions, safe harbour;
  keeps the pointer to SECURITY.adoc.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014BxjiTAaTZCHVWn2U5NWhL
@hyperpolymath
hyperpolymath force-pushed the rescue/d37-phase-zero-recovery branch from f1ea64c to d19776e Compare October 7, 2026 10:01
@hyperpolymath
hyperpolymath merged commit e01c959 into main Oct 7, 2026
44 of 48 checks passed
@hyperpolymath
hyperpolymath deleted the rescue/d37-phase-zero-recovery branch October 7, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant