Skip to content

fix(ci): sort out the lint-workflows class, the lock re-desync, and the freeze bypass — with the sources cured - #141

Merged
hyperpolymath merged 7 commits into
mainfrom
arena/01a0ef91-rpa-elysium
Sep 30, 2026
Merged

hyperpolymath merged 7 commits into
mainfrom
arena/01a0ef91-rpa-elysium

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown
Contributor

What this sorts out

Closes the acceptance criteria of #138 and goes after the three sources behind today's reds, in one change set. Each cure carries its inverse (januskey); nothing was muted, demoted, or removed from any required set (standards#994 AC5).

1. lint-workflows ×2 (issue #138) — determination: FIXED

Two governors claimed the same byte: gh actions-lock inserts # This workflow is managed by gh actions-lock. at line 1 whenever it mints or refreshes a lockfile, while the local Check SPDX headers step demanded the SPDX identifier on line 1. Every lock refresh re-failed the check. Measured same-commit (a045f44):

check predicate result on identical files
lint-workflows (local workflow-linter.yml) SPDX on head -1 🔴 18 of 19 files "missing" headers they all have (including its own file)
governance / Workflow security linter (canonical, standards@fad242d) SPDX in the leading comment block 🟢 green

The canonical predicate has existed in hyperpolymath/standards governance-reusable.yml since 2026-08-07, with the exact warning recorded: a line-1 test "fights the estate's own tool and re-fails every time a lockfile is refreshed" — it falsely reported 27 hypatia + 13 other workflows and "fixing" it mis-licensed 3 files. The local copy was a stale divergent mutant of the estate's own check.

The fix converges the local copy to the canonical form (scripts/check-workflow-headers.sh, byte-faithful): SPDX anywhere in the leading comment block (banner- and doc-marker-tolerant) + top-level permissions:. Same requirements, correct frame. Job name lint-workflows kept; the check stays blocking.

Expected-rejection controls (--self-test, from occupancy-types' gate contract and pons-asinorum's falsifier rule): 3 fixtures that must pass and 2 that must be killed, run first in the job. A predicate that cannot kill its own mutant is a Certified Null Operation (absolute-zero) and is not allowed to judge the tree. This promotes PR #137's manual mutation notes into a permanent control.

2. The freeze bypass — determination: FIXED (gate-enforced)

Dependabot #140 moved github/codeql-action b96794f0 (v4.38.0) → 2892aa5e (a 2026-09-24 releases/v4 merge, update-v4.38.2) in SHA form while copying the # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) comment verbatim — the witness of intent survived the rewrite with its meaning inverted. That pin is under an estate freeze (nexia-list#100: v4.38.1+ refused at startup; standards main still pins b96794f0 today). This is the second documented bypass of the hold (nexia-list#101: versions-scope; nexia-list#104: unconditional; then this).

An ignore rule is a request to a robot; this PR reverts the bump and adds scripts/check-frozen-pins.sh — the freeze as a check this repo owns, with its own mutants (SHA-form and tag-form bump both killed in self-test). Lifting the freeze becomes a deliberate, reviewable one-line table edit.

3. The lock re-desync (standards#968 class) — determination: FIXED, source cured

#140 bumped haskell-actions/setup v2.12.1 and did not regenerate actions.lock ("60 of 60 repos have Dependabot AND a lockfile AND no regeneration step — repos appear to go bad again; nobody broke them, the clock did"). Measured on main today: Lock Sync Gate 🔴, governance / Actions lockfile verify 🔴, CodeQL + GitHub Pages startup_failure (jobs=0), cflite poised to die. The lock is re-synced (haskell-actions/setup@v2.12.1 peeled via API; all four check-lock-sync.sh clauses verified), and lock-sync-heal.yml is the source cure: gh actions-lock (the sanctioned writer) on every workflow change + weekly backstop, opening one standing refresh PR whose body carries the checker's output as a receipt — obtained on the regenerated tree before the PR exists (epistemic-types: transported proof arrives with a sound check of the receiver's claim). Inverse: close the PR.

Residue list (honest boundary, echo-types/OND)

Not claimed, not erased — listed with dates:

  • hypatia / Hypatia Neurosymbolic Analysis — red on main since 2026-09-29 (Build Hypatia scanner). Cause not established from here (job logs unreachable from the triage sandbox); candidate classes: hyperpolymath/hypatia HEAD build-rot or transient hex.pm failure. It is standards#994's class 3; the reusable builds the scanner from a moving HEAD, which is the fragile contract. It is a required context and may block this PR's merge mechanically — per the stopping rule, nothing is required of a branch that its base does not satisfy.
  • mirror / mirror-gitea, mirror / mirror-disroot — red on main (infrastructure/credentials). Not measured further.

Verification

  • bash -n clean on every script and every run: block (extracted and parsed)
  • YAML parse clean on every touched workflow + lockfile
  • header predicate self-test: 3 accepted, 2 rejected
  • freeze gate self-test: 1 accepted, 2 rejected (SHA-form + tag-form mutants killed)
  • both predicates green on the full tree (all 20 workflow files)
  • check-lock-sync.sh clauses 1–4 pass on the repaired lock (verified via a clause-faithful port; gawk is not in the triage sandbox — the gate itself runs the real script on ubuntu-latest)
  • lint-workflows green on this PR head (both legs)
  • Lock Sync Gate green on this PR head

Theory basis (full map in docs/ci-guard-cures-2026-09-29.adoc)

pons-asinorum (contradiction taxonomy; negative corpus) · absolute-zero (CNO vacuous gates; OND residue lists) · januskey (inversion metadata; shared core over divergent copies) · echo-types (structured loss; comments that outlive their meaning) · epistemic-types (warrant ≠ knowledge; receipts) · choreographic-types (YAML+lock is one cut) · occupancy-types (expected-rejection controls; rung contracts) · panic-attack (signatures: TWO-GOVERNORS-ONE-INVARIANT, ROBOT-PROMISE-WITHOUT-GATE, STATE-CURE-WITHOUT-SOURCE-CURE).

🤖 Generated with Claude Code

hyperpolymath and others added 4 commits September 30, 2026 00:21
… hold bypass

Dependabot PR #140 moved github/codeql-action from b96794f0 (v4.38.0) to
2892aa5e (a 2026-09-24 releases/v4 merge, 'update-v4.38.2') in SHA form
while copying the inline '# v4.38.0 (4.38.1 blocked estate-wide;
nexia-list#100)' comment verbatim — the comment survived the rewrite with
its meaning inverted (echo-types: structured loss in a lossy map).

That pin is under an estate freeze: nexia-list#100 measured v4.38.1+
refused at workflow startup (tag AND SHA form) and rolled the estate back
to the v4.38.0 SHA; nexia-list#104 upgraded the defence to an
UNCONDITIONAL dependabot hold — which #140 bypassed anyway (second
documented bypass after nexia-list#101's versions-scope failure).
hyperpolymath/standards main still pins b96794f0 today.

Revert the three workflow files to the held SHA. The inline comment is
truthful again. The dependabot.yml comment now records the bypass and
points at the gate that will actually enforce the freeze (the next
commit's scripts/check-frozen-pins.sh) — an ignore rule is a request to a
robot; this repository now asserts the invariant itself.

Inverses: git revert this commit restores the bump (do that only after
deliberately lifting the freeze in scripts/check-frozen-pins.sh).

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…elf-tests, pin-freeze gate

Fixes the two red lint-workflows checks (issue #138). Root cause is a
contradiction between two governors over one byte: gh actions-lock INSERTS
'# This workflow is managed by gh actions-lock.' at line 1 whenever it
mints or refreshes a lockfile, while this workflow's 'Check SPDX headers'
step demanded the SPDX identifier on line 1 — so every lock refresh
re-failed the check. Measured same-commit: 18 of 19 workflow files failed
the line-1 test (including this file, judging itself) while
'governance / Workflow security linter' — the canonical predicate in
hyperpolymath/standards governance-reusable.yml since 2026-08-07 — was
green on the identical files. The local copy had diverged into a stale,
over-strict mutant of the estate's own check.

Changes:

* scripts/check-workflow-headers.sh — the canonical predicate, byte-
  faithful to governance-reusable.yml ('Check SPDX headers + permissions'):
  SPDX anywhere in the leading comment block (tolerating the lock banner
  and a YAML document marker) plus top-level permissions:. The SPDX and
  permissions requirements are unchanged; only the line-1 framing, which
  was wrong and fighting the estate's tool, is gone.
* Expected-rejection controls (--self-test): fixtures that must pass
  (banner+SPDX, line-1 SPDX, doc-marker+SPDX) and fixtures that must be
  rejected (no SPDX, no permissions). The self-test runs FIRST in the job:
  a predicate that cannot kill its own mutant is a Certified Null
  Operation and must not be allowed to judge the tree. This promotes PR
  #137's manual mutation-testing notes into a control that runs forever.
* scripts/check-frozen-pins.sh — the codeql-action freeze as a gate this
  repo owns, with its own mutants (SHA-form bump and tag-form bump both
  killed in self-test). Lifting the freeze is a deliberate one-line table
  edit in its own commit; git revert of that edit restores it.
* Job name 'lint-workflows' kept — check contexts must not be renamed
  casually (standards#994). The check stays blocking; nothing was muted,
  demoted, or removed from any required set.

Determination for issue #138: FIXED (both legs — the second occurrence is
the same job on the push event, cleared by the same change).

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…healer

PR #140 bumped haskell-actions/setup v2.12.0 -> v2.12.1 in casket-pages.yml
without regenerating actions.lock — Dependabot rewrites workflow YAML and
never touches the lock — so the tree entered the exact state the
actions.lock campaign cured (standards#968): GitHub refuses to start any
workflow whose step-level uses: refs are not recorded under its own path.
Measured consequences on main today: Lock Sync Gate red,
'governance / Actions lockfile verify' red, CodeQL and GitHub Pages
startup_failure (jobs=0), and cflite_batch/cflite_pr poised to die on
their next trigger.

* actions.lock — bless haskell-actions/setup@v2.12.1 (tag peeled to
  0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d via the API; owner_id/repo_id
  unchanged) and onboard the healer below. All four clauses of
  scripts/check-lock-sync.sh verified against the result, including
  clause 4 (COVERAGE). Hand-structured to gh actions-lock's format
  (precedent: PR #137); the healer will re-canonicalise on its first run.
* .github/workflows/lock-sync-heal.yml — the source cure. The lockfile's
  own header names the sanctioned writer (gh actions-lock); this workflow
  runs it on every workflow change and on a weekly backstop, and when the
  regenerated lock differs it opens one standing PR whose body carries
  check-lock-sync.sh's output as a receipt (checked on the regenerated
  tree BEFORE the PR exists). Audit mode by default on manual dispatch;
  fail-loud if the generator is unavailable. Inverse: close the PR or
  revert its commit.

A state cure without a source cure is a countdown: the campaign fixed the
estate once and the clock re-broke this repo in seven days. This is the
fix for the clock.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Records what the estate's formal-methods repos contribute to the nature of
these failures and which lines of the fix each concept changed:
pons-asinorum (contradiction/waste taxonomy, negative corpus), absolute-
zero (CNO gates, OND residue lists), januskey (inversion metadata,
shared-core over divergent copies), echo-types (structured loss; comments
that outlive their meaning), epistemic-types (warrant vs knowledge;
receipts), choreographic-types (cuts/frontiers), occupancy-types
(expected-rejection controls, rung contracts), panic-attack (bug
signatures for class-level triage). Includes the three failure signatures
and the recommended estate moves.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 9956fda4-a04c-4774-8266-bc1ae8457756

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

hyperpolymath and others added 2 commits September 30, 2026 00:36
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@hyperpolymath
hyperpolymath merged commit 3b0ca5e into main Sep 30, 2026
5 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0ef91-rpa-elysium branch September 30, 2026 07:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant